Discord’s CDN exploited to deliver a Remote Access Trojan (RAT) disguised as a legitimate OneDrive file.

Discord’s CDN exploited to deliver a Remote Access Trojan (RAT) disguised as a legitimate OneDrive file.

A recent cybersecurity investigation has revealed a sophisticated phishing campaign leveraging Discord’s Content Delivery Network (CDN) to distribute Remote Access Trojan (RAT) malware disguised as legitimate Microsoft OneDrive files. This campaign primarily targets Microsoft 365 users and underscores the evolving tactics employed by cybercriminals to bypass conventional security measures.
The UK’s Online Safety Act was broken on the first day when a user found he could bypass Discord’s age verification using Death Stranding’s “photo mode” hack.

The UK’s Online Safety Act was broken on the first day when a user found he could bypass Discord’s age verification using Death Stranding’s “photo mode” hack.

On July 25, 2025, an X (formerly known as Twitter) user named Dany Sterkhov publicly revealed a method to circumvent Discord’s newly implemented age verification system in the United Kingdom, exploiting the photo mode feature in the video game Death Stranding. Sterkhov’s post included a demonstration on X, showing how Discord’s verification could be bypassed by utilizing a virtual “selfie” of the game’s protagonist, Sam Porter Bridges, in place of a real user’s image.
Fake gaming and AI firms are using Telegram and Discord to spread malware to cryptocurrency users.

Fake gaming and AI firms are using Telegram and Discord to spread malware to cryptocurrency users.

A sophisticated cybercrime campaign is targeting cryptocurrency users by impersonating legitimate gaming, artificial intelligence (AI), and Web3 startup companies. According to recent research from cybersecurity firm Darktrace, these threat actors are leveraging popular communication platforms such as Telegram and Discord to distribute malware.