惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Project Zero
Project Zero
Y
Y Combinator Blog
雷峰网
雷峰网
Last Week in AI
Last Week in AI
人人都是产品经理
人人都是产品经理
F
Fortinet All Blogs
Microsoft Azure Blog
Microsoft Azure Blog
有赞技术团队
有赞技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - Franky
博客园 - 聂微东
S
SegmentFault 最新的问题
Engineering at Meta
Engineering at Meta
罗磊的独立博客
M
MIT News - Artificial intelligence
B
Blog
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
大猫的无限游戏
大猫的无限游戏
V
V2EX
I
InfoQ
The Cloudflare Blog
Cloudbric
Cloudbric
Stack Overflow Blog
Stack Overflow Blog
V
Vulnerabilities – Threatpost
博客园_首页
Google DeepMind News
Google DeepMind News
Jina AI
Jina AI
T
The Exploit Database - CXSecurity.com
宝玉的分享
宝玉的分享
H
Hackread – Cybersecurity News, Data Breaches, AI and More
The GitHub Blog
The GitHub Blog
The Register - Security
The Register - Security
美团技术团队
K
Kaspersky official blog
C
CXSECURITY Database RSS Feed - CXSecurity.com
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
T
Tor Project blog
P
Privacy International News Feed
P
Privacy & Cybersecurity Law Blog
G
GRAHAM CLULEY
博客园 - 三生石上(FineUI控件)
Cyberwarzone
Cyberwarzone
Vercel News
Vercel News
Cisco Talos Blog
Cisco Talos Blog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
C
Cisco Blogs
G
Google Developers Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
A
Arctic Wolf
MongoDB | Blog
MongoDB | Blog

Devoriales - DevOps and Python Tutorials

Cloud & DevOps & AI Digest: The Week of Jun 28, 2026 Cloud & DevOps & AI Digest: The Week of Jun 20, 2026 Ansible for DevOps Engineers: Architecture, Core Concepts, and Hands-On Lab Login Must-Have Kubernetes CLI Tools Every Platform Engineer Should Know Login Login Login Why Your Best Engineers Are Quitting (And How to Stop It) Login ArgoCD Vulnerability: How the ServerSideDiff Feature Exposes Kubernetes Secrets Login How Kubernetes Controls What Your Containers Can Do Login Multi-AZ Is Not Disaster Recovery: What the AWS Bahrain Outage Finally Proved Trivy Supply Chain Attack: When Your Security Scanner Becomes the Threat Is Claude Opus 4.6 Fast Mode Really Worth 6× the Price? Login Unlocking Higher Pod Density in EKS with Prefix Delegation AWS Regional NAT Gateway: What It Is and Why You Should Care Kubernetes 1.35 Timbernetes Release AWS re:Invent 2025: The Future of Kubernetes on EKS Debate Series: How Do We Control Deployment Order in Kubernetes? Debate Series: Should We Eliminate Kubernetes Secrets Entirely? Kubernetes CRDs Explained: A Beginner-Friendly Guide to Extending the Kubernetes API Reduce Cloud Cross-Zone Data Transfer Costs with Kubernetes 1.33 trafficDistribution Building Custom Bitnami Images: A Guide for Self-Hosted Container Images New Features in Kubernetes 1.34: An Overview From Free to Fee: How Broadcom's Bitnami Monetization Disrupts DevOps Infrastructure Claude Code Cheat Sheet: The Reference Guide Kubernetes Loses Enterprise Slack Status: Discord Among Platforms Being Considered Understanding Container Security: A Guide to Docker and Pod Security Container Patterns in Kubernetes: Init Containers, Sidecars, and Co-located Containers Explained AWS Launches Serverless MCP Server: AI-Powered Development Gets a Serverless Boost ArgoCD 3.0: The Evolution Toward Secure GitOps Redis Returns to Open Source: The AGPLv3 Licensing Decision New Features in Kubernetes 1.33: An Overview Prometheus: How We Slashed Memory Usage IngressNightmare: Critical Ingress-NGINX Vulnerabilities and How to Check Your Exposure New Features in Kubernetes 1.32: An Overview What to Consider If You're Not Signing Up for Bitnami Premium Certified Kubernetes Administrator (CKA) Exam Updates for 2025 DeepSeek AI and the Question of the AI Bubble Python Tops the Tiobe Index: The Most Popular Programming Languages - January 2025 2024 in Review: IT Trends, Startups, and What’s Next Inside Argo: The Open-Source Journey Captured in a CNCF Documentary Running Docker on macOS Without Docker Desktop - updated with Kubernetes installation HashiCorp Rolls Out Terraform 2.0 at HashiConf, Keeps IBM Acquisition in the Shadows Is the EU Falling Behind in the Global AI Race? Prometheus Essentials: Node Exporter And System Monitoring Prometheus Essentials: Install and Start Monitoring Your App Prometheus Essentials: Introduction To Metric Types Kubernetes Pod Scheduling Explained: Taints, Tolerations, and Node Affinity Retrieval Augmented Generation (RAG) Explained for Beginners Like Me Using Sealed Secrets with Your Kubernetes Applications
Valve Responds to Alleged Steam Data Breach Reports: What Users Need to Know
Aleksandro Matejic · 2025-05-15 · via Devoriales - DevOps and Python Tutorials

Recent reports of a potential Steam data breach affecting 89 million accounts have caused significant concern among the gaming community. However, Valve, the company that owns and operates Steam, has now issued an official statement clarifying the situation.

Let's examine what happened, the conflicting reports, and what Steam users should do to protect their accounts.

Initial Reports and Claims

On May 13, 2025, cybersecurity firm Underdark AI published a LinkedIn post claiming a "Massive Alleged Steam Data Breach" with over 89 million records reportedly for sale on a dark web forum. According to these initial reports, a threat actor using the alias "Machine1337" (also known as "EnergyWeaponsUser") was offering the database for US$5,000.

The alleged stolen data was said to include phone numbers and one-time passwords, potentially allowing unauthorized access to accounts without two-factor authentication.

Conflicting Information Emerges

As the story spread across social media and news outlets, conflicting information began to surface about the source and extent of the alleged breach:

  1. Twilio Connection Questioned: Early speculation pointed to Twilio, a communications provider, as the potential source of the breach. However, Twilio explicitly denied any involvement. In a statement to BleepingComputer, a Twilio spokesperson said: "There is no evidence to suggest that Twilio was breached. We have reviewed a sampling of the data found online, and see no indication that this data was obtained from Twilio."
  2. Valve's Official Response: On May 14, Valve issued a comprehensive statement addressing the situation: "Yesterday we were made aware of reports of leaks of older text messages that had previously been sent to Steam customers. We have examined the leak sample and have determined this was NOT a breach of Steam systems." Valve clarified they are still investigating the source of the leak, noting that "SMS messages are unencrypted in transit, and routed through multiple providers on the way to your phone."

What Was Actually Exposed?

According to Valve's statement, the leaked data consisted of:

  • Older text messages containing one-time codes (valid for only 15-minute windows)
  • Phone numbers these messages were sent to

Importantly, Valve emphasized that "The leaked data did not associate the phone numbers with a Steam account, password information, payment information or other personal data."

When BleepingComputer examined the sample of leaked files containing 3,000 records, they found historical SMS text messages with one-time passcodes for Steam, including recipient phone numbers, which aligns with Valve's assessment.

Security Implications for Users

Despite the limited nature of the exposed data, security experts recommend taking precautionary measures:

Valve's Official Guidance

Valve has clearly stated: "From a Steam perspective, customers do not need to change their passwords or phone numbers as a result of this event."

However, they recommend:

Additional Security Best Practices

While Valve indicates no immediate action is required, following these general security practices remains advisable:

  • Use strong, unique passwords for gaming accounts
  • Enable Steam Guard (Steam's two-factor authentication system)
  • Be cautious of phishing attempts via email, messages, or suspicious links
  • Consider using a password manager to maintain secure credentials

The Investigation Continues

Valve has stated they are "still digging into the source of the leak," suggesting this situation may evolve as more information becomes available.

The conflicting narratives between the initial reports and Valve's assessment highlight the importance of waiting for official confirmation before taking drastic action based on cybersecurity news.

What This Means for the Gaming Community

With over 30 million users regularly active on Steam, security concerns naturally generate significant attention.

While the current evidence suggests this incident was not a breach of Steam's systems and poses limited risk to users, it serves as an important reminder about digital security hygiene.

The focus on SMS-based one-time passwords also underscores a potential vulnerability in text message-based authentication methods, which security experts have long noted are less secure than app-based authenticators.

Conclusion

Based on Valve's official statement, Steam users can breathe a sigh of relief knowing their accounts and personal information appear to remain secure. The situation offers a timely reminder about maintaining good security practices and treating unexpected security messages with appropriate caution.

As the investigation continues, users should stay informed through official Steam channels rather than relying on unverified reports circulating online.