Chat bots are sending friend requests in Riot immediately after ending your game. What are the scammers up to now?

Players of Riot Games' *League of Legends* are reporting a surge of AI-powered bots sending friend requests through the game client immediately after matches, initiating flirtatious conversations, and ultimately attempting to funnel users to paid subscription platforms like OnlyFans. This activity aligns with a broader trend of AI-assisted social engineering migrating from dating apps to gaming platforms.
The scam typically begins with a friend request in the Riot client from an unfamiliar account moments after a game concludes. The initial message often includes generic flattery, such as "you played really well last game" or "I liked your playstyle," designed to appear as a genuine compliment. When asked about their identity, these accounts frequently claim to have been on the opposing team, despite name mismatches, and often present themselves as women seeking a duo partner. Profiles associated with these accounts are frequently blank, showing no match history, overview data, or a very low account level, consistent with disposable accounts created for outreach.
After a brief exchange, the bot directs the conversation off-platform, typically to Discord, citing an imminent departure. Once on Discord, the persona shifts into a more elaborate romance or flirtation script, involving hours of rapport-building and a steady stream of suggestive photos. These images have been found to be recycled across various unrelated websites and videos, indicating a large-scale operation rather than individual interaction. One user reported that when they paused replying, the bot sent new images of the model looking concerned, asking "Why are you not replying?", suggesting automated image generation tied to the script. Attempts to "jailbreak" the bot by prompting it to reveal its instructions were unsuccessful, as it maintained its persona, indicating built-in guardrails or a simpler, scripted flow with some AI-generated text.
The primary goal of this particular scam appears to be driving paid subscriptions to OnlyFans-style pages, often featuring a fabricated AI persona. While some underlying OnlyFans accounts may be legitimate, the conversations are highly likely managed by paid chat operators or AI systems using shared scripts and media libraries. However, more malicious variants have also been reported, where clicking a link from these bot accounts can lead to Discord account hijacking or credential harvesting.
The prevalence of these bot requests immediately after matches has led to speculation that operators are monitoring publicly available match data through third-party tracking sites and APIs to identify and target recent game participants. Riot's client architecture, which exposes local endpoints like the friends list API to third-party tools, may inadvertently facilitate this. Some affected players have found that enabling the client's "streamer mode," which hides recent match and online status information, appears to reduce the frequency of these bot requests, suggesting the targeting relies on visible activity signals.
Because the scam starts with a low-cost, disposable Riot account and quickly moves the conversation to Discord, the *League of Legends* client friend request serves as an initial filter. This allows operators to generate contacts cheaply, discard accounts easily after single use, and operate outside the reach of Riot's in-game reporting tools once the conversation shifts off-platform.
To protect themselves, players are advised to treat any unrecognized Riot client friend request as suspicious, especially those arriving immediately after a match. Verifying if the account was actually in their last game before accepting is recommended. Enabling privacy settings like streamer mode can limit visible activity data. Skepticism is warranted for anyone quickly attempting to move the conversation to Discord. Reverse image searches on any profile or personal photos sent early in a conversation can reveal recycled images, a strong indicator of a bot or catfishing operation. Players should also be wary of AI-typical conversation patterns, such as scripted responses, instant replies, grammatically flawless but emotionally generic language, or consistent evasion of voice or video calls. Finally, players should never send money, gift cards, cryptocurrency, or payment details to contacts met exclusively through in-game or Discord interactions.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.