Intelligence View
2K Games is pulling its games from NVIDIA GeForce Now
Yet another big removal from NVIDIA's streaming service. What you need to know 2K Games is a publisher owned by Take-Two that publishes games such as the Borderlands franchise. 2K Games has requested all of its titles be pulled from…
What you need to know
2K Games is a publisher owned by Take-Two that publishes games such as the Borderlands franchise.
2K Games has requested all of its titles be pulled from NVIDIA GeForce Now streaming.
This comes after publishers like Bethesda Softworks and Activision have pulled most and all of their games respectively.
If you've been hoping some big publishers would continue to have their games on NVIDIA's GeForce Now streaming service, well, this isn't the time to keep hoping. Today, NVIDIA announced on the GeForce Now forums that 2K Games has requested its titles be removed from the service.
"Per publisher request, please be advised 2K Games titles will be removed from GeForce NOW today," the statement reads. "We are working with 2K Games to re-enable their games in the future."
This follows a long list of other removals, as Activision Blizzard has pulled all of its games, The Long Dark has been removed and Bethe...
1. Sofort-Triage & Abwehrmaßnahmen
SOC Incident Playbook: Remote Code Execution (RCE) Defense
title: Detect Exploitation - 2K Games is pulling its games from NVIDIA GeForce Now
id: 174b4905-28d9-4b65-b15e-9334234e6cca
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
- https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-27
logsource:
category: network_connection
product: any
detection:
selection:
CommandLine|contains:
- 'exploit'
condition: selection
falsepositives:
- Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
- attack.initial_accessrule CTI_Threat_Indicator {
meta:
author = "iShareStuff CTI Automated Detection Engine"
date = "2026-09-27"
description = "YARA Signature for "
strings:
$str = "2K Games is pulling its games " ascii wide
condition:
any of them
}index=security sourcetype IN ("cisco:asa", "pan:traffic", "zeek_conn", "suricata", "WinEventLog:Security")
("2K Games is pulling its games from NVIDI")
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, dest_host, signature
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - countmessage: "*2K Games is pulling its games from NVIDI*"CommonSecurityLog
| where Message has "2K Games is pulling its games from NVIDI"
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, DestinationIP, DestinationPort, Activity
| extend DetectionRule = "iShareStuff-CTI-Compiled"
| sort by EventCount desc2. Cyber Threat Intelligence & Forensik
MITRE ATT&CK Matrix Navigator 14 Taktiken
tsecurity.de Cognitive Threat RAG
Analyse für identifizierte Bedrohung auf Basis von Live-CTI (ENISA EUVD): CVSS 0.0 · EPSS 0.0% · CISA KEV: nein. Handlungsableitung aus den verlinkten Hersteller-Quellen.
Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.
- 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
- 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
- 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.