A threat actor keeps spreading the WeedHack malware to Minecraft players despite its original infrastructure taken down in July

A widespread malware campaign targeting Minecraft players, dubbed "WeedHack," has continued to evolve and spread despite the takedown of its initial infrastructure in July. Cybersecurity researchers reported that over 6,300 attempts to access malicious sites associated with WeedHack were blocked in the past month, indicating ongoing activity.
The WeedHack campaign, first identified in July, utilizes SEO poisoning techniques to direct users to malicious websites impersonating legitimate Minecraft clients. These sites then deliver the WeedHack malware. The initial campaign reportedly infected over 116,464 gamers.
Following the July takedown of the campaign's original command-and-control (C2) server and other infrastructure, threat actors shifted their distribution tactics. They are now increasingly leveraging file-hosting services to spread WeedHack. Discord accounts for nearly half (49.6%) of the identified malicious links, followed by MediaFire (23.4%), GitHub (8.2%), and Dropbox (4.6%). The remaining URLs lead to fake Minecraft reseller websites, some of which offer paid tools for free to entice users.
Researchers observed instances where the top two Google search results for a popular Minecraft client led directly to sites distributing WeedHack, highlighting the effectiveness of the SEO poisoning. In one case, a malicious site was found to have been built using an AI-powered website creation platform.
To mitigate the risk of infection, security experts advise gamers to download mods, clients, and other files exclusively from trusted, official sources. They also recommend avoiding suspicious offers, such as free versions of paid software or cracked programs. Users should maintain active security software, scan all downloads before opening them, and carefully inspect URLs for lookalike domains that could lead to malicious sites.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a