LIVE · cybersecurity feed
Live wire
Australia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attackHackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)Fake Microsoft security scans trick victims into uninstalling their antivirusCVE-2026-19478 · ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreThe Vulnerability Gap: Why Discovery Is Outrunning RepairCISA’s logging guidance works beyond government
malware

Fake Minecraft Clients Deliver WeedHack Malware Despite Infrastructure Takedown

A threat actor keeps spreading the WeedHack malware to Minecraft players despite its original infrastructure taken down in July

zeroday.news ·

A widespread malware campaign targeting Minecraft players, dubbed "WeedHack," has continued to evolve and spread despite the takedown of its initial infrastructure in July. Cybersecurity researchers reported that over 6,300 attempts to access malicious sites associated with WeedHack were blocked in the past month, indicating ongoing activity.

The WeedHack campaign, first identified in July, utilizes SEO poisoning techniques to direct users to malicious websites impersonating legitimate Minecraft clients. These sites then deliver the WeedHack malware. The initial campaign reportedly infected over 116,464 gamers.

Following the July takedown of the campaign's original command-and-control (C2) server and other infrastructure, threat actors shifted their distribution tactics. They are now increasingly leveraging file-hosting services to spread WeedHack. Discord accounts for nearly half (49.6%) of the identified malicious links, followed by MediaFire (23.4%), GitHub (8.2%), and Dropbox (4.6%). The remaining URLs lead to fake Minecraft reseller websites, some of which offer paid tools for free to entice users.

Researchers observed instances where the top two Google search results for a popular Minecraft client led directly to sites distributing WeedHack, highlighting the effectiveness of the SEO poisoning. In one case, a malicious site was found to have been built using an AI-powered website creation platform.

To mitigate the risk of infection, security experts advise gamers to download mods, clients, and other files exclusively from trusted, official sources. They also recommend avoiding suspicious offers, such as free versions of paid software or cracked programs. Users should maintain active security software, scan all downloads before opening them, and carefully inspect URLs for lookalike domains that could lead to malicious sites.

malware
ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

First Malware Built Specifically for Car Head Units Fuels Botnet

Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices. The post First Malware Built Specifically for Car Head Units Fuels Botnet appeared first on SecurityWeek.

security

The County Prosecutors Who Became ICE Informants

Illinois prosecutors shared defendants’ personal data with federal immigration agents without criminal warrants, public disclosure, or legislative oversight.

vulnerabilitycritical

Australia Warns of Active Exploitation of Critical TeamCity Server Flaw

Australian officials are urging TeamCity customers to patch an actively exploited critical flaw, which follows a similar warning from the US government

vulnerability

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

Disclosed in January and honeypots buzzed soon after, CISA says it’s finally time for the USG to plug the gap

CVE-2026-73570

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. About CVE-2026-73570 Zimbra Collaboration Suite (ZCS) is a communication and collaboration platform popular with organizations that need to have control over their data or can’t afford a pricy alternative service like Microsoft 365 or Google Wor

security

ReliaQuest Rejects Compromise Claims After ShinyHunters Incident

ReliaQuest has detailed a social engineering attack linked to ShinyHunters, denying reports that the threat actor successfully compromised its systems