Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content

2026-06-03T07:24:07Z38368ed9c670af9f11c743d4b030612c053ddb68a5a5a5f96fd2daf97d636c90
IoT/botnetLLM-abuseRCEactive-exploitationcredential-theftmalwarenation-statenpmphishingprivilege-escalationsupply-chain-attackwordpress-exploit

What happened

A batch of high-risk incidents and disclosures: McAfee Labs flags a Minecraft-focused MaaS campaign dubbed 'Weedhack' spreading malware via YouTube and fake clients/mods; Google issued June 2026 Android patches including actively exploited privilege-escalation CVE-2025-48595; Gamaredon weaponized WinRAR path-traversal CVE-2025-8088 to deliver multiple payloads; CISA added Oracle WebLogic CVE-2024-21182 to its KEV catalog after active exploitation; a supply-chain campaign (Miasma) compromised @redhat-cloud-services npm packages to steal credentials and deploy a worm; the codexui-android npm/OSS

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
38368ed9c670af9f11c743d4b030612c053ddb68a5a5a5f96fd2daf97d636c90
Enrichment time
2026-06-03T07:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.