### Critical Exploits Summary
1. **Active Vulnerabilities Detected:** 6 critical vulnerabilities have been identified today, including:
- **CVE-2021-23758:** Ajax.NET Professional deserialization issue.
- **CVE-2015-3246:** Red Hat Libuser race condition.
- **CVE-2015-5287:** Red Hat Automatic Bug Reporting Tool privilege escalation.
- **CVE-2022-0995:** Linux Kernel out-of-bounds write vulnerability.
- **CVE-2026-8452:** Citrix NetScaler ADC memory buffer restriction issue.
- **CVE-2019-1068:** Microsoft SQL Server remote code execution vulnerability.
### Malware Overview
- **Malware Name:** WeedHack, operates as a Malware-as-a-Service (MaaS) infostealer targeting Minecraft gamers.
- **Threat Actors:** Unnamed operators and customers.
- **Spread Mechanism:** Through fake client websites, SEO poisoning, and platforms like Discord, MediaFire, and GitHub.
- **Infections:** Over 116,464 reported infections among gamers.
- **Current Tactics:** Post disruption of original infrastructure, the operators have shifted tactics, using convincing-looking websites that clone official tools and utilize SEO techniques to rank higher in search results.
### Infection Chain
- Attackers initiate infections via disguised JAR downloads that contain the WeedHack payload. Platforms like Discord and GitHub have been frequently used for hosting malicious files.
### Protection Guidance
- Users are advised to only download from reputable sources, verify URLs carefully, and employ web protection measures to detect malicious sites.