CVE Tools

Critical SimpleHelp flaw exploited to deploy new stealer malware

BleepingComputerBy Bill Toulas

Reported exploitedSimpleHelp

Our summary

Attackers are actively exploiting a recently disclosed critical vulnerability in SimpleHelp (CVE-2026-48558) to compromise exposed instances and deploy new malware, including Djinn Stealer and a TaskWeaver loader. The affected SimpleHelp deployments—often used by MSPs, IT teams, and helpdesks—matter because the flaw can be used to bypass authentication via OpenID Connect (OIDC), enabling attackers to gain a trusted technician session for remote execution. Djinn Stealer then targets cross-platform developer and infrastructure data on Windows, macOS, and Linux, potentially allowing theft of credentials and downstream access to cloud resources, repositories, and API-connected AI tooling.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store