CVE Tools

'Djinn' Stealer Targets Cloud, AI Credentials

Dark ReadingBy Jai Vijayan

Reported exploitedSimpleHelp

Our summary

A campaign targeting the remote management product SimpleHelp has been observed using the critical authentication bypass vulnerability CVE-2026-48558 as an entry point. After exploiting an Internet-facing SimpleHelp instance, attackers gained technician-level access, deployed a JavaScript loader (TaskWeaver), and delivered Djinn Stealer to collect and encrypt high-value secrets. The malware can harvest cloud and developer credentials—including keys and configuration data tied to AI tooling/agents—highlighting why RMM compromise can quickly escalate into broader access and downstream supply-chain risk.

Read at Dark Reading

Dark Reading publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store