CVE Tools

Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer

The Hacker NewsBy The Hacker News

Reported exploitedSimpleHelp RMM

Our summary

An unidentified threat actor is actively exploiting the critical SimpleHelp flaw CVE-2026-48558 (CVSS 10.0), which allows an unauthenticated attacker to bypass authentication in OpenID Connect (OIDC) flows and obtain a fully authenticated “Technician” session. Using that access, they deployed two malware families, TaskWeaver (a Node.js loader) and Djinn Stealer (a cross-platform credential and data-stealing payload targeting systems across Windows, macOS, and Linux). The scale of harvested secrets—spanning cloud accounts, code repositories, AI tooling, and cryptocurrency wallets—makes this a high-impact risk, and CISA has added CVE-2026-48558 to its Known Exploited Vulnerabilities catalog.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store