Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer

An unknown threat actor has been observed exploiting a recently disclosed maximum-severity security flaw in SimpleHelp to deliver two previously unreported malware families, TaskWeaver and Djinn Stealer.

The intrusion involves the exploitation of CVE-2026-48558 (CVSS score: 10.0), a critical authentication bypass vulnerability impacting the OpenID Connect (OIDC) flow that an unauthenticated

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Why the Legendary Erdős Problems Are Falling to AI

Why the Legendary Erdős Problems Are Falling to AI Source: Hacker News

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first