Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer

An unknown threat actor has been observed exploiting a recently disclosed maximum-severity security flaw in SimpleHelp to deliver two previously unreported malware families, TaskWeaver and Djinn Stealer.

The intrusion involves the exploitation of CVE-2026-48558 (CVSS score: 10.0), a critical authentication bypass vulnerability impacting the OpenID Connect (OIDC) flow that an unauthenticated

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Perforce charges $500 for training training videos.. and it’s AI narrated

Perforce charges $500 for training training videos.. and it’s AI narrated Source: Hacker News

The tragedy of the commons, AI edition

The tragedy of the commons, AI edition Source: Hacker News

GLM 5.2 and the coming AI margin collapse

GLM 5.2 and the coming AI margin collapse Source: Hacker News