Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Severe SimpleHelp Flaw Used to Deploy New Malware

Severe SimpleHelp Flaw Used to Deploy New Malware

Posted on June 30, 2026 By CWS

Emerging Threat Exploits Critical SimpleHelp Vulnerability

In a concerning development, cybersecurity experts have identified an unidentified threat actor leveraging a newly discovered critical vulnerability in the SimpleHelp software to distribute two previously unknown malware strains. The vulnerability, cataloged as CVE-2026-48558, represents a severe security risk due to its ability to bypass authentication protocols, allowing unauthorized actors to gain full access to technician sessions.

Understanding the SimpleHelp Vulnerability

The flaw, characterized by a CVSS score of 10.0, exploits weaknesses in the OpenID Connect (OIDC) flow, enabling attackers to forge identity claims and initiate a technician session without authentication. This vulnerability, first brought to light by Horizon3.ai, affects servers configured with generic OIDC or Azure AD OIDC, and stems from improper validation of IdP assertions within SimpleHelp.

According to Zach Hanley, a security researcher at Horizon3.ai, attackers can exploit this flaw to create a new ‘Technician’ user with full privileges, thus enabling them to perform sensitive management tasks, including executing scripts and accessing managed endpoints.

Deployment of TaskWeaver and Djinn Stealer

Blackpoint Cyber researchers have detailed the deployment of two new malware families, TaskWeaver and Djinn Stealer, as part of the attack strategy exploiting this vulnerability. TaskWeaver, a sophisticated Node.js loader, is utilized to establish encrypted communication channels for payload delivery, while Djinn Stealer is engineered to extract credentials from various platforms, including cloud services, development tools, and web browsers.

Djinn Stealer targets systems across multiple operating systems—Windows, macOS, and Linux—aiming to collect sensitive data such as cloud platform credentials, SSH keys, and cryptocurrency wallets.

Implications and Response

The exploitation of CVE-2026-48558 has triggered a response from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), which has added the vulnerability to its Known Exploited Vulnerabilities catalog. Federal agencies are required to address this vulnerability by July 2, 2026, to mitigate potential threats.

The attack underscores the growing trend of targeting AI-powered platforms and highlights the extensive reach of compromised systems, which can extend from cloud environments to AI tools and customer infrastructure. This emphasizes the importance of bolstering security measures to protect against such sophisticated threats.

Overall, the incident serves as a stark reminder of the critical need for robust authentication mechanisms and proactive vulnerability management to safeguard sensitive systems against emerging cyber threats.

The Hacker News Tags:authentication bypass, credential theft, CVE-2026-48558, Cybersecurity, Djinn Stealer, Malware, OIDC, RMM software, SimpleHelp, TaskWeaver

Post navigation

Previous Post: GitHub’s Advisory Database Faces Surge in Vulnerability Reports
Next Post: Chris Thompson’s Journey: From Game Hacker to Cybersecurity Pioneer

Related Posts

Security Patches Released by Over 60 Software Vendors Security Patches Released by Over 60 Software Vendors The Hacker News
Apple Enhances Security for Older iOS Devices Against Exploits Apple Enhances Security for Older iOS Devices Against Exploits The Hacker News
The State of Trusted Open Source The State of Trusted Open Source The Hacker News
How VexTrio and Affiliates Run a Global Scam Network How VexTrio and Affiliates Run a Global Scam Network The Hacker News
ServiceNow AI Agents Can Be Tricked Into Acting Against Each Other via Second-Order Prompts ServiceNow AI Agents Can Be Tricked Into Acting Against Each Other via Second-Order Prompts The Hacker News
TP-Link Patches Four Omada Gateway Flaws, Two Allow Remote Code Execution TP-Link Patches Four Omada Gateway Flaws, Two Allow Remote Code Execution The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • BlueHammer Flaw Leveraged in Recent Ransomware Assaults
  • SystemBC Malware: A Stealthy Threat to Enterprise Networks
  • Bash Vulnerabilities Threaten AI Coding Security
  • Cyber Threats Surrounding FIFA 2026: Key Insights
  • Bing Search Leads to Akira Ransomware Attack via SEO Poisoning

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • BlueHammer Flaw Leveraged in Recent Ransomware Assaults
  • SystemBC Malware: A Stealthy Threat to Enterprise Networks
  • Bash Vulnerabilities Threaten AI Coding Security
  • Cyber Threats Surrounding FIFA 2026: Key Insights
  • Bing Search Leads to Akira Ransomware Attack via SEO Poisoning

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark