Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Severe SimpleHelp Flaw Used to Deploy New Malware

Severe SimpleHelp Flaw Used to Deploy New Malware

Posted on June 30, 2026 By CWS

Emerging Threat Exploits Critical SimpleHelp Vulnerability

In a concerning development, cybersecurity experts have identified an unidentified threat actor leveraging a newly discovered critical vulnerability in the SimpleHelp software to distribute two previously unknown malware strains. The vulnerability, cataloged as CVE-2026-48558, represents a severe security risk due to its ability to bypass authentication protocols, allowing unauthorized actors to gain full access to technician sessions.

Understanding the SimpleHelp Vulnerability

The flaw, characterized by a CVSS score of 10.0, exploits weaknesses in the OpenID Connect (OIDC) flow, enabling attackers to forge identity claims and initiate a technician session without authentication. This vulnerability, first brought to light by Horizon3.ai, affects servers configured with generic OIDC or Azure AD OIDC, and stems from improper validation of IdP assertions within SimpleHelp.

According to Zach Hanley, a security researcher at Horizon3.ai, attackers can exploit this flaw to create a new ‘Technician’ user with full privileges, thus enabling them to perform sensitive management tasks, including executing scripts and accessing managed endpoints.

Deployment of TaskWeaver and Djinn Stealer

Blackpoint Cyber researchers have detailed the deployment of two new malware families, TaskWeaver and Djinn Stealer, as part of the attack strategy exploiting this vulnerability. TaskWeaver, a sophisticated Node.js loader, is utilized to establish encrypted communication channels for payload delivery, while Djinn Stealer is engineered to extract credentials from various platforms, including cloud services, development tools, and web browsers.

Djinn Stealer targets systems across multiple operating systems—Windows, macOS, and Linux—aiming to collect sensitive data such as cloud platform credentials, SSH keys, and cryptocurrency wallets.

Implications and Response

The exploitation of CVE-2026-48558 has triggered a response from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), which has added the vulnerability to its Known Exploited Vulnerabilities catalog. Federal agencies are required to address this vulnerability by July 2, 2026, to mitigate potential threats.

The attack underscores the growing trend of targeting AI-powered platforms and highlights the extensive reach of compromised systems, which can extend from cloud environments to AI tools and customer infrastructure. This emphasizes the importance of bolstering security measures to protect against such sophisticated threats.

Overall, the incident serves as a stark reminder of the critical need for robust authentication mechanisms and proactive vulnerability management to safeguard sensitive systems against emerging cyber threats.

The Hacker News Tags:authentication bypass, credential theft, CVE-2026-48558, Cybersecurity, Djinn Stealer, Malware, OIDC, RMM software, SimpleHelp, TaskWeaver

Post navigation

Previous Post: GitHub’s Advisory Database Faces Surge in Vulnerability Reports
Next Post: Chris Thompson’s Journey: From Game Hacker to Cybersecurity Pioneer

Related Posts

Automation Is Redefining Pentest Delivery Automation Is Redefining Pentest Delivery The Hacker News
North Korean PurpleBravo Campaign Targeted 3,136 IP Addresses via Fake Job Interviews North Korean PurpleBravo Campaign Targeted 3,136 IP Addresses via Fake Job Interviews The Hacker News
Researchers Uncover Batavia Windows Spyware Stealing Documents from Russian Firms Researchers Uncover Batavia Windows Spyware Stealing Documents from Russian Firms The Hacker News
Windows Vulnerabilities: BitLocker Bypass and CTFMON Exploit Windows Vulnerabilities: BitLocker Bypass and CTFMON Exploit The Hacker News
AI Model Uncovers 10,000 Critical Software Flaws AI Model Uncovers 10,000 Critical Software Flaws The Hacker News
Google Warns of Active Exploitation of WinRAR Vulnerability CVE-2025-8088 Google Warns of Active Exploitation of WinRAR Vulnerability CVE-2025-8088 The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cyber Threats Surrounding FIFA 2026: Key Insights
  • Bing Search Leads to Akira Ransomware Attack via SEO Poisoning
  • Chris Thompson’s Journey: From Game Hacker to Cybersecurity Pioneer
  • Severe SimpleHelp Flaw Used to Deploy New Malware
  • GitHub’s Advisory Database Faces Surge in Vulnerability Reports

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cyber Threats Surrounding FIFA 2026: Key Insights
  • Bing Search Leads to Akira Ransomware Attack via SEO Poisoning
  • Chris Thompson’s Journey: From Game Hacker to Cybersecurity Pioneer
  • Severe SimpleHelp Flaw Used to Deploy New Malware
  • GitHub’s Advisory Database Faces Surge in Vulnerability Reports

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark