Security · 1h ago
SimpleHelp Flaw Exploited to Deploy New TaskWeaver and Djinn Stealer Malware
Attackers are exploiting CVE-2026-48558, a critical authentication bypass in SimpleHelp with a CVSS score of 10.0, to deliver two new malware families: TaskWeaver and Djinn Stealer. The flaw allows unauthenticated attackers to compromise systems. The campaign targets organizations using SimpleHelp's remote support software.
Meridian48 take
The maximum-severity score and active exploitation underscore how quickly attackers weaponize critical vulnerabilities in widely used remote access tools.
Read the full reporting
Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer →
The Hacker News
cve-2026-48558malware-delivery