Forged Technician Logins Put RMM Fleets at Risk

A SimpleHelp server is not just a host to patch. If an attacker can forge the OIDC technician login, they get the same trusted admin channel MSPs use to reach every managed endpoint, and that turns one compromise into fleet-wide malware delivery and credential theft. Blackpoint’s report shows that abuse in the wild already moved from access to payload delivery. Attackers used the stolen technician session to push TaskWeaver and Djinn Stealer through SimpleHelp’s own file-transfer and remote-execution tools, and Djinn is built to harvest cloud, source-control, package-registry, SSH, and AI development-assistant credentials. CISA has now added CVE-2026-48558 to KEV, with a 2026-07-02 deadline, and SimpleHelp fixed the flaw in 5.5.16 and 6.0 RC2. The forward risk is downstream. If technicians manage developer or cloud accounts from the same environment, stolen tokens can outlast the patched server and carry the compromise into codebases, registries, and cloud control planes.

Part of the PlainSec briefing for 2026-06-29

Every edition of this story: Forged Technician Logins Put RMM Fleets at Risk

Sources