Vulnerabilities · 76 days ago
Forged Technician Logins Put RMM Fleets at Risk A SimpleHelp server is not just a host to patch. If an attacker can forge the OIDC technician login, they get the same trusted admin channel MSPs use to reach every managed endpoint, and that turns one compromise into fleet-wide malware delivery and credential theft.
Blackpoint’s report shows that abuse in the wild already moved from access to payload delivery. Attackers used the stolen technician session to push TaskWeaver and Djinn Stealer through SimpleHelp’s own file-transfer and remote-execution tools, and Djinn is built to harvest cloud, source-control, package-registry, SSH, and AI development-assistant credentials. CISA has now added CVE-2026-48558 to KEV, with a 2026-07-02 deadline, and SimpleHelp fixed the flaw in 5.5.16 and 6.0 RC2 .
The forward risk is downstream. If technicians manage developer or cloud accounts from the same environment, stolen tokens can outlast the patched server and carry the compromise into codebases, registries, and cloud control planes.
NVD KEV
Known exploited · CISA KEV
CVSS 10 CRITICAL: simpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. EPSS 64% (99th percentile).
CISA federal remediation date Jul 2
Timeline Sources 7 sources covering this story
Infosecurity Magazine Jun 30
Critical SimpleHelp Vulnerability Exploited For Malware Delivery
Attackers exploited a critical SimpleHelp RMM bug to deploy TaskWeaver and Djinn Stealer malware
Cybersecurity Dive Jun 30
Critical flaw in SimpleHelp exploited in attacks targeting sensitive credentials
Researchers found two previously undisclosed malware samples used to steal AI assistant tokens and other valuable secrets.
The Hacker News Jun 30
Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer
Attackers exploited SimpleHelp CVE-2026-48558 to deliver TaskWeaver and Djinn Stealer, targeting credentials across cloud, code, AI, and wallet tools.
Help Net Security Jun 30
SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558) - Help Net Security
Attackers are exploiting CVE-2026-48558, an authentication bypass in SimpleHelp RMM, to drop the Djinn Stealer malware on victim computers.
SecurityWeek Jun 30
Critical SimpleHelp Vulnerability Exploited for Malware Delivery
The threat actor is focused on collecting credentials, SSH keys, cryptocurrency wallets, and development tooling.
Dark Reading Jun 29
'Djinn' Stealer Targets Cloud, AI Credentials
The infostealer was delivered via CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp.
BleepingComputer Jun 29
Critical SimpleHelp flaw exploited to deploy new stealer malware
Hackers are exploiting a recently disclosed critical vulnerability (CVE-2026-48558) in SimpleHelp to deploy Djinn Stealer, a previously undocumented cross-platform information stealer targeting Windows, macOS, and Linux.
Entities Part of the PlainSec briefing for 2026-06-29
Editions Related stories
Vulnerabilities · 76 days ago
Forged Technician Logins Put RMM Fleets at Risk A SimpleHelp server is not just a host to patch. If an attacker can forge the OIDC technician login, they get the same trusted admin channel MSPs use to reach every managed endpoint, and that turns one compromise into fleet-wide malware delivery and credential theft.
Blackpoint’s report shows that abuse in the wild already moved from access to payload delivery. Attackers used the stolen technician session to push TaskWeaver and Djinn Stealer through SimpleHelp’s own file-transfer and remote-execution tools, and Djinn is built to harvest cloud, source-control, package-registry, SSH, and AI development-assistant credentials. CISA has now added CVE-2026-48558 to KEV, with a 2026-07-02 deadline, and SimpleHelp fixed the flaw in 5.5.16 and 6.0 RC2 .
The forward risk is downstream. If technicians manage developer or cloud accounts from the same environment, stolen tokens can outlast the patched server and carry the compromise into codebases, registries, and cloud control planes.
NVD KEV
Known exploited · CISA KEV
CVSS 10 CRITICAL: simpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. EPSS 64% (99th percentile).
CISA federal remediation date Jul 2
Timeline Sources 7 sources covering this story
Infosecurity Magazine Jun 30
Critical SimpleHelp Vulnerability Exploited For Malware Delivery
Attackers exploited a critical SimpleHelp RMM bug to deploy TaskWeaver and Djinn Stealer malware
Cybersecurity Dive Jun 30
Critical flaw in SimpleHelp exploited in attacks targeting sensitive credentials
Researchers found two previously undisclosed malware samples used to steal AI assistant tokens and other valuable secrets.
The Hacker News Jun 30
Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer
Attackers exploited SimpleHelp CVE-2026-48558 to deliver TaskWeaver and Djinn Stealer, targeting credentials across cloud, code, AI, and wallet tools.
Help Net Security Jun 30
SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558) - Help Net Security
Attackers are exploiting CVE-2026-48558, an authentication bypass in SimpleHelp RMM, to drop the Djinn Stealer malware on victim computers.
SecurityWeek Jun 30
Critical SimpleHelp Vulnerability Exploited for Malware Delivery
The threat actor is focused on collecting credentials, SSH keys, cryptocurrency wallets, and development tooling.
Dark Reading Jun 29
'Djinn' Stealer Targets Cloud, AI Credentials
The infostealer was delivered via CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp.
BleepingComputer Jun 29
Critical SimpleHelp flaw exploited to deploy new stealer malware
Hackers are exploiting a recently disclosed critical vulnerability (CVE-2026-48558) in SimpleHelp to deploy Djinn Stealer, a previously undocumented cross-platform information stealer targeting Windows, macOS, and Linux.
Entities Part of the PlainSec briefing for 2026-06-29
Editions Related stories