Critical SimpleHelp RMM Vulnerability Exploited for Malware Delivery (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Critical SimpleHelp RMM vulnerability (CVE-2026-48558, CVSS 10) exploited
- Deployment of new malware families TaskWeaver and Djinn Stealer
- SimpleHelp patched in late May; CISA KEV entry on June 29
"Attackers exploited CVE-2026-48558 (CVSS 10) in SimpleHelp's RMM software to deploy the previously undocumented TaskWeaver and Djinn Stealer malware. By forging an OpenID Connect token, they gained full technician access and used SimpleHelp's own tools for distribution. Patches were released in late May; CISA added the vulnerability to its KEV catalog on June 29."
no comments yet.