Post
CRITICAL

Djinn Stealer Exploits Critical SimpleHelp Auth Bypass to Steal Cloud and AI Credentials

· vulnerability · cve · malware · cloud-security

A new infostealer dubbed Djinn is being delivered through CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp remote support software. The malware targets credentials linking development and admin environments to broader enterprise systems, including cloud, AI, SSH, and cryptocurrency wallet credentials. Because SimpleHelp is widely used for remote IT support, a compromised instance can provide a foothold into both engineering and production environments. Organizations running SimpleHelp should patch immediately and rotate credentials accessible from affected hosts.