Post
CRITICAL

Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer

· cve · vulnerability · malware

An unknown threat actor is exploiting CVE-2026-48558, a maximum-severity (CVSS 10.0) authentication bypass vulnerability in SimpleHelp’s OpenID Connect (OIDC) flow, to deliver two newly identified malware families: TaskWeaver and Djinn Stealer. Post-exploitation activity focuses on collecting credentials, SSH keys, cryptocurrency wallets, and development tooling from compromised systems. Organizations running SimpleHelp should patch immediately and check for indicators of the new malware families.