threat-intel
Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer
Critical
Summary
An attacker exploited a critical vulnerability (CVE-2026-48558) in SimpleHelp’s OpenID Connect (OIDC) flow to deploy the TaskWeaver and Djinn Stealer malware. This allowed for unauthorized access to authenticated ‘Technician’ sessions, enabling the theft of sensitive data from various systems, including cloud platforms, code repositories, AI assistants, and cryptocurrency wallets. The attack highlights the growing risk of targeting AI-powered platforms for data exfiltration.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
