Find notable cyber news and cases, enriched with sources, timelines, and signals.

TaskWeaver and Djinn Stealer malware delivery via abused SimpleHelp technician access

Malware Activity
First reported
Last updated
Happening score
H score 36
1 unique sources, 1 articles

Summary

Hide ▲

An abused SimpleHelp technician session led to the delivery of TaskWeaver and Djinn Stealer, turning an access flaw into malware execution on managed systems and developer machines. The activity matters because it gave the attacker a path to load payloads, fingerprint hosts, and steal high-value secrets from development environments.

Related Happenings

SimpleHelp remote management software privileged technician account creation security flaw (CVE-2026-48558)

Vulnerability
H score46 First: 15.06.2026 23:06 Last: 15.06.2026 23:06 Sources 1

How related: Tracked as CVE-2026-48558 (CVSS score of 10), the bug impacts SimpleHelp’s OpenID Connect (OIDC) authentication flow and allows a remote attacker to obtain a fully authenticated technician session.

About this happening: CVE-2026-48558 is a critical authentication bypass in SimpleHelp RMM that affects OIDC authentication and can let an unauthenticated attacker forge a token and obt...

Timeline

  1. 30.06.2026 11:43 2 articles · 15d ago

    TaskWeaver and Djinn Stealer malware delivery via abused SimpleHelp technician access

    Initial Disclosure

    An attacker first abused SimpleHelp technician access to reach managed systems and start malware delivery. The initial observed payloads were TaskWeaver and Djinn Stealer.

    Show sources