As cited
Copy frozen at (site build).
threat intel
'Djinn' Stealer Targets Cloud, AI Credentials
A malware variant known as 'Djinn' stealer is being delivered through CVE-2024-48558, a critical authentication bypass vulnerability in SimpleHelp, to harvest cloud and AI credentials from development and admin environments. The attack aims to compromise credentials that connect to broader enterprise infrastructure.
Why it matters: Development teams and administrators using SimpleHelp should patch immediately, as attackers are actively exploiting this vulnerability to steal credentials that could provide lateral movement into cloud and AI platforms across your organization.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
'Djinn' Stealer Targets Cloud, AI Credentials
A malware infostealer known as Djinn was distributed through CVE-2026-48558, a critical authentication bypass flaw in SimpleHelp, to harvest cloud and artificial intelligence (AI) service credentials. The vulnerability allows attackers to access credentials that link development and administrative environments to broader enterprise infrastructure.
Why it matters: Organizations using SimpleHelp must immediately patch CVE-2026-48558 to prevent credential theft that could compromise cloud accounts, AI services, and connected enterprise systems.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
'Djinn' Stealer Targets Cloud, AI Credentials
A malware infostealer known as Djinn was distributed through CVE-2026-48558, a critical authentication bypass flaw in SimpleHelp, to harvest cloud and artificial intelligence (AI) service credentials. The vulnerability allows attackers to access credentials that link development and administrative environments to broader enterprise infrastructure.
Why it matters: Organizations using SimpleHelp must immediately patch CVE-2026-48558 to prevent credential theft that could compromise cloud accounts, AI services, and connected enterprise systems.
- Source published
- First seen by Cybersecurity Tracker