Security Briefing | June 30, 2026 - CVSS 10.0 SimpleHelp Flaw Deploys New Malware, Ransomware Gangs Hit Windows BlueHammer, Oracle E-Business Suite Under Attack
Attackers are exploiting a maximum-severity SimpleHelp authentication bypass (CVE-2026-48558, CVSS 10.0) to deploy two previously undocumented malware families, Djinn Stealer and TaskWeaver. CISA confirms ransomware gangs are now weaponizing the Windows BlueHammer Microsoft Defender privilege escalation flaw. Meanwhile, a critical Oracle E-Business Suite vulnerability (CVE-2026-46817, CVSS 9.8) is being actively exploited to take over Oracle Payments instances without authentication.
By EACA Summit Content Team

1. Critical SimpleHelp Flaw Exploited to Deploy Djinn Stealer and TaskWeaver Malware
Attackers are actively exploiting CVE-2026-48558, a maximum-severity authentication bypass vulnerability in SimpleHelp (CVSS 10.0), to deliver two previously undocumented malware families: TaskWeaver and Djinn Stealer. Djinn Stealer is a cross-platform information stealer targeting Windows, macOS, and Linux, focusing on credentials, SSH keys, cryptocurrency wallets, and development tooling.
Verified Facts
- CVE-2026-48558 is a critical authentication bypass in SimpleHelp's OpenID Connect flow
- Exploitation leads to deployment of Djinn Stealer and TaskWeaver malware
- Djinn Stealer targets credentials, SSH keys, cryptocurrency wallets, and development tools
- The threat actor is unknown but actively exploiting the vulnerability
Evidence
- CVE-2026-48558
- CVSS 10.0
- SimpleHelp advisory
Impact
Organizations using SimpleHelp should immediately apply patches and monitor for signs of Djinn Stealer or TaskWeaver, which can compromise sensitive credentials and development assets.
Confidence Level: High
The Hacker News | BleepingComputer | SecurityWeek
2. CISA Confirms Ransomware Gangs Exploiting Windows BlueHammer Flaw

CISA has confirmed that ransomware gangs are now exploiting the Microsoft Defender privilege escalation vulnerability known as BlueHammer, which was previously abused in zero-day attacks. The flaw allows attackers to escalate privileges and deploy ransomware. Organizations are urged to apply Microsoft's security updates immediately.
Verified Facts
- CISA added BlueHammer to its Known Exploited Vulnerabilities catalog
- Ransomware gangs are actively exploiting the vulnerability
- The flaw is a Microsoft Defender privilege escalation vulnerability
Evidence
- CISA advisory
- Microsoft security update
Impact
This vulnerability is being weaponized by ransomware actors, making it critical for defenders to patch Windows systems and monitor for privilege escalation attempts.
Confidence Level: High
BleepingComputer | The Hacker News
3. Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited
A critical vulnerability in Oracle E-Business Suite (CVE-2026-46817, CVSS 9.8) is being actively exploited in the wild. The flaw allows unauthenticated attackers to take over Oracle Payments instances. Defused Cyber reported exploitation, and multiple sources confirm active attacks.
Verified Facts
- CVE-2026-46817 is an improper privilege management and authentication flaw in Oracle Payments
- CVSS score 9.8
- Exploitation allows unauthenticated takeover of susceptible instances
- Active exploitation confirmed by Defused Cyber
Evidence
- CVE-2026-46817
- Oracle advisory
- Defused Cyber report
Impact
Organizations using Oracle E-Business Suite should apply the latest patches immediately and monitor for unauthorized access to Oracle Payments.
Confidence Level: High
The Hacker News | BleepingComputer | SecurityWeek
Also Noted
A malicious Chrome extension impersonating Perplexity AI has been discovered in the wild. Users should verify extension authenticity before installation and audit currently installed Chrome extensions for unauthorized additions.
All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.



