EACA Summit 2026 was July 2–3, 2026 — see you next year!
East Africa Cyber & AI Summit
All news
SECURITY BRIEFINGJUNE 30, 20263 min read

Security Briefing | June 30, 2026 - CVSS 10.0 SimpleHelp Flaw Deploys New Malware, Ransomware Gangs Hit Windows BlueHammer, Oracle E-Business Suite Under Attack

Attackers are exploiting a maximum-severity SimpleHelp authentication bypass (CVE-2026-48558, CVSS 10.0) to deploy two previously undocumented malware families, Djinn Stealer and TaskWeaver. CISA confirms ransomware gangs are now weaponizing the Windows BlueHammer Microsoft Defender privilege escalation flaw. Meanwhile, a critical Oracle E-Business Suite vulnerability (CVE-2026-46817, CVSS 9.8) is being actively exploited to take over Oracle Payments instances without authentication.

By EACA Summit Content Team

Security Briefing | June 30, 2026 - CVSS 10.0 SimpleHelp Flaw Deploys New Malware, Ransomware Gangs Hit Windows BlueHammer, Oracle E-Business Suite Under Attack

1. Critical SimpleHelp Flaw Exploited to Deploy Djinn Stealer and TaskWeaver Malware

Attackers are actively exploiting CVE-2026-48558, a maximum-severity authentication bypass vulnerability in SimpleHelp (CVSS 10.0), to deliver two previously undocumented malware families: TaskWeaver and Djinn Stealer. Djinn Stealer is a cross-platform information stealer targeting Windows, macOS, and Linux, focusing on credentials, SSH keys, cryptocurrency wallets, and development tooling.

Verified Facts

  • CVE-2026-48558 is a critical authentication bypass in SimpleHelp's OpenID Connect flow
  • Exploitation leads to deployment of Djinn Stealer and TaskWeaver malware
  • Djinn Stealer targets credentials, SSH keys, cryptocurrency wallets, and development tools
  • The threat actor is unknown but actively exploiting the vulnerability

Evidence

  • CVE-2026-48558
  • CVSS 10.0
  • SimpleHelp advisory

Impact

Organizations using SimpleHelp should immediately apply patches and monitor for signs of Djinn Stealer or TaskWeaver, which can compromise sensitive credentials and development assets.

Confidence Level: High

The Hacker News | BleepingComputer | SecurityWeek

2. CISA Confirms Ransomware Gangs Exploiting Windows BlueHammer Flaw

A server rack displaying "RANSOMWARE" in red on a monitor with flames and smoke at the base and a sticky note reading "Remember: Patch Tuesday," representing ransomware gangs exploiting a Windows privilege escalation vulnerability.

CISA has confirmed that ransomware gangs are now exploiting the Microsoft Defender privilege escalation vulnerability known as BlueHammer, which was previously abused in zero-day attacks. The flaw allows attackers to escalate privileges and deploy ransomware. Organizations are urged to apply Microsoft's security updates immediately.

Verified Facts

  • CISA added BlueHammer to its Known Exploited Vulnerabilities catalog
  • Ransomware gangs are actively exploiting the vulnerability
  • The flaw is a Microsoft Defender privilege escalation vulnerability

Evidence

  • CISA advisory
  • Microsoft security update

Impact

This vulnerability is being weaponized by ransomware actors, making it critical for defenders to patch Windows systems and monitor for privilege escalation attempts.

Confidence Level: High

BleepingComputer | The Hacker News

3. Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited

A critical vulnerability in Oracle E-Business Suite (CVE-2026-46817, CVSS 9.8) is being actively exploited in the wild. The flaw allows unauthenticated attackers to take over Oracle Payments instances. Defused Cyber reported exploitation, and multiple sources confirm active attacks.

Verified Facts

  • CVE-2026-46817 is an improper privilege management and authentication flaw in Oracle Payments
  • CVSS score 9.8
  • Exploitation allows unauthenticated takeover of susceptible instances
  • Active exploitation confirmed by Defused Cyber

Evidence

  • CVE-2026-46817
  • Oracle advisory
  • Defused Cyber report

Impact

Organizations using Oracle E-Business Suite should apply the latest patches immediately and monitor for unauthorized access to Oracle Payments.

Confidence Level: High

The Hacker News | BleepingComputer | SecurityWeek

Also Noted

A malicious Chrome extension impersonating Perplexity AI has been discovered in the wild. Users should verify extension authenticity before installation and audit currently installed Chrome extensions for unauthorized additions.

All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.

Next step

Continue with the official EACA Summit 2026 program.

View All Briefings