SimpleHelp is a tool tracked across 18 threat clusters and 34 intelligence report mentions on ThreatCluster. First observed November 3, 2025; most recent activity July 13, 2026.
On April 24, 2026, CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog. The affected products include SimpleHelp remote management software, Samsung MagicINFO 9 Server, and…
In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular…
A maximum-severity vulnerability in SimpleHelp's RMM software, tracked as CVE-2026-48558, has been exploited to deliver two new malware families: TaskWeaver and Djinn Stealer. The flaw allows unauthenticated attackers…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified a critical authentication bypass vulnerability in SimpleHelp, tracked as CVE-2026-48558, which is actively being exploited. This flaw…
A phishing campaign known as VENOMOUS#HELPER has affected over 80 organizations, primarily in the US, Western Europe, and Latin America. Attackers are utilizing legitimate remote monitoring and management (RMM) tools,…
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
A misconfigured server in Budapest has exposed a phishing operation targeting Microsoft 365 users. The server was running a Python HTTP server with directory listing enabled, allowing access to phishing configurations…
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
In 2025, ransomware groups Medusa and DragonForce targeted UK organizations by exploiting three critical vulnerabilities in the SimpleHelp Remote Monitoring and Management platform. These vulnerabilities…
In 2025, ransomware groups Medusa and DragonForce targeted UK organizations by exploiting vulnerabilities in the SimpleHelp Remote Monitoring and Management platform. They leveraged three critical vulnerabilities…