惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 三生石上(FineUI控件)
D
DataBreaches.Net
博客园_首页
J
Java Code Geeks
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
罗磊的独立博客
腾讯CDC
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
B
Blog
D
Docker
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
A
About on SuperTechFans
博客园 - 聂微东
Stack Overflow Blog
Stack Overflow Blog
WordPress大学
WordPress大学
MyScale Blog
MyScale Blog
G
Google Developers Blog
博客园 - 司徒正美
aimingoo的专栏
aimingoo的专栏
小众软件
小众软件
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 叶小钗
M
MIT News - Artificial intelligence
Recent Announcements
Recent Announcements

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! Hackers Use Rokarolla Android Malware to Disable Google Play Protect and Control Devices UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Au...
Abinaya · 2026-06-16 · via Cyber Security News

Nearly 14,000 internet-facing SimpleHelp servers are exposed following the disclosure of a critical authentication bypass vulnerability tracked as CVE-2026-48558.

The flaw raises serious concerns for enterprises using the remote monitoring and management (RMM) platform.

Horizon3.ai identified the vulnerability through its autonomous research initiative “Sua Sponte,” which leverages AI-driven analysis to uncover exploitable flaws.

The issue affects SimpleHelp deployments configured with OpenID Connect (OIDC) authentication, including integrations with Azure Active Directory.

CVE-2026-48558 is caused by improper validation of identity provider assertions during the OIDC authentication process.

This flaw allows unauthenticated attackers to create a new “Technician” account and log in without valid credentials.

SimpleHelp Servers Exposed by Auth Bypass

Once inside, the attacker gains elevated privileges, as technician accounts can access managed endpoints, execute scripts, and perform administrative actions. Even environments protected by multi-factor authentication are not immune.

The vulnerability enables attackers to bypass MFA by registering their own authentication method during the first login, effectively nullifying this security layer.

Indicators of Compromise ( source : horizon3.ai)
Indicators of Compromise ( source : horizon3.ai)

The issue becomes exploitable in environments where OIDC authentication is enabled, a TechnicianGroup is linked to the OIDC provider, and group-authenticated logins are permitted.

These settings are commonly found in enterprise deployments, increasing the likelihood of exploitation in real-world scenarios.

To detect potential compromise, administrators should carefully review technician accounts within the SimpleHelp interface, specifically checking for unfamiliar names or email addresses.

Server logs should also be analyzed for suspicious activity, such as unauthorized technician registrations or unexpected configuration changes.

Log files stored on the host system, including those in the /opt/SimpleHelp/logs/ directory, may provide additional evidence of malicious activity.

The scale of exposure has grown significantly over the past year. Horizon3.ai reports that the number of publicly accessible SimpleHelp servers has increased from around 3,400 in early 2025 to nearly 14,000 as of June 2026.

Further analysis suggests that approximately 7.2% of these systems are configured in a way that makes them vulnerable to this authentication bypass.

Given SimpleHelp’s role in remote access and endpoint management, successful exploitation could allow attackers to move laterally across networks and compromise critical systems.

Organizations are strongly advised to apply the latest security updates released by SimpleHelp to remediate the vulnerability.

SimpleHelp offers optional settings to enhance Technician login security( source : horizon3.ai)
SimpleHelp offers optional settings to enhance Technician login security( source : horizon3.ai)

In cases where immediate patching is not possible, administrators should implement temporary controls, such as restricting technician login access based on IP address in the platform’s security settings.

The vulnerability was discovered on May 21, 2026, reported to the vendor the following day, and publicly disclosed on June 12, 2026. A patch was released on June 9, before the public advisory.

This disclosure underscores the ongoing risks associated with widely deployed RMM tools. It highlights the importance of securing authentication mechanisms, particularly when integrating with enterprise identity providers.

Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

Abinaya

Abinayahttps://cybersecuritynews.com/

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.