Cyber Threat Brief — June 30 2026

⚠️ This report is AI-generated. Always validate findings.

1. SimpleHelp OIDC Auth Bypass → Djinn Stealer — CVE-2026-48558

TL;DR: CISA KEV addition June 29. CVSS 10 auth bypass in SimpleHelp RMM OIDC flow lets unauthenticated attackers forge technician sessions — actively exploited to deploy TaskWeaver loader and Djinn Stealer targeting developer credentials, AI coding assistant configs, and cloud keys.

What’s New:

  • OIDC callback handler fails to verify IdP token cryptographic signatures — forged identity token → full technician session, bypasses MFA (attacker self-registers MFA on first login)
  • Blackpoint APG observed intrusion: TaskWeaver (obfuscated JS jquery.js from temp Cloudflare domain) fingerprints host → downloads Djinn Stealer modules
  • Djinn Stealer harvests: MCP configs for AI assistants (Claude, Gemini, Codex, Cline), cloud creds (AWS/GCP/Azure), Git/SSH/Docker/Terraform/Vault secrets, npm/pip/Cargo registry tokens, crypto wallets, browser data, Linux /proc/*/environ for running process secrets
  • ~14,000 SimpleHelp servers internet-exposed; ~7.2% running vulnerable OIDC config (Horizon3.ai)
  • Federal remediation deadline: July 7 (BOD 26-04)

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
jquery.js (obfuscated TaskWeaver loader)FilenameT1059.007EDR / file creation logsHunt for jquery.js downloaded to non-web-root paths
Temp Cloudflare domain (TaskWeaver C2)InfrastructureT1102Proxy / DNSBlock *.trycloudflare.com egress from managed endpoints
Djinn Stealer TAR→GZIP→AES-256-GCM exfilBehaviorT1560.001, T1041EDR / networkAlert on tar+gzip+large outbound from RMM-managed hosts
~/.claude/mcp.json, ~/.config/github-copilot/File accessT1552.001EDR / auditdMonitor reads of AI assistant config files by non-IDE processes
/proc/<pid>/cmdline, /proc/<pid>/environFile accessT1057, T1552.001auditdAlert on bulk /proc/*/environ reads
Rogue technician accounts in SimpleHelpAccountT1136.001SimpleHelp server.logReview Administration → Technicians → Show Group Authenticated Users for unknown entries
SimpleHelp log: Registering technician login for...Log entryT1078.001SimpleHelp server.logHunt for unfamiliar technician names/emails in logs

Detection

SourceRuleGap
Splunk ESCUNoneNo SimpleHelp OIDC bypass or Djinn Stealer detection; need RMM-spawned-process + AI config file access rules
ElasticNoneNo coverage for OIDC token forgery or Djinn Stealer exfil pattern
SigmaNoneNo coverage; need rules for bulk /proc/*/environ reads and MCP config access

Sources: Horizon3.ai IOC Blog · BleepingComputer · Blackpoint Cyber · CISA KEV


Status Updates

  • CVE-2026-50656 (RoguePlanet / Windows Defender LPE): Splunk ESCU Analytics Story: RoguePlanet now published — detects ADS :WDFOO creation, MsMpEng.exe suspicious child processes, and RP_* temp directory activity via Sysmon EID 15. Still UNPATCHED zero-day. Original brief.
  • CVE-2026-43503 (DirtyClone / Linux Kernel LPE): No new artifacts since June 27. Kernel fix available in v7.1-rc7. No ITW exploitation confirmed. Original brief.