ZeroHour
Product

SimpleHelp

0 mentions in 7 days · 5 in 30 days · 7 total · first seen · last

Timeline

Attackers plant remote access tools on compromised PaperCut servers

Attackers chained two PaperCut NG/MF zero-days for unauthenticated access, installing SimpleHelp and AnyDesk remote access tools on compromised servers.

An ongoing campaign exploits chained zero-days CVE-2026-81578 (improper access control) and CVE-2026-82078 (unsafe dynamic class loading) in internet-facing PaperCut NG and MF Application Servers, enabling authentication bypass and arbitrary Java bytecode execution. Post-compromise activity includes user and domain enumeration, payload download from sendit.sh, and silent installation of SimpleHelp and AnyDesk for redundant remote access; Defused observed CVE-2026-81578/CVE-2026-82078 exploit activity in honeypots since August 29, including data theft via Derby database dumps. Emergency patches were released August 28 and August 30, but 47% of roughly 2,500 PaperCut installs tracked by Huntress run v23 or older, for which no patch is available.

Help Net Security · 13d agoExploit / PoC in the wildCVE-2026-81578CVE-2026-82078

SimpleHelp OpenID Connect Auth Bypass to RCE [CVE-2026-48558]

Metasploit adds a module chaining SimpleHelp OpenID Connect authentication bypass to remote code execution, tracked as CVE-2026-48558.

A commit to the Rapid7 Metasploit Framework (dee04cdb) adds an exploit module for CVE-2026-48558, an OpenID Connect authentication bypass in SimpleHelp that can be escalated to remote code execution. SimpleHelp is widely deployed remote access and remote support software, making the auth bypass a serious exposure for exposed deployments. The commit provides public exploit code but the listing does not state observed exploitation.

Attackers Exploit Critical Langflow and Rails Flaws in Credential

VulnCheck reports active exploitation of critical Langflow CVE-2026-0768 and Rails CVE-2026-66066 for credential harvesting, with detections rising to 360.

VulnCheck observed active exploitation of CVE-2026-0768 (CVSS 9.8) in Langflow and CVE-2026-66066 'KindaRails2Shell' (CVSS 9.5) in Ruby on Rails, with detections rising from 50 on August 30, 2026 to 360 by September 1. The Rails flaw allows unauthenticated arbitrary file reads, leaking secret_key_base, Rails master key, database passwords, cloud credentials and API tokens, ultimately enabling RCE; the patch still leaves the variation-key Marshal deserialization RCE gadget functional. Observed chains include a Python credential harvester with SimpleHelp remote access via CVE-2026-5027, and weaponization of CVE-2025-3248 to enlist hosts into an XMR mining botnet after disabling auditd. More than 7,100 exposed vulnerable Ruby on Rails instances and over 15,000 successful exploitation attempts across three Langflow flaws were recorded.

The Hacker News · 14d agoExploit / PoC in the wildCVE-2026-0768CVE-2026-66066CVE-2026-0769+2 CVEs

Medusa ransomware gang has hit over 500 organizations, CISA warns

FBI, CISA, and HHS warn Medusa ransomware has hit over 500 organizations across critical infrastructure since June 2021, using phishing and unpatched flaws.

An updated joint advisory from CISA, FBI, and HHS states Medusa ransomware has affected more than 500 organizations, spanning healthcare, defense, manufacturing, government, IT, financial services, education, insurance, and legal sectors. Since early 2023 Medusa has operated a ransomware-as-a-service affiliate model and buys access from initial access brokers for $100 to $1 million. Affiliates gain entry via phishing and unpatched internet-facing software, exploiting newly disclosed flaws in ScreenConnect, Fortinet EMS, Fortra GoAnywhere, and BeyondTrust within 24 hours. The group runs double extortion, giving victims 48 hours before leak-site publication, with $10,000 in cryptocurrency buying a one-day delay.

Help Net Security · 27d agoRansomware in the wild

More than 200 victims of Medusa ransomware identified over the last year, CISA says

CISA and FBI update Medusa ransomware advisory, reporting more than 500 total victims and warning the gang operationalizes newly disclosed exploits within 24 hours.

CISA and the FBI updated their March 2025 advisory, stating Medusa actors had hit more than 500 victims as of April 2026, up from 300 in 2025, with a focus on healthcare and critical infrastructure. The agencies say Medusa rapidly adopts newly announced exploits, sometimes using them up to a week before public vulnerability disclosure, but does not develop its own zero-days, preferring access obtained from unknown sources. The gang moved to an affiliate model in 2023, offers up to $1 million for exclusive initial access brokers, and uses credential stealers plus legitimate remote access tools including AnyDesk, Atera, ConnectWise and Splashtop. No new victims have appeared on its leak site since April, after the shutdown of the University of Mississippi Medical Center drew significant law enforcement attention.

The Record · 28d agoRansomware in the wild1

Storm-1175 Replaces Medusa With New StormEncryptor Ransomware

Microsoft reports China-linked ransomware group Storm-1175 switched from Medusa to a new C++ strain, StormEncryptor, likely exploiting N-able flaw CVE-2026-18577.

Microsoft Threat Intelligence reports that the financially motivated, China-linked group Storm-1175 began deploying a new ransomware strain called StormEncryptor on August 2, 2026, replacing its previous Medusa ransomware. StormEncryptor is written in C++, appends the .encrypted extension to files, and drops a !!!README_FIRST!!!.txt ransom note in each scanned directory. Microsoft assesses the group is likely exploiting CVE-2026-18577, an authentication bypass in N-able disclosed on August 2, 2026 and added to CISA's Known Exploited Vulnerabilities catalog the next day. Since 2023, Storm-1175 has exploited more than 16 vulnerabilities in products including Microsoft Exchange, Ivanti, ConnectWise ScreenConnect, JetBrains TeamCity, SimpleHelp, CrushFTP, and GoAnywhere MFT, often moving from initial access to data theft and ransomware deployment within days.

Security Affairs · Aug 13, 2026Ransomware in the wildCVE-2026-18577CVE-2026-1731CVE-2023-21529+15 CVEs

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577

N-able shipped a second N-central hotfix as attackers actively exploit authentication bypass CVE-2026-18577, attributed to ransomware group Storm-1175.

N-able released Hotfix 2 (N-central 2026.3.1.10) to counter ongoing exploitation of CVE-2026-18577, an authentication bypass that evades the patch for the earlier CVE-2026-18556; exploitation was first detected on August 1, 2026. Post-exploitation includes using the Take Control feature to reach managed endpoints, registering a Cloudflare tunnel service for persistence, creating a 'veeam' domain account, resetting admin passwords, and disabling Microsoft and Sophos security tooling. Microsoft analysts link the activity to Storm-1175, which now deploys a new StormEncryptor ransomware strain instead of Medusa, often reaching data exfiltration and ransomware within days. Sophos and Huntress expanded the IOCs and warned that partners who patched late should treat environments as potentially compromised.

Help Net Security · Aug 12, 2026Exploit / PoC in the wildCVE-2026-18577CVE-2026-185561

Related CVEs

  • Authentication Bypass and Account Takeover in N-able N-central (Incomplete Patch)
    CVE-2026-18577 is an authentication bypass (CWE-288) in N-able's N-central RMM platform caused by an incomplete patch for the earlier vulnerability CVE-2026-18556. Because the original fix can be bypassed via an alternate path or channel, a remote, unauthenticated attacker needs no privileges or user interaction, though the attack requires meeting exploit-specific conditions (high attack complexity, CVSS 4.0: 8.2 High). Successful exploitation lets the attacker bypass authentication and take over N-central accounts, gaining high-impact access to the management console with limited direct effects on downstream services. All N-central versions through 2026.3.1 are affected. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2026-08-03, EPSS estimates a 54.1% chance of exploitation within 30 days (99th percentile), and news reports say attackers kept exploiting it even as N-able shipped successive hotfixes; ransomware use is currently unknown.
    · N-able N-central all versions through 2026.3.1 (incomplete patch for CVE-2026-18556) KEVmoderate
  • Unauthenticated RCE in Langflow /api/v1/validate/code
    Langflow, an open-source visual framework for building LLM and agentic AI applications, contains a missing authentication flaw (CWE-306) in its /api/v1/validate/code endpoint. A remote attacker with network reachability to the endpoint can send crafted HTTP requests without any credentials, causing arbitrary code execution on the server. Successful exploitation yields code execution under the application's privileges, enabling data theft, backdoor installation, and, per CISA, ransomware deployment. Any running Langflow instance is affected; the tool is typically self-hosted by development teams building AI workflows, so real-world exposure depends on whether each instance is reachable from untrusted networks. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2025-05-05 with known ransomware use, EPSS assigns a 100% probability of exploitation within 30 days (100th percentile), and a public PoC is available.
    · Langflow KEV ransomware PoC ×2moderate
  • Authentication Bypass in CrushFTP File Transfer Servers (CVE-2025-31161)
    CrushFTP contains an authentication bypass (CWE-305) in its handling of the HTTP authorization header, allowing crafted header values to grant access without valid credentials. A remote, unauthenticated attacker who can reach the server's HTTP/HTTPS interface can use this flaw to authenticate as any known or guessable account, such as the built-in crushadmin user. With administrative access, the attacker can typically achieve full compromise of the file-transfer server, including access to hosted files and user accounts. Any organization running CrushFTP is affected, with internet-exposed instances at the highest risk. The flaw is being actively exploited: it was added to CISA's KEV on 2025-04-07 with known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days.
    · CrushFTP KEV ransomware PoC ×4moderate
  • Authentication Bypass via Forged OIDC Tokens in SimpleHelp
    CVE-2026-48558 is an authentication bypass (CWE-347, improper verification of cryptographic signature) in the SimpleHelp remote access/support platform's OpenID Connect (OIDC) login flow, where submitted identity tokens are accepted without verifying their signature. It is triggered when OIDC authentication is configured: a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims and obtain a fully authenticated technician session, and in some configurations this also bypasses multi-factor authentication. Related reporting describes a path from this bypass to remote code execution. Only SimpleHelp deployments using OIDC-based (e.g., SSO) authentication are affected; deployments relying on local SimpleHelp accounts are not described as affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-06-29, confirming exploitation in the wild, with a 30% EPSS probability of exploitation within 30 days and no public proof-of-concept known.
    · SimpleHelp KEVmoderate
  • Unauthenticated Admin Password Reset Bypass in SmarterTools SmarterMail
    SmarterTools SmarterMail builds prior to 9511 contain an authentication bypass (CWE-288) in the password reset API: the force-reset-password endpoint accepts anonymous requests and, when targeting a system administrator account, never verifies the existing password or requires a reset token. An unauthenticated remote attacker simply submits a target administrator username and a new password, taking over the system administrator account with no privileges or user interaction required. Because SmarterMail's system administrator role can execute operating system commands through built-in management functionality, this escalation effectively yields SYSTEM/root-level access on the underlying mail server host, making it a path to full server and network compromise. All SmarterMail deployments running builds older than 9511 are affected, with roughly 6,000+ likely vulnerable servers observed exposed to the internet. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-26 with known ransomware use (including Storm-1175 and Warlock activity), and public PoCs exist from WatchTowr and Huntress.
    · SmarterTools SmarterMail All versions prior to build 9511 KEV ransomware PoC ×2moderate
  • Authenticated Deserialization RCE in Microsoft Exchange Server (CVE-2023-21529)
    CVE-2023-21529 is a deserialization-of-untrusted-data flaw (CWE-502) in on-premises Microsoft Exchange Server that allows remote code execution. Per its CVSS vector, an attacker with valid low-privileged credentials (PR:L) sends crafted untrusted serialized data to the server over the network, requiring no user interaction. Successful exploitation yields code execution on the Exchange server, exposing mail stores and providing a foothold for lateral movement, and related coverage ties it to the fast-moving Storm-1175 ransomware operation, with ransomware use listed as known in CISA's KEV entry. Organizations running self-hosted Exchange Server are in scope; the source data does not list specific affected builds, but the fix shipped in Microsoft's February 2023 Patch Tuesday updates. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-13, EPSS estimates a 62.1% probability of exploitation within 30 days (99th percentile), and no public proof-of-concept is known.
    · Microsoft Exchange Server KEV ransomwaremass
  • Missing Authentication for Critical Function in PaperCut NG/MF Web Interface
    CVE-2026-81578 is an improper access control flaw (CWE-305) in the web management interface of PaperCut MF and PaperCut NG in which administrative requests from unauthenticated remote users trigger backend actions before access validation completes. An attacker can invoke administrative functions without logging in, allowing modification of certain system configurations. When chained with CVE-2026-82078 (unsafe dynamic class loading), the flaw has been used to achieve unauthenticated code execution. Any organization running PaperCut NG/MF, particularly servers whose web management interface is reachable from the internet or untrusted networks, is affected. The vulnerability was added to CISA KEV on 2026-08-31 and is being exploited in the wild as part of an AI-orchestrated campaign that compromised roughly 395–440 organizations.
    · PaperCut MF · PaperCut NG KEVlarge
  • Path Traversal RCE in ConnectWise ScreenConnect (CVE-2024-1708)
    ConnectWise ScreenConnect 23.9.7 and prior contain a path-traversal flaw (CWE-22, rated 8.4 high) that can allow an attacker to execute remote code or access confidential data and critical systems. Public analysis (Huntress) shows it is triggered by manipulating directory paths in the product's administrative setup wizard, and that it is typically chained with a companion authentication-bypass flaw (CVE-2024-1709) disclosed at the same time to achieve unauthenticated remote code execution on the ScreenConnect server. An attacker who compromises a ScreenConnect server gains control of the remote-access platform itself and can pivot to every endpoint that server manages, making it an efficient foothold for ransomware. Any organization running ScreenConnect 23.9.7 or earlier is affected, most commonly MSPs and IT teams that use the tool to manage client and internal machines. The flaw is being actively exploited in the wild: it is listed in CISA's Known Exploited Vulnerabilities catalog with known ransomware use, EPSS puts the 30-day exploitation probability at 95.5% (100th percentile), and recent reporting ties fast-moving exploitation to the Storm-1175 activity cluster, which drops Medusa ransomware.
    · ConnectWise ScreenConnect 23.9.7 and prior KEV ransomware PoC large
  • Unauthenticated Path Traversal File Download in SimpleHelp 5.5.7 and Earlier
    CVE-2024-57727 consists of multiple path traversal vulnerabilities (CWE-22) in SimpleHelp remote support/remote access software that affect versions 5.5.7 and earlier. Because affected request handlers do not properly validate file paths, an unauthenticated remote attacker can send crafted HTTP requests to traverse directories and download arbitrary files from the SimpleHelp server host. The attacker gains access to sensitive server configuration files containing secrets and hashed user passwords, which can support follow-on attacks such as offline password cracking and deeper compromise; ransomware operators have chained SimpleHelp flaws in double-extortion attacks, including against an MSP and its downstream customers. Any organization running SimpleHelp is affected, particularly internet-facing deployments and MSPs that use the product for remote support and access. Exploitation is confirmed in the wild: CISA added the flaw to the KEV on 2025-02-13 with known ransomware use, EPSS assigns a 95.2% probability of exploitation within 30 days, and reporting links exploitation to campaigns such as a DragonForce operator targeting an MSP and its customers and Storm-1175 ransomware activity.
    · SimpleHelp (remote support/remote access software) 5.5.7 and all earlier versions KEV ransomwaremoderate
  • Path Traversal in JetBrains TeamCity Allows Limited Admin Actions
    JetBrains TeamCity, a widely used continuous integration/continuous delivery (CI/CD) server, contains a relative path traversal vulnerability (CWE-23) in which the application fails to properly neutralize traversal sequences in file paths. An attacker who can reach the vulnerable component can supply crafted relative paths that escape the intended directory, gaining the ability to perform limited administrative actions on the TeamCity server. Any organization running an affected JetBrains TeamCity deployment, especially instances exposed to the internet or reachable by untrusted users, is potentially affected. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-20 with known ransomware use, and the EPSS model assigns it a 100% probability of exploitation within the next 30 days. No public proof-of-concept is known, but the KEV listing confirms active exploitation in the wild per CISA.
    · JetBrains TeamCity Affected as listed by CISA; the source data provides no specific affected version ranges, so verify exact affected and patched versions in JetBrains' security b KEV ransomware PoC large

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.