AUTO-UPDATED

Week in review: SimpleHelp vulnerability exploited, Oracle EBS Payments flaw under attack

Recent cybersecurity reports highlight active exploitation of SimpleHelp and Oracle E-Business Suite vulnerabilities, alongside growing security concerns regarding the rapid integration of AI features into enterprise software products.

Key Points

  • Attackers are actively exploiting a critical authentication bypass vulnerability (CVE-2026-48558) in SimpleHelp RMM to deploy the Djinn Stealer malware.
  • A critical flaw in the Oracle E-Business Suite Payments module (CVE-2026-46817) is currently under active exploitation by threat actors.
  • Researchers identified six vulnerabilities affecting AirDrop and Quick Share protocols, impacting approximately five billion devices across major mobile and desktop operating systems.
  • Mozilla’s 0DIN team warned that AI-powered coding agents are susceptible to indirect prompt injection attacks via malicious GitHub repositories.
  • A suspected member of the Scattered Spider hacking group was extradited to the U.S. for an $8 million cryptocurrency ransom scheme.

Why it Matters

The surge in vulnerabilities linked to AI-integrated tools and widely used file-sharing protocols demonstrates that rapid feature deployment is outpacing current security testing capabilities. Organizations must prioritize patching known exploits and re-evaluating their risk models to prevent attackers from leveraging these increasingly common entry points.
Help Net Security Published by Help Net Security
Read original