
New 'Djinn' Malware Steals Login Credentials from Business Tools
A new type of malware is stealing passwords from cloud services and AI tools that businesses use. It targets work accounts that could give hackers wider access.
Source
Dark Reading
Original headline: 'Djinn' Stealer Targets Cloud, AI Credentials
Plain-English summary by GetCyberRight. Read the full report at the source above.
A new malware called Djinn is targeting businesses by stealing usernames and passwords for cloud services and artificial intelligence tools. The malware gets in through a security flaw in software called SimpleHelp, which some companies use for remote computer support. Once inside, it specifically looks for credentials that connect to important business systems. This threat mainly affects people who use work computers or business accounts. If your employer uses SimpleHelp for tech support, or if you access company cloud services and AI development tools from your computer, your work credentials could be at risk. The stolen passwords could let hackers access broader company systems, potentially exposing customer data or business information.
What You Should Do Right Now:
- If you use SimpleHelp at work, alert your IT department immediately about this vulnerability (reference CVE-2026-48558 (an industry tracking number for this software flaw)).
- Change passwords for all work-related cloud services and AI tools you access.
- Enable multi-factor authentication on every work account that offers it.
- Never use your work passwords for personal accounts, and vice versa.
- Watch for any unusual login attempts or password reset emails for your work accounts. Keep your work and personal digital lives separate. Use different passwords for work and home accounts. If you work from home or use personal devices for work, talk to your employer about security policies. Make sure any remote support software on your computer is kept updated. Strong password habits and multi-factor authentication remain your best defenses against credential theft.
Curated from trusted cybersecurity sources by GetCyberRight
Source: Dark ReadingStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles

Police Now Need Warrants to Track Your Phone's Location History
A major Supreme Court ruling protects your family's privacy by requiring warrants before police can access geofence location data from tech companies.
3 min read
New 'Djinn' Hacking Tool Targets Business Cloud Accounts
Hackers are using a new tool to steal cloud and AI system login credentials from businesses through a flaw in remote support software called SimpleHelp.
2 min readNissan Employee Data Breach: What Workers and Families Need to Know
A zero-day attack on Nissan's Oracle software exposed employee data. Here's what affected workers should do right now to protect themselves.
4 min readOracle Software Flaw Exposes Nissan and Insurance Worker Data
A hacking group exploited an unpatched Oracle PeopleSoft vulnerability to steal employee information from Nissan and a major insurance organization.
3 min read