← All posts

Your IT Provider Just Handed Attackers the Keys to Your Kingdom

Here is a question most boards never think to ask: "If our managed service provider gets compromised, what happens to us?"

Last week, we got the answer. And it should keep every executive up at night.

A critical vulnerability in SimpleHelp — a remote monitoring and management tool used by thousands of IT service providers — gave attackers the ability to forge authentication tokens and walk into managed networks as if they were trusted technicians. No passwords required. No multi-factor authentication to bypass. Just a forged token that the software accepted without checking the signature. CVSS score: 10 out of 10. The worst possible rating.

That alone would be bad enough. What happened next was worse.

The Attack Chain Boards Need to Understand

Security firm Blackpoint Cyber documented the full intrusion in detail. After exploiting the SimpleHelp flaw (tracked as CVE-2026-48558), the attacker used the remote management platform itself — the same tool your IT provider uses to push updates and fix problems — to deploy two previously unknown pieces of malware across managed systems.

The first, called TaskWeaver, was a loader disguised as a legitimate JavaScript library. It established an encrypted channel back to the attacker and could deliver any payload the operator chose. The second, called Djinn Stealer, swept through compromised machines collecting cloud credentials, source code access tokens, SSH keys, cryptocurrency wallets, and — notably — credentials for AI development tools.

Think about that for a moment. A single vulnerability in a management tool gave attackers a trusted pathway into every organization that provider managed. The malicious activity looked like normal IT support operations. And the stolen credentials could provide persistent access to cloud platforms, software pipelines, and customer data long after the original compromise was contained.

Why This Is a Board-Level Problem

In my experience, most organizations treat their IT service provider relationship as a procurement decision. They negotiate the contract, check a few compliance boxes, and move on. The security of the tools that provider uses to access your environment? That rarely makes it into the board packet.

It should. Here is why.

Arctic Wolf's analysis found approximately 14,000 SimpleHelp servers exposed to the internet, with an estimated 1,000 directly vulnerable. SimpleHelp is popular among managed service providers, IT service organizations, and cloud providers — the very companies that hold administrative access to your systems. When CISA added this vulnerability to its Known Exploited Vulnerabilities catalog on June 29, they gave federal agencies just three days to patch. Three days. That timeline tells you everything you need to know about how seriously the government views this threat.

The Cyber Risk Is Business Risk framework asks three questions about any threat: What could happen? How likely is it? How bad could it get? For the SimpleHelp vulnerability, the answers are sobering. What could happen is a complete compromise of every organization a managed service provider supports — through a single entry point. How likely? The vulnerability was actively exploited in the wild before the patch was available. How bad? Blackpoint's research shows the attackers were harvesting credentials that could unlock cloud infrastructure, software supply chains, and customer environments independently of the original compromised server.

The Vendor Risk Question Your Board Should Be Asking

If your organization relies on a managed service provider — and most mid-market companies do — your board needs to ask a version of this question at the next meeting: "What remote management tools does our IT provider use to access our environment, and how do we verify they are keeping those tools patched and properly configured?"

This is not a technical question. It is a governance question. Under the SEC's cybersecurity disclosure rules, boards have formal responsibility for overseeing cyber risk. The 2026 NACD Director's Handbook on Cyber-Risk makes clear that this oversight extends to third-party risk. A breach that originates through your vendor's tools is still your breach to disclose, your customers to notify, and your reputation to repair.

The SimpleHelp incident also highlights a dimension that most vendor risk assessments miss entirely. Djinn Stealer specifically targeted credentials for AI development tools — Claude, Gemini, Codex, and others. Many development teams grant AI assistants standing access to repositories, databases, and cloud accounts. Steal those tokens, and you inherit everything the AI was trusted to reach. Your vendor risk questionnaire probably does not have a line item for that.

What to Ask Your CISO This Week

If the SimpleHelp incident does nothing else, let it prompt three concrete conversations:

First, ask about your RMM exposure. Find out what remote management tools your IT providers use to access your environment. Ask whether those tools are internet-facing or restricted behind a VPN. Ask when they were last patched. If your CISO cannot answer these questions, that gap is itself the finding.

Second, ask about credential scope. The SimpleHelp attack worked because a single compromised management server gave attackers reach across every client that provider managed. Ask your CISO what would happen if your provider's management platform were compromised tomorrow. How many of your systems would be exposed? What credentials could be harvested? How quickly would you know?

Third, ask about AI tool credentials. This is the emerging risk most organizations have not yet accounted for. If your development teams are using AI coding assistants with access to production systems, those integration tokens are now a target. Ask whether anyone has inventoried what your AI tools can reach and whether those credentials are rotated regularly.

The Uncomfortable Truth

The SimpleHelp vulnerability is not an isolated event. It is the latest in a pattern of attacks targeting the tools we trust most — remote management platforms, identity providers, software update mechanisms. Each one exploits the same fundamental dynamic: the systems designed to make IT management easier are also the systems that give attackers the broadest possible reach when compromised.

For boards and executives, the lesson is straightforward but uncomfortable. You cannot outsource accountability for cybersecurity by outsourcing IT management. The provider manages the systems. The risk stays with you.