Skip to main content
skharoliwal
Staff
Staff
June 18, 2025

Outbreak Alert: SimpleHelp Support Software Attack

  • June 18, 2025
  • 0 replies
  • 215 views

FortiRecon Digital Risk Protection (DRP), a SaaS-based service, includes External Attack Surface Management, Brand Protection, and Adversary Centric Intelligence.

Adversary Centric Intelligence (ACI): leverages FortiGuard Threat Analysis to provide comprehensive coverage of dark web, open-source, and technical threat intelligence, including threat actor insights to enable organizations to respond proactively assess risks, respond faster to incidents, better understand their attackers, and guard assets.

The Vulnerability Intelligence Module under Adversary Centric Intelligence (ACI) provides a realistic view of the impact of the vulnerability based upon chatter and discussion of the same across various external sources such as Darkweb, social media, News / Blogs etc.

 

CVE ID CVE-2024-57728
CVE Title SimpleHelp remote support software v5.5.7 and before allows admin users...
NVD Severity HIGH
FortiRecon Severity CRITICAL
FortiRecon Score 90/100
Epss Score 0.00335
Exploited Yes
Exploited by Ransomware Group(s) Yes
Exploited by APT Group(s) No
Included in CISA KEV List No
Available working exploit(s) 0
Available POC exploit(s) 0
Darknet Mention(s) 1 (crdclub)
Telegram Mention(s) 0
FortiRecon Intelligence Reporting(s) 5 (OSINT), 1 (Technical Intelligence), 5 (FortiGuard Research)
Vendor Advisory:

 

CVE ID CVE-2024-57727
CVE Title SimpleHelp Path Traversal Vulnerability
NVD Severity HIGH
FortiRecon Severity CRITICAL
FortiRecon Score 90/100
Epss Score 0.94097
Exploited Yes
Exploited by Ransomware Group(s) Yes
Exploited by APT Group(s) No
Included in CISA KEV List Yes
Available working exploit(s) 0
Available POC exploit(s) 1
Darknet Mention(s) 0
Telegram Mention(s) 0
FortiRecon Intelligence Reporting(s) 8 (OSINT), 6 (FortiGuard Research), 2 (Technical Intelligence)
Vendor Advisory:

 

CVE ID CVE-2024-57726
CVE Title SimpleHelp remote support software v5.5.7 and before has a vulnerability...
NVD Severity CRITICAL
FortiRecon Severity CRITICAL
FortiRecon Score 90/100
Epss Score 0.00095
Exploited Yes
Exploited by Ransomware Group(s) Yes
Exploited by APT Group(s) No
Included in CISA KEV List No
Available working exploit(s) 0
Available POC exploit(s) 0
Darknet Mention(s) 1 (crdclub)
Telegram Mention(s) 0
FortiRecon Intelligence Reporting(s) 5 (OSINT), 1 (Technical Intelligence), 5 (FortiGuard Research)
Vendor Advisory:

 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!