A maximum-severity vulnerability in SimpleHelp remote support software is being exploited in the wild right now, and the payload is ugly: credential-stealing malware with no patch lag between disclosu