MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-09 · via BleepingComputer

Attackers exploit unpatched AhsayCBS bugs for webshells and cryptomining

Image via BleepingComputer
Image via BleepingComputer

Threat actors are chaining two unpatched vulnerabilities in AhsayCBS, an authentication bypass and an OS command injection flaw, to compromise systems. Huntress observed attackers deploying JSP webshells and an XMRig miner disguised as edge.exe, with persistence through a service and a PowerShell script that hides mining activity. The flaws were reported fixed in version 10.3.2 but also affect the latest 10.3.4 release, and no patch was available at publication.

Expanded Detail

AhsayCBS is backup management software often used by managed service providers and system integrators. The exploited flaws are CVE-2026-105133, an authentication bypass with a public exploit, and CVE-2026-105134, an OS command injection issue. Although listed as fixed in 10.3.2, Huntress found both still affect 10.3.4, the newest release. Attacks observed October 7 hit at least five organizations.

After bypassing login and achieving command execution, intruders conducted reconnaissance, placed JSP webshells, and fetched XMRig renamed edge.exe. Persistence involved a service called MicrosoftEdgeUpdateSvc running a modified NSSM copy as msedge.exe. A PowerShell script, Taskgmr.ps1, allegedly AI-assisted, paused mining when Task Manager opened and stopped Task Manager at 6 p.m. or after an hour overnight. One victim also had WinRing0x64.sys deployed.

Context

Because AhsayCBS is used by MSPs and integrators, compromised instances could expose not only the provider but also downstream client systems and backup data. Attackers may use webshells and miners to consume resources, maintain access, or disrupt recovery operations. Organizations relying on affected backups could face service interruptions, higher remediation costs, and potential data-restoration challenges. Until patched, limiting management interface access and restoring from clean backups may reduce risk.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
AI Agents Emerge as a New Target for Business Email Compromise Tactics · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto.” Browse more stories.