MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-09 · via The Hacker News

AhsayCBS Bugs Abused to Install XMRig Miners and Web Shells

Image via The Hacker News
Image via The Hacker News

Threat actors are exploiting two recently disclosed vulnerabilities in the AhsayCBS backup utility. The flaws let attackers seize affected devices and deploy web shells and XMRig cryptocurrency miners while disguising the activity as Microsoft Edge. One flaw, CVE-2026-105133, is an improper authentication issue in the checkSysPwd() function.

Expanded Detail

Two recently disclosed vulnerabilities in AhsayCBS, a backup utility, are being exploited by threat actors. The flaws permit attackers to seize affected devices. Once in control, they can deploy web shells and XMRig cryptocurrency miners, and they can disguise this activity as Microsoft Edge.

One flaw is CVE-2026-105133, described as an improper authentication issue in the checkSysPwd() function. The available information does not identify affected versions, patch availability, or the scope of exploitation. The case illustrates how backup software can become a target for both remote access and resource-hijacking attacks.

Context

Organizations using AhsayCBS could face system compromise, resource abuse, or persistent access if the flaws are exploited. Because attackers may install web shells, compromised systems might remain accessible after initial intrusion. Cryptocurrency mining could consume computing resources and raise costs. The disguise as Microsoft Edge may complicate detection for defenders and users. The broader impact may extend to customers and partners whose data or services depend on affected backups.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at The Hacker News →
Related stories
Attackers exploit unpatched AhsayCBS bugs for webshells and cryptomining · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge.” Browse more stories.