
Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners.
AhsayCBS is typically used by managed service providers (MSPs) and system integrators. The malicious activity was observed on October 7, and targeted at least five organizations.
The two security issues exploited in attacks are tracked as CVE-2026-105133, an authentication bypass vulnerability that has a public exploit, and CVE-2026-105134, which can be leveraged for OS command injection.
Both vulnerabilities are reported as fixed in AhsayCBS 10.3.2, but researchers at managed detection and response company (MDR) Huntress found that they also affect Ahsay 10.3.4, currently the latest version.
"After further investigation, Huntress has determined that Ahsay 10.3.4 is also affected by these vulnerabilities," Huntress says in an update today.
In the observed attacks, the threat actor chained the two vulnerabilities, CVE-2026-105133 first to bypass authentication and then CVE-2026-105134 for code execution.
After gaining access, Huntress observed the attacker perform reconnaissance, deploy Java Server Page (JSP) webshells, and download the XMRig miner disguised as edge.exe.
The miner persists on the host via a service named ‘MicrosoftEdgeUpdateSvc,’ which runs msedge.exe, identified by Huntress as a modified copy of the legitimate Non-Sucking Service Manager (NSSM) utility.
A PowerShell file (Taskgmr.ps1) that Huntress believes to be an AI-assisted script conceals mining activity by stopping the service when Task Manager opens and restarting it when Task Manager closes.
The script also terminates Task Manager at 6 p.m. local time or if it remains open for more than an hour overnight.
In one case, the attacker also deployed the vulnerable WinRing0x64.sys driver, likely in an attempt to unlock more hardware resources for the miner.
BleepingComputer has contacted AhsayCBS to ask about its plans to fix the two flaws, but we have not heard back as of publication.
Until a patch is available, Huntress recommends that system administrators restrict access to the AhsayCBS management interface to trusted IP addresses only, and investigate signs of compromise.
If a compromise is confirmed, administrators should perform a full restore of the host from a safe backup, because the attacker may have installed additional backdoors for prolonged persistence.
Huntress has also provided indicators of compromise (IoCs) for this activity, along with four Sigma rules to help defenders detect it.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat