Hackers exploit AhsayCBS flaws to install cryptominers
Attackers are exploiting two unpatched vulnerabilities in the AhsayCBS backup management platform to gain remote access to systems, install webshells, and deploy cryptocurrency miners disguised as Microsoft Edge services. At least five organizations have been targeted since October 7. The flaws, present even in the latest AhsayCBS version, involve authentication bypass and command injection, allowing attackers to chain exploits for full control.
- Exploited vulnerabilities are CVE-2026-105133 and CVE-2026-105134
- Attackers install webshells and XMRig cryptominers
- Malware impersonates legitimate Microsoft Edge processes
- AI-assisted scripts help evade detection and maintain persistence
- Vulnerabilities affect the latest AhsayCBS release
Sources covering this
In this story
More in Cybersecurity
Hackers hijack ccTLDs to forge Google certificates
Attackers gained control of the main domain registries for Ghana (.gh), Sierra Leone (.sl), and American Samoa (.as), allowing them to…
US offers $10M reward for alleged Hafnium hacker Zhang Yu
The US State Department has announced a reward of up to $10 million for information that could help identify or locate Zhang Yu, a…
Fraudulent Google Ads redirect users to fake Claude downloads
Hackers are using Google search ads that redirect through Bing's click-tracking system to lure users seeking Claude for Mac to install…
Red Hat and IBM remediate 400+ Java library vulnerabilities
Red Hat and IBM have addressed over 400 previously unknown vulnerabilities in widely used open source Java libraries, following the…