Threat actors are actively exploiting two unpatched vulnerabilities in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners. The targeted attacks, first observed on October 7, have affected at least five organizations, primarily managed service providers (MSPs) and system integrators.
The vulnerabilities in question are CVE-2026-105133, an authentication bypass with a publicly available exploit, and CVE-2026-105134, which allows for OS command injection. While Ahsay initially reported these issues as fixed in AhsayCBS version 10.3.2, researchers at Huntress, a managed detection and response (MDR) company, have confirmed that the flaws also impact AhsayCBS 10.3.4, which is currently the latest version of the platform.
Attackers are chaining these two vulnerabilities, first leveraging CVE-2026-105133 to bypass authentication, then using CVE-2026-105134 to achieve code execution. Following successful exploitation, Huntress observed the attackers conducting reconnaissance, deploying Java Server Page (JSP) webshells, and installing the XMRig cryptocurrency miner.
The XMRig miner is disguised as "edge.exe" and achieves persistence through a service named "MicrosoftEdgeUpdateSvc." This service runs "msedge.exe," which Huntress identified as a modified version of the legitimate Non-Sucking Service Manager (NSSM) utility.
To evade detection, the attackers utilize a PowerShell script named "Taskgmr.ps1." This script is believed to be an AI-assisted tool designed to conceal mining activity by stopping the "MicrosoftEdgeUpdateSvc" service when Task Manager is opened and restarting it once Task Manager is closed. The script also includes functionality to terminate Task Manager at 6 p.m. local time or if it remains open for more than an hour overnight.
In one instance, the attackers also deployed the vulnerable "WinRing0x64.sys" driver. This action suggests an attempt to unlock additional hardware resources for the cryptocurrency miner, potentially to increase its efficiency.
Ahsay has not yet publicly commented on these findings or outlined plans for a patch to address the vulnerabilities in the latest version of AhsayCBS.
Until a patch becomes available, Huntress recommends that system administrators implement several mitigation strategies. These include restricting access to the AhsayCBS management interface to only trusted IP addresses. Administrators should also actively investigate their systems for any indicators of compromise (IoCs) provided by Huntress.
If a compromise is confirmed, a full restoration of the affected host from a known safe backup is advised. This is crucial because attackers may have installed additional backdoors to maintain prolonged persistence within the compromised environment. Huntress has also released four Sigma rules to assist defenders in detecting this malicious activity.






