LIVE · cybersecurity feed
Live wire
vulnerabilitycritical

Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto

Threat actors are actively exploiting two unpatched vulnerabilities in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners. The targeted attacks, first observed on October 7, have affected at least five organizations, primarily managed service providers (MSPs) and system integrators.

ZeroDay News ·

Source: BleepingComputer

Threat actors are actively exploiting two unpatched vulnerabilities in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners. The targeted attacks, first observed on October 7, have affected at least five organizations, primarily managed service providers (MSPs) and system integrators.

The vulnerabilities in question are CVE-2026-105133, an authentication bypass with a publicly available exploit, and CVE-2026-105134, which allows for OS command injection. While Ahsay initially reported these issues as fixed in AhsayCBS version 10.3.2, researchers at Huntress, a managed detection and response (MDR) company, have confirmed that the flaws also impact AhsayCBS 10.3.4, which is currently the latest version of the platform.

Attackers are chaining these two vulnerabilities, first leveraging CVE-2026-105133 to bypass authentication, then using CVE-2026-105134 to achieve code execution. Following successful exploitation, Huntress observed the attackers conducting reconnaissance, deploying Java Server Page (JSP) webshells, and installing the XMRig cryptocurrency miner.

The XMRig miner is disguised as "edge.exe" and achieves persistence through a service named "MicrosoftEdgeUpdateSvc." This service runs "msedge.exe," which Huntress identified as a modified version of the legitimate Non-Sucking Service Manager (NSSM) utility.

To evade detection, the attackers utilize a PowerShell script named "Taskgmr.ps1." This script is believed to be an AI-assisted tool designed to conceal mining activity by stopping the "MicrosoftEdgeUpdateSvc" service when Task Manager is opened and restarting it once Task Manager is closed. The script also includes functionality to terminate Task Manager at 6 p.m. local time or if it remains open for more than an hour overnight.

In one instance, the attackers also deployed the vulnerable "WinRing0x64.sys" driver. This action suggests an attempt to unlock additional hardware resources for the cryptocurrency miner, potentially to increase its efficiency.

Ahsay has not yet publicly commented on these findings or outlined plans for a patch to address the vulnerabilities in the latest version of AhsayCBS.

Until a patch becomes available, Huntress recommends that system administrators implement several mitigation strategies. These include restricting access to the AhsayCBS management interface to only trusted IP addresses. Administrators should also actively investigate their systems for any indicators of compromise (IoCs) provided by Huntress.

If a compromise is confirmed, a full restoration of the affected host from a known safe backup is advised. This is crucial because attackers may have installed additional backdoors to maintain prolonged persistence within the compromised environment. Huntress has also released four Sigma rules to assist defenders in detecting this malicious activity.

vulnerabilitypatchcloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

FBI Arrests Founder of Ransomware Negotiation Firm

Federal agents have arrested a Canadian cybersecurity professional in Pennsylvania, linking him to an ongoing investigation into the ShinyHunters hacking group. Edward Dubrovsky, co-founder of the Canadian firm CyberSteward, was taken into custody on October 8, facing charges of conspiracy to threaten to impair the confidentiality of information with intent to extort money, and interference…

saashigh

ASOS Breach Reveals the Risks in Customer-Facing SaaS

A recent security incident involving the British online fashion retailer ASOS has brought to light the inherent risks associated with customer-facing Software-as-a-Service (SaaS) platforms. The breach reportedly showcased how the compromise of a single user identity could serve as an initial access vector, subsequently allowing attackers to achieve broad penetration into a company's internal…

patch

Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks

A new malvertising campaign, dubbed "Adception" by security researchers at Push Security, is leveraging Google Ads and Bing redirects to distribute fake Claude installers that deploy "ClickFix" attacks. The campaign was identified after researchers observed malicious Google ads targeting users searching for "claude mac."

cybersecurity

AI Fuels Cybersecurity Mergers and Acquisitions

The cybersecurity industry is currently undergoing a substantial wave of mergers and acquisitions (M&A), with 117 deals reported in the most recent quarter. A key driver behind this heightened activity appears to be the increasing integration of artificial intelligence (AI) across various sectors, leading to a broader range of companies seeking to acquire cybersecurity capabilities.

cloud

AWS AgentCore security undone by prompt requesting credentials

Researchers have identified a critical vulnerability in Amazon Bedrock AgentCore that could allow an attacker to compromise all agents within an AWS account and region by exploiting insufficient network isolation and overly permissive default IAM roles. The flaw, disclosed by Zenity Labs, centers on an attacker's ability to extract temporary AWS credentials from an agent through a single prompt.

security

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Cybersecurity researchers have reported an active credential-theft campaign leveraging GitHub Actions workflows, which has led to the compromise of tens of thousands of repositories. The campaign reportedly exploited two high-profile open-source maintainer accounts to propagate a malicious workflow into over 340 repositories directly. One notable instance involved the account of Takashi Kitao,…