A Critical Flaw in AhsayCBS Backup Management Platform Exposes Organizations to Webshell and Crypto-Mining Attacks
Threat actors have been exploiting a critical vulnerability in the AhsayCBS backup management platform, which has left at least five organizations vulnerable to webshell deployment and cryptocurrency mining. The two unpatched flaws, tracked as CVE-2026-105133 and CVE-2026-105134, were discovered by researchers at Huntress, a managed detection and response company. These vulnerabilities are not only present in the latest version of AhsayCBS (10.3.4), but also in previous versions that have been patched, leaving users with a false sense of security.
AhsayCBS is primarily used by managed service providers (MSPs) and system integrators to manage backup operations for their clients. The malicious activity was observed on October 7, and it appears that the attackers are targeting organizations that have not yet patched their systems. By exploiting the first vulnerability, CVE-2026-105133, the attackers can bypass authentication and gain access to the AhsayCBS management interface. Once inside, they can chain this with the second vulnerability, CVE-2026-105134, which allows for OS command injection.
The attackers’ ultimate goal is not only to deploy webshells but also to mine cryptocurrency using a miner disguised as an edge.exe file. This miner persists on the host by running under a service named ‘MicrosoftEdgeUpdateSvc’, which is actually a modified version of the legitimate Non-Sucking Service Manager (NSSM) utility. To conceal their mining activity, the attackers use an AI-assisted script that terminates Task Manager at specific times or when it remains open for too long.
The extent to which these vulnerabilities are being exploited is concerning, and Huntress has provided indicators of compromise (IoCs) along with four Sigma rules to help defenders detect this activity. Until a patch is available, system administrators are advised to restrict access to the AhsayCBS management interface to trusted IP addresses only and investigate signs of compromise.
The takeaway from this incident is clear: organizations must prioritize patching their systems regularly and be aware of potential vulnerabilities in third-party software. This is especially crucial for MSPs and system integrators, who often manage multiple client environments with varying levels of security. By staying vigilant and taking proactive measures to secure their systems, organizations can minimize the risk of falling victim to these types of attacks.
In conclusion, this incident serves as a reminder that even critical vulnerabilities in widely used software can have significant consequences for organizations that fail to address them promptly. As we move forward in an increasingly complex threat landscape, it is essential for security professionals and IT administrators to stay informed about emerging threats and take proactive steps to protect their systems.
Source: Bleeping Computer — 2026-10-09