Unpatched AhsayCBS Flaws Used to Deploy Webshells and Crypto Miners
Threat actors are chaining two AhsayCBS vulnerabilities to bypass authentication, execute commands, install webshells and hide XMRig mining activity on backup management servers.

Threat actors are using two still-unpatched vulnerabilities in AhsayCBS backup management servers to plant webshells and cryptocurrency miners, BleepingComputer reported, citing findings from Huntress.
The activity was observed on October 7 and had hit at least five organisations by the time Huntress documented the campaign.
AhsayCBS is commonly used by managed service providers and system integrators, which makes exposed backup management systems a higher-value foothold when they are reachable from attacker infrastructure.
The exploit chain begins with CVE-2026-105133, an authentication bypass flaw with a public exploit, before moving to CVE-2026-105134 for operating-system command injection.
Both issues had been described as fixed in AhsayCBS 10.3.2, but Huntress found that Ahsay 10.3.4, listed as the latest version, remained affected.
Once inside a target, the attacker moved from access to monetisation rather than a simple proof-of-concept.
Huntress observed reconnaissance, Java Server Page webshell deployment and delivery of the XMRig miner under the filename edge.exe.
The miner then persisted through a service named MicrosoftEdgeUpdateSvc, which ran msedge.exe.
That persistence layer borrowed from legitimate tooling.
The msedge.exe component was identified as a modified copy of Non-Sucking Service Manager, a utility often used to run applications as Windows services.
A separate PowerShell script, Taskgmr.ps1, appeared designed to hide mining activity from administrators by stopping the service when Task Manager opened and restarting it after Task Manager closed.
The evasion routine also watched the clock.
Huntress found logic that closed the Windows monitoring tool in the early evening and during long overnight inspections, a pattern that would make the mining service less visible during hands-on troubleshooting.
Another compromised environment contained WinRing0x64.sys, a vulnerable driver that may have been added to give the miner broader access to system hardware.
The incident leaves defenders in an awkward position because the newest named AhsayCBS release is also reported as affected.
Until a fixed build is available, internet-exposed AhsayCBS instances carry a practical exploitation risk: compromise can lead quickly from authentication bypass to command execution, persistence and concealed resource theft.












