News Date: 2026-10-09
Active attacks against AhsayCBS have placed another widely trusted administrative platform at the center of an urgent security problem. The backup management product is commonly operated by managed service providers and system integrators, giving successful intruders a potentially valuable position inside infrastructure responsible for protecting customer data.
Attackers Chain Two Vulnerabilities
The observed intrusions combine CVE-2026-105133, an authentication bypass with publicly available exploit code, and CVE-2026-105134, an operating-system command-injection weakness. Attackers first enter the management interface without valid credentials and then execute commands on the underlying server.
Although the vulnerabilities were described as corrected in AhsayCBS 10.3.2, Huntress researchers determined that version 10.3.4, the latest release available at the time of publication, was also affected. Malicious activity was detected on October 7 and involved at least five organizations.
After obtaining access, the attacker conducted reconnaissance and installed Java Server Page web shells, creating persistent channels for future control. The intruder also deployed the XMRig cryptocurrency miner under filenames and service names designed to resemble Microsoft Edge components.
Mining Activity Designed to Hide
One PowerShell component monitored the Windows Task Manager and stopped the mining service whenever the utility was opened. It restarted mining after Task Manager closed and could terminate the monitoring tool under certain time-based conditions. Researchers believe the script may have been produced with AI assistance.
This detail matters because cryptocurrency mining may be only the visible symptom. Web shells can support credential theft, data collection, lateral movement or the installation of additional malware long after the original miner has been removed.
What Administrators Should Do
- Restrict the AhsayCBS management interface to approved IP addresses.
- Review servers for unfamiliar JSP files, services and PowerShell scripts.
- Use the published indicators and Sigma detection rules to hunt for compromise.
- Rebuild affected servers from a verified clean backup rather than removing only the miner.
- Rotate credentials and secrets accessible from the management platform.
In my view, backup servers should be treated as privileged security infrastructure, not ordinary application hosts. Until a confirmed fix is available, isolating the interface and investigating existing deployments should be considered emergency work.
