Select a theme from the list.
Insights

From our experts

Latest
Microsoft Urges Enterprises to Test the Certificate Systems Needed for a Post-Quantum FutureTP-Link Faces Expanding State Lawsuits Over Router Security and China DisclosuresBackup Control Plane Under Fire as Unpatched AhsayCBS Flaws Face Active ExploitationMatchBoil Evolves Into a Stealthier Espionage Tool Against Ukraine's Essential IndustriesFBI Domain Seizures Cut Into Flax Typhoon's Global Hacking PlatformActive Directory Defenses Face an 11-Hour Race to Protect Tier 0Southern Company Portal Breach Exposes 400,000 Utility AccountsRegistry Hijacks Expose a Dangerous Weak Link Beneath HTTPS TrustRansomware Recovery CEO Accused of Hiding Millions in Secret PaymentsAlleged Ploutus Developer Arrested as ATM Jackpotting Crackdown Reaches Malware LeadershipRogue AI Agents Tested Wikimedia's Boundaries and Tried to Turn Web Tools Into ProxiesPwn2Own Researchers Break 32 Zero-Days Across Phones, AI Systems and Smart DevicesMicrosoft Urges Enterprises to Test the Certificate Systems Needed for a Post-Quantum FutureTP-Link Faces Expanding State Lawsuits Over Router Security and China DisclosuresBackup Control Plane Under Fire as Unpatched AhsayCBS Flaws Face Active ExploitationMatchBoil Evolves Into a Stealthier Espionage Tool Against Ukraine's Essential IndustriesFBI Domain Seizures Cut Into Flax Typhoon's Global Hacking PlatformActive Directory Defenses Face an 11-Hour Race to Protect Tier 0Southern Company Portal Breach Exposes 400,000 Utility AccountsRegistry Hijacks Expose a Dangerous Weak Link Beneath HTTPS TrustRansomware Recovery CEO Accused of Hiding Millions in Secret PaymentsAlleged Ploutus Developer Arrested as ATM Jackpotting Crackdown Reaches Malware LeadershipRogue AI Agents Tested Wikimedia's Boundaries and Tried to Turn Web Tools Into ProxiesPwn2Own Researchers Break 32 Zero-Days Across Phones, AI Systems and Smart Devices
Security Insight

Backup Control Plane Under Fire as Unpatched AhsayCBS Flaws Face Active Exploitation

Backup Control Plane Under Fire as Unpatched AhsayCBS Flaws Face Active Exploitation
Photo by Negative Space on Pexels

Attackers are chaining two vulnerabilities in the AhsayCBS backup management platform to bypass authentication, execute commands and install persistent web shells and cryptocurrency miners. Researchers found that the latest available version remains vulnerable, leaving managed service providers and system integrators dependent on access restrictions, monitoring and incident-response measures while awaiting an effective patch.

News Date: 2026-10-09

Active attacks against AhsayCBS have placed another widely trusted administrative platform at the center of an urgent security problem. The backup management product is commonly operated by managed service providers and system integrators, giving successful intruders a potentially valuable position inside infrastructure responsible for protecting customer data.

Attackers Chain Two Vulnerabilities

The observed intrusions combine CVE-2026-105133, an authentication bypass with publicly available exploit code, and CVE-2026-105134, an operating-system command-injection weakness. Attackers first enter the management interface without valid credentials and then execute commands on the underlying server.

Although the vulnerabilities were described as corrected in AhsayCBS 10.3.2, Huntress researchers determined that version 10.3.4, the latest release available at the time of publication, was also affected. Malicious activity was detected on October 7 and involved at least five organizations.

After obtaining access, the attacker conducted reconnaissance and installed Java Server Page web shells, creating persistent channels for future control. The intruder also deployed the XMRig cryptocurrency miner under filenames and service names designed to resemble Microsoft Edge components.

Mining Activity Designed to Hide

One PowerShell component monitored the Windows Task Manager and stopped the mining service whenever the utility was opened. It restarted mining after Task Manager closed and could terminate the monitoring tool under certain time-based conditions. Researchers believe the script may have been produced with AI assistance.

This detail matters because cryptocurrency mining may be only the visible symptom. Web shells can support credential theft, data collection, lateral movement or the installation of additional malware long after the original miner has been removed.

What Administrators Should Do

  • Restrict the AhsayCBS management interface to approved IP addresses.
  • Review servers for unfamiliar JSP files, services and PowerShell scripts.
  • Use the published indicators and Sigma detection rules to hunt for compromise.
  • Rebuild affected servers from a verified clean backup rather than removing only the miner.
  • Rotate credentials and secrets accessible from the management platform.

In my view, backup servers should be treated as privileged security infrastructure, not ordinary application hosts. Until a confirmed fix is available, isolating the interface and investigating existing deployments should be considered emergency work.

Talk to our team →

Latest

Microsoft Urges Enterprises to Test the Certificate Systems Needed for a Post-Quantum FutureOct 10, 2026TP-Link Faces Expanding State Lawsuits Over Router Security and China DisclosuresOct 10, 2026Backup Control Plane Under Fire as Unpatched AhsayCBS Flaws Face Active ExploitationOct 10, 2026MatchBoil Evolves Into a Stealthier Espionage Tool Against Ukraine's Essential IndustriesOct 9, 2026FBI Domain Seizures Cut Into Flax Typhoon's Global Hacking PlatformOct 9, 2026Active Directory Defenses Face an 11-Hour Race to Protect Tier 0Oct 9, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication4Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path5Global CMS Exploitation Wave Plants Webshells on Business Websites6Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards