Ethical Hacking News
Threat actors have been exploiting two vulnerabilities in the AhsayCBS backup utility, a widely used solution for data protection and management. The vulnerabilities, identified as CVE-2026-105133 and CVE-2026-105134, have been found to be improperly authenticated and have been chained together to allow remote attackers to bypass authentication and execute arbitrary commands on affected systems. This exploitable vulnerability has been observed to be exploited by threat actors since October 7, 2026, at 11:20 p.m. UTC, with unidentified threat actors weaponizing the flaws to achieve remote code execution on impacted hosts.
Two vulnerabilities, CVE-2026-105133 and CVE-2026-105134, have been found in the AhsayCBS backup utility, allowing remote attackers to bypass authentication and execute arbitrary commands. Threat actors have exploited the vulnerabilities since October 7, 2026, at 11:20 p.m. UTC, with the aim of achieving remote code execution on impacted hosts. The vulnerabilities have a CVSS score of 5.5 and 9.3, indicating moderate and high levels of severity, respectively. Five organizations have been estimated to have been affected by the flaws as of October 8, 2026. Threat actors are conducting reconnaissance, dropping web shells, and planting cryptocurrency miners to impersonate Microsoft Edge. The cryptocurrency miners are equipped with anti-analysis checks and can terminate the Task Manager after a certain period. The AhsayCBS software, including the latest version, has been found to be impacted, turning the vulnerabilities into zero-days. Users and organizations are advised to limit access to the management interface and implement robust security measures to prevent similar incidents.
Threat Intelligence Alert: AhsayCBS Vulnerability Exploited by Threat Actors for Cryptojacking and Web Shell Deployment
In a recent and alarming development, threat actors have been observed exploiting two vulnerabilities in the AhsayCBS backup utility, a widely used solution for data protection and management. The vulnerabilities, identified as CVE-2026-105133 and CVE-2026-105134, have been found to be improperly authenticated and have been chained together to allow remote attackers to bypass authentication and execute arbitrary commands on affected systems. This exploitable vulnerability has been observed to be exploited by threat actors since October 7, 2026, at 11:20 p.m. UTC, with unidentified threat actors weaponizing the flaws to achieve remote code execution on impacted hosts.
The vulnerability, CVE-2026-105133, is an improper authentication vulnerability in the checkSysPwd() function in the "com/ahsay/obs/api/ApiStructsAction.java" component. This vulnerability has a CVSS (Common Vulnerability Scoring System) score of 5.5, indicating a moderate level of severity. The vulnerability, CVE-2026-105134, is an operating system command injection vulnerability in the Replication Receiver component. This vulnerability has a CVSS score of 9.3, indicating a high level of severity.
According to Huntress, a cybersecurity company, exploitation efforts aimed at the two flaws began on October 7, 2026, at 11:20 p.m. UTC, with unidentified threat actors weaponizing them to achieve remote code execution on impacted hosts. As of October 8, 2026, five organizations targeted are estimated to have been affected by these flaws.
Post-exploitation, threat actors are conducting reconnaissance, dropping web shells, planting XMRig cryptominers masquerading as Microsoft Edge, and more. The cryptocurrency miners have been found to impersonate the Microsoft Edge browser by using the name "edge.exe" to fly under the radar. Also dropped is a PowerShell script ("Taskgmr.ps1") that facilitates cryptomining operations after it's launched via curl.
The script, which is suspected to be written with assistance from an artificial intelligence (AI) tool, packs in anti-analysis checks that stop the mining activity as soon as a victim opens the Windows Task Manager app. It's also configured to terminate the Task Manager at 6 p.m. if it has been left open for more than one hour overnight.
Although the advisories published in the National Vulnerability Database (NVD) state that the issues have been addressed in the latest version of the software (10.3.4), Huntress has since revealed that it's also impacted, essentially turning them to zero-days. In at least one incident, the threat actors are said to have used the built-in "certutil.exe" binary to download a legitimate-but-vulnerable driver ("WinRing0x64.sys") to the TEMP folder, likely with the aim of gaining kernel-level access to the underlying hardware and optimizing the mining process.
In the absence of a patch, users are recommended to limit access to the management interface and hunt for signs of compromise. Organizations are advised to restrict AhsayCBS management interface web access, as the exploit targets the externally accessible web app service on the host, and access should be limited to trusted IP addresses only or require VPN.
The recent discovery of the AhsayCBS vulnerability exploitation highlights the importance of staying vigilant and proactive in the face of emerging threats. As threat actors continue to evolve and improve their tactics, it's crucial that organizations take immediate action to patch vulnerabilities and implement robust security measures to prevent similar incidents from occurring.
Related Information:
https://www.ethicalhackingnews.com/articles/Threat-Intelligence-Alert-AhsayCBS-Vulnerability-Exploited-by-Threat-Actors-for-Cryptojacking-and-Web-Shell-Deployment-ehn.shtml
https://thehackernews.com/2026/10/attackers-exploit-ahsaycbs-flaws-to.html
https://nvd.nist.gov/vuln/detail/CVE-2026-105133
https://www.cvedetails.com/cve/CVE-2026-105133/
https://nvd.nist.gov/vuln/detail/CVE-2026-105134
https://www.cvedetails.com/cve/CVE-2026-105134/
Published: Fri Oct 9 11:20:33 2026 by llama3.2 3B Q4_K_M