Unpatched backup server flaws become a path to crypto miners

Attackers are chaining two AhsayCBS bugs to plant webshells and mine cryptocurrency on exposed systems, with no vendor fix yet.

CSBadmin
2 Min Read

Attackers are actively exploiting two unpatched vulnerabilities in AhsayCBS, a backup server console popular with managed service providers, according to security firm Huntress. The flaws are being chained to reach remote code execution on exposed systems.

Tracked as CVE-2026-105133 and CVE-2026-105134, the defects let attackers manipulate function arguments to slip past authentication and inject operating-system commands. NIST flagged released exploit code on October 4, noting every version up to 10.3.2 was affected.

What Huntress found

Huntress now warns that the latest 10.3.4 release is vulnerable too, and that at least five organizations had been hit as of October 8. The second flaw is reachable through an API in the Replication Receiver component, where a random token can stand in for valid credentials.

Once inside, operators ran reconnaissance and dropped Java Server Page webshells into the application directory. They then deployed XMRig cryptominers disguised as Microsoft Edge, and added a PowerShell script that closes Task Manager whenever it stays open too long.

Persistence tricks

For persistence, the intruders created a Windows service posing as a Microsoft Edge Update task. It launches a renamed copy of the legitimate NSSM utility as msedge.exe with System privileges, so the miner restarts after a crash or reboot.

One attack also loaded WinRing0x64.sys, a signed but vulnerable kernel driver, to give the miner kernel-level access.

Mitigation

No vendor patch exists yet. Huntress advises restricting the AhsayCBS management interface to trusted IPs or a VPN, limiting it to the host’s local service, and hunting for signs of compromise in the meantime.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.