Skip to main content
Cyber News & CTI Reports :: 2026-10-09 | Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto
Contact Page | Privacy Policy

2026-10-09 | Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto

1. AI Summary

Threat actors are exploiting two unpatched AhsayCBS vulnerabilities to deploy webshells and cryptocurrency miners. The attacks chain an authentication bypass with OS command injection, then use PowerShell scripts and a malicious driver to hide mining activity. Huntress recommends restricting access and investigating compromise.

2. IOCs

IOC Type Value Description Relevant MITRE ATT&CK Techniques
Filename
edge.exe
Disguised XMRig miner T1036|T1105|T1027
Filename
msedge.exe
Modified copy of NSSM used as service executable T1036|T1543.002
Filename
Taskgmr.ps1
PowerShell script to hide mining and disable Task Manager T1059.001|T1562.001
Filename
WinRing0x64.sys
Exploits CVE-2020-14979 for privilege escalation T1566.001
Service
MicrosoftEdgeUpdateSvc
Malicious service for persistence T1543.002

3. MITRE ATT&CK

Code Title
T1190 Exploit Public-Facing Application to bypass authentication
T1059.001 Command and Scripting Interpet: PowerShell - PowerShell script execution for mining and evasion
T1105 Ingress Tool Transfer - Ingress Tool Transfer of XMRig miner
T1036 Masquerading as legitimate files (edge.exe, msedge.exe)
T1505.003 Web Shell persistence via JSP webshell
T1543.002 Create or Modify System Process: Service for persistence
T1562.001 Disable Tools to hide mining activity
T1027 Obfuscated Files or Information - Obfuscated Files or Encoding (disguised miner)
T1060 Enable or Disable System Features (installing driver)
T1082 System Information Discovery during reconnaissance

4. Targets

Type Value
Sector Managed Service Providers and system integrators

5. Article Details

6. Original text

Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners. AhsayCBS is typically used by managed service providers (MSPs) and system integrators. The malicious activity was observed on October 7, and targeted at least five organizations. The two security issues exploited in attacks are tracked as CVE-2026-105133 , an authentication bypass vulnerability that has a public exploit, and CVE-2026-105134, which can be leveraged for OS command injection. Both vulnerabilities are reported as fixed in AhsayCBS 10.3.2, but researchers at managed detection and response company (MDR) Huntress found that they also affect Ahsay 10.3.4, currently the latest version. "After further investigation, Huntress has determined that Ahsay 10.3.4 is also affected by these vulnerabilities," Huntress says in an update today. In the observed attacks, the threat actor chained the two vulnerabilities, CVE-2026-105133 first to bypass authentication and then CVE-2026-105134 for code execution. After gaining access, Huntress observed the attacker perform reconnaissance, deploy Java Server Page (JSP) webshells, and download the XMRig miner disguised as

edge.exe
. The miner persists on the host via a service named ‘
MicrosoftEdgeUpdateSvc
,’ which runs ms
edge.exe
, identified by Huntress as a modified copy of the legitimate Non-Sucking Service Manager (NSSM) utility. A PowerShell file (
Taskgmr.ps1
) that Huntress believes to be an AI-assisted script conceals mining activity by stopping the service when Task Manager opens and restarting it when Task Manager closes. The script also terminates Task Manager at 6 p.m. local time or if it remains open for more than an hour overnight. In one case, the attacker also deployed the vulnerable
WinRing0x64.sys
driver, likely in an attempt to unlock more hardware resources for the miner.

BleepingComputer has contacted AhsayCBS to ask about its plans to fix the two flaws, but we have not heard back as of publication. Until a patch is available, Huntress recommends that system administrators restrict access to the AhsayCBS management interface to trusted IP addresses only, and investigate signs of compromise. If a compromise is confirmed, administrators should perform a full restore of the host from a safe backup, because the attacker may have installed additional backdoors for prolonged persistence. Huntress has also provided indicators of compromise (IoCs) for this activity, along with four Sigma rules to help defenders detect it. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat