Friday, 9 October 2026

AhsayCBS vulnerabilities let attackers plant Edge‑named crypto miner

Two recently revealed AhsayCBS flaws let attackers bypass authentication and plant web shells, then drop a cryptocurrency miner that impersonates the Edge browser.

A generic backup software console on a server

The short version

  • Two newly disclosed AhsayCBS flaws are being exploited to gain remote access, drop web shells, and install a crypto miner.
  • CVE-2026-105133 is an improper authentication flaw; CVE-2026-105134 is a command injection flaw. Attackers chain them to bypass authentication and execute commands.
  • Exploitation appears to have begun around Oct 7, 2026, with several organizations affected so far, according to Huntress.
  • The miner hides under the name edge.exe and uses a PowerShell script to manage activity and evade basic detection.
Quick read · 1 min

Two flaws in the AhsayCBS backup tool are being used to take control of systems, plant web shells, and install a crypto miner that hides as Edge. Exploitation started around Oct 7, 2026, affecting several organizations. Patch to the latest version, restrict management-console access, and monitor for edge.exe and suspicious PowerShell activity. Verify backups to ensure they haven’t been tampered with.

Why this matters: backups are a common entry point for attackers. What to do next: patch, limit exposure, monitor, and verify backup integrity.

  • Patch AhsayCBS to the latest version
  • Restrict management interfaces to VPN or trusted IPs
  • Watch for edge.exe, curl-based scripts, and unusual PowerShell

Two recently disclosed flaws in the AhsayCBS backup utility are being used to seize control of networks, plant web shells, and install a cryptocurrency miner that masquerades as the Microsoft Edge browser. Researchers say the attackers chain a login- bypass flaw with a remote command execution bug to get into vulnerable systems and run their payloads.

The two weaknesses are CVE-2026-105133, described as an improper authentication issue in a checkSysPwd() function, and CVE-2026-105134, an OS command injection vulnerability in the Replication Receiver component. When combined, these holes can let an attacker bypass login checks and issue arbitrary commands on affected machines. The CVEs were published on October 4, 2026, and activity linked to them started around Oct 7, 2026, at 11:20 p.m. UTC, with several organizations reported as impacted by Oct 8, 2026.

After gaining access, the attackers drop web shells and a crypto miner. The miner disguises itself by using the edge.exe name to blend in with legitimate processes. A PowerShell script named Taskgmr.ps1 is used to facilitate mining after the payload is launched via curl. The script also contains anti-analysis checks and can shut down the Windows Task Manager if it stays open overnight, making the attack harder to spot during routine checks.

In addition to the miner, researchers say attackers may use a legitimate-looking driver file located in TEMP to gain deeper access, potentially enabling broader control over the compromised system. Even systems that have patched to the latest version can be at risk if they are misconfigured or left open to the internet or poorly protected internal networks.

The vendor’s latest update is version 10.3.4, which includes fixes, but security firm Huntress cautions that some configurations may still be vulnerable. The broader risk isn’t just data loss; a compromised backup tool can serve as a foothold for further lateral movement and malicious activity within an organization.

01

Who’s at risk

Organizations running AhsayCBS with exposed management interfaces or backup servers accessible from the internet or poorly protected networks are the most likely targets. The exact versions affected aren’t fully spelled out in every report, but the pattern is clear: a login bypass combined with remote command execution lets attackers plant malware and move through networks.

Padlock
02

Plain-English takeaway for everyday users

If your business or organization relies on AhsayCBS for backups, patch promptly and tighten access controls around the backup console. Prefer VPN access or restrict the management interface to trusted IPs. Watch for unusual process names like edge.exe and any PowerShell activity that seems out of the ordinary, especially if it runs from TEMP. Regularly verify that your backups are intact and not being altered by an attacker.

03

What to do right now

– Update to the latest AhsayCBS version or apply the vendor’s security patch and follow any guidance from Huntress or the vendor about exposed configurations.

– Limit access to the backup management interface. Use VPNs or restrict to a narrow set of trusted IPs.

– Monitor for signs of compromise: the edge.exe process name, curl-based script launches, and unusual PowerShell commands. Set up alerts for these indicators.

– Validate backups after patching to ensure data integrity and restore capabilities remain intact.

Computer keyboard
04

Quick answers

What happened?

Attackers exploited two AhsayCBS flaws to bypass authentication and run commands, dropping web shells and a miner that pretends to be Edge.

Who is at risk?

Organizations with exposed AhsayCBS management interfaces or vulnerable backup servers should patch promptly and tighten access controls.

You're reading the quick version.