Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AhsayCBS Flaws Actively Exploited, Urgent Action Needed

AhsayCBS Flaws Actively Exploited, Urgent Action Needed

Posted on October 9, 2026 By CWS

Cybersecurity experts are raising alarms over two critical vulnerabilities in the AhsayCBS backup solution that have been exploited for remote code execution (RCE). These vulnerabilities, identified as CVE-2026-105133 and CVE-2026-105134, have been actively targeted by threat actors, according to Huntress, a prominent cybersecurity firm.

Understanding the AhsayCBS Vulnerabilities

AhsayCBS, developed by Ahsay Systems, is widely used by managed service providers (MSPs) and system integrators for backup management. The software allows users to manage backup policies and storage effectively. However, it has recently come under scrutiny due to these unpatched security flaws that enable attackers to bypass authentication and execute unauthorized operating system commands.

The vulnerabilities were initially disclosed on October 4, with the National Institute of Standards and Technology (NIST) warning about available exploit code. All versions up to 10.3.2 were confirmed to be susceptible, and even the latest version, 10.3.4, remains vulnerable as per recent reports from Huntress.

Immediate Security Recommendations

Huntress advises organizations to take immediate precautions by restricting access to the AhsayCBS management interface. Until a patch is released, limiting access to trusted IP addresses or using a VPN is recommended to mitigate potential risks. The firm has observed multiple instances where attackers have chained these vulnerabilities to gain unauthorized access and deploy malicious webshells.

As of October 8, at least five organizations have been confirmed as targets of these exploits. The attackers utilized these flaws to execute arbitrary code, achieving unauthenticated remote code execution with system privileges through the platform’s Replication Receiver component.

Exploitation Techniques and Defensive Measures

The attackers also employed advanced techniques post-exploitation, including deploying XMRig cryptominers with kernel-level privileges. They used legitimate software, such as WinRing0x64.sys, to maintain persistence and avoid detection. Additionally, they created a Windows service disguised as Microsoft Edge Update to execute malicious scripts.

Organizations are urged to implement strict access controls and monitor their networks for signs of compromise. By limiting the exposure of the AhsayCBS management interface, companies can reduce the risk of these vulnerabilities being exploited in the wild.

In light of these developments, cybersecurity professionals emphasize the importance of regular updates and vigilance against potential threats. As the exploitation of these vulnerabilities continues, staying informed and proactive is crucial to safeguarding sensitive data.

Security Week News Tags:AhsayCBS, CVE-2026-105133, CVE-2026-105134, Cybersecurity, Exploit, Huntress, MSPs, NIST, RCE, remote code execution, security flaws, system integrators, Unpatched, Vulnerabilities, Webshell

Post navigation

Previous Post: Hackers Break Into Google Pixel 10 at Pwn2Own Contest
Next Post: MATCHBOIL Deploys Backdoor via Hidden Servers

Related Posts

AppSignal Raises  Million for Application Monitoring Solution AppSignal Raises $22 Million for Application Monitoring Solution Security Week News
Webinar Explores Designing OT SOC for Enhanced Safety Webinar Explores Designing OT SOC for Enhanced Safety Security Week News
Godfather Android Trojan Creates Sandbox on Infected Devices Godfather Android Trojan Creates Sandbox on Infected Devices Security Week News
New Insights on Optimizing KEV Catalog Usage for Security New Insights on Optimizing KEV Catalog Usage for Security Security Week News
Google Offers Up to ,000 in New AI Bug Bounty Program Google Offers Up to $20,000 in New AI Bug Bounty Program Security Week News
Companies Warned of Commvault Vulnerability Exploitation Companies Warned of Commvault Vulnerability Exploitation Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New Exploit in Telegram Desktop Allows Account Takeover
  • AI Involvement in South Korean Bank Hacks Raises Concerns
  • AI Ambitions Clash with Outdated Security Measures
  • MATCHBOIL Deploys Backdoor via Hidden Servers
  • AhsayCBS Flaws Actively Exploited, Urgent Action Needed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New Exploit in Telegram Desktop Allows Account Takeover
  • AI Involvement in South Korean Bank Hacks Raises Concerns
  • AI Ambitions Clash with Outdated Security Measures
  • MATCHBOIL Deploys Backdoor via Hidden Servers
  • AhsayCBS Flaws Actively Exploited, Urgent Action Needed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark