Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Exploits Target AhsayCBS to Deploy Crypto Miners

Exploits Target AhsayCBS to Deploy Crypto Miners

Posted on October 9, 2026 By CWS

Cybersecurity experts have identified a concerning trend in which attackers are exploiting vulnerabilities in the AhsayCBS backup utility to gain control of systems and deploy cryptocurrency miners. These flaws, recently disclosed, have allowed threat actors to install web shells and XMRig miners that are cleverly disguised as Microsoft Edge.

Details of Vulnerabilities

The identified vulnerabilities, CVE-2026-105133 and CVE-2026-105134, carry CVSS scores of 5.5 and 9.3, respectively. The first involves improper authentication in the checkSysPwd() function, while the second allows for operating system command injection in the Replication Receiver component. Together, these flaws enable remote attackers to bypass authentication protocols and execute arbitrary commands.

Discovered on October 4, 2026, these vulnerabilities have been targeted since October 7, 2026, with attackers leveraging them to achieve remote code execution. As of October 8, 2026, five organizations are known to have been impacted.

Attack Methodology and Tools

Following successful exploitation, attackers conduct system reconnaissance, plant web shells, and deploy XMRig miners disguised as ‘edge.exe’ to avoid detection. A PowerShell script, ‘Taskgmr.ps1’, is utilized to facilitate these operations. This script, possibly created with AI assistance, includes anti-analysis features that halt mining if the Windows Task Manager is detected open, and it automatically closes the Task Manager after prolonged overnight activity.

Although recent advisories claim that these issues are resolved in AhsayCBS version 10.3.4, Huntress reports the vulnerabilities persist, effectively categorizing them as zero-days. In some cases, attackers have used ‘certutil.exe’ to download a vulnerable driver, aiming for kernel-level access to enhance mining efficiency.

Recommendations for Mitigation

In the absence of a comprehensive patch, limiting access to the AhsayCBS management interface is crucial. It’s recommended that organizations restrict web access to trusted IPs or implement VPN requirements. This strategy aims to prevent exploitation of the web app service, which is externally accessible on the host.

As organizations work to mitigate these threats, maintaining vigilance for signs of compromise and monitoring system activity is essential. Proactive measures will be critical in preventing unauthorized access and securing systems against future attacks.

The Hacker News Tags:AhsayCBS, Cryptojacking, Cryptomining, Cybersecurity, kernel access, Microsoft Edge, PowerShell script, remote code execution, Vulnerabilities, web shells, XMRig, zero-day

Post navigation

Previous Post: CastleStealer Malware Expands with New Browser Bypass
Next Post: Critical AnyDesk Linux Vulnerability Allows Remote Code Execution

Related Posts

INTERPOL’s Cybercrime Crackdown Nets 651 Arrests in Africa INTERPOL’s Cybercrime Crackdown Nets 651 Arrests in Africa The Hacker News
APT36 and SideCopy Target Indian Defense with RATs APT36 and SideCopy Target Indian Defense with RATs The Hacker News
Google Sues 25 Chinese Entities Over BADBOX 2.0 Botnet Affecting 10M Android Devices Google Sues 25 Chinese Entities Over BADBOX 2.0 Botnet Affecting 10M Android Devices The Hacker News
Cybersecurity Threats: DeFi Hack & AI Vulnerabilities Cybersecurity Threats: DeFi Hack & AI Vulnerabilities The Hacker News
Redis Security Flaws Lead to Critical Patches Redis Security Flaws Lead to Critical Patches The Hacker News
Discord Invite Link Hijacking Delivers AsyncRAT and Skuld Stealer Targeting Crypto Wallets Discord Invite Link Hijacking Delivers AsyncRAT and Skuld Stealer Targeting Crypto Wallets The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Autonomous AI Agents Pose New Cybersecurity Threats
  • OpenAI Dismisses Researchers Amid AI Safety Concerns
  • GitHub Action Flaw Exposes Thousands to Credential Theft
  • Critical AnyDesk Linux Vulnerability Allows Remote Code Execution
  • Exploits Target AhsayCBS to Deploy Crypto Miners

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Autonomous AI Agents Pose New Cybersecurity Threats
  • OpenAI Dismisses Researchers Amid AI Safety Concerns
  • GitHub Action Flaw Exposes Thousands to Credential Theft
  • Critical AnyDesk Linux Vulnerability Allows Remote Code Execution
  • Exploits Target AhsayCBS to Deploy Crypto Miners

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark