Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Exploits Target AhsayCBS to Deploy Crypto Miners

Exploits Target AhsayCBS to Deploy Crypto Miners

Posted on October 9, 2026 By CWS

Cybersecurity experts have identified a concerning trend in which attackers are exploiting vulnerabilities in the AhsayCBS backup utility to gain control of systems and deploy cryptocurrency miners. These flaws, recently disclosed, have allowed threat actors to install web shells and XMRig miners that are cleverly disguised as Microsoft Edge.

Details of Vulnerabilities

The identified vulnerabilities, CVE-2026-105133 and CVE-2026-105134, carry CVSS scores of 5.5 and 9.3, respectively. The first involves improper authentication in the checkSysPwd() function, while the second allows for operating system command injection in the Replication Receiver component. Together, these flaws enable remote attackers to bypass authentication protocols and execute arbitrary commands.

Discovered on October 4, 2026, these vulnerabilities have been targeted since October 7, 2026, with attackers leveraging them to achieve remote code execution. As of October 8, 2026, five organizations are known to have been impacted.

Attack Methodology and Tools

Following successful exploitation, attackers conduct system reconnaissance, plant web shells, and deploy XMRig miners disguised as ‘edge.exe’ to avoid detection. A PowerShell script, ‘Taskgmr.ps1’, is utilized to facilitate these operations. This script, possibly created with AI assistance, includes anti-analysis features that halt mining if the Windows Task Manager is detected open, and it automatically closes the Task Manager after prolonged overnight activity.

Although recent advisories claim that these issues are resolved in AhsayCBS version 10.3.4, Huntress reports the vulnerabilities persist, effectively categorizing them as zero-days. In some cases, attackers have used ‘certutil.exe’ to download a vulnerable driver, aiming for kernel-level access to enhance mining efficiency.

Recommendations for Mitigation

In the absence of a comprehensive patch, limiting access to the AhsayCBS management interface is crucial. It’s recommended that organizations restrict web access to trusted IPs or implement VPN requirements. This strategy aims to prevent exploitation of the web app service, which is externally accessible on the host.

As organizations work to mitigate these threats, maintaining vigilance for signs of compromise and monitoring system activity is essential. Proactive measures will be critical in preventing unauthorized access and securing systems against future attacks.

The Hacker News Tags:AhsayCBS, Cryptojacking, Cryptomining, Cybersecurity, kernel access, Microsoft Edge, PowerShell script, remote code execution, Vulnerabilities, web shells, XMRig, zero-day

Post navigation

Previous Post: CastleStealer Malware Expands with New Browser Bypass
Next Post: Critical AnyDesk Linux Vulnerability Allows Remote Code Execution

Related Posts

GitHub Breach Linked to Malicious VS Code Extension GitHub Breach Linked to Malicious VS Code Extension The Hacker News
Understanding Magecart Threats in Web Supply Chains Understanding Magecart Threats in Web Supply Chains The Hacker News
Now-Patched Fortinet FortiWeb Flaw Exploited in Attacks to Create Admin Accounts Now-Patched Fortinet FortiWeb Flaw Exploited in Attacks to Create Admin Accounts The Hacker News
Chinese Hackers Exploit Ivanti CSA Zero-Days in Attacks on French Government, Telecoms Chinese Hackers Exploit Ivanti CSA Zero-Days in Attacks on French Government, Telecoms The Hacker News
AI-Driven Exploitation Challenges Vulnerability Management AI-Driven Exploitation Challenges Vulnerability Management The Hacker News
Two Distinct Botnets Exploit Wazuh Server Vulnerability to Launch Mirai-Based Attacks Two Distinct Botnets Exploit Wazuh Server Vulnerability to Launch Mirai-Based Attacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical AnyDesk Linux Vulnerability Allows Remote Code Execution
  • Exploits Target AhsayCBS to Deploy Crypto Miners
  • CastleStealer Malware Expands with New Browser Bypass
  • FBI Nabs Suspect Linked to ShinyHunters Hack
  • Comprehensive AI Security Checklist Introduces 222 Tests

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical AnyDesk Linux Vulnerability Allows Remote Code Execution
  • Exploits Target AhsayCBS to Deploy Crypto Miners
  • CastleStealer Malware Expands with New Browser Bypass
  • FBI Nabs Suspect Linked to ShinyHunters Hack
  • Comprehensive AI Security Checklist Introduces 222 Tests

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark