NewsLayer

Install NewsLayer

Get the app experience — one tap from your home screen, instant loads and breaking-news alerts.

NewsLayer.com
NewsLayer PulseLIVEBTC$83,608+0.84%ETH$2,533+1.15%SOL$111.11+1.02%XRP$1.41+0.59%DOGE$0.0867+1.15%ADA$0.252+1.31%Total Cap$2.96T+0.86%Layer Index46 Neutral

Crypto

breaking

Critical vulnerabilities in AhsayCBS exploited for webshells and crypto miners

Threat actors are actively exploiting two vulnerabilities, one critical and one medium-severity, in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners. These vulnerabilities, still unpatched in some…

SC Media

Publisher

Oct 11, 2026 at 6:02 PM UTC · 1 Min. Lesezeit

Critical vulnerabilities in AhsayCBS exploited for webshells and crypto miners
Image via SC Media

Threat actors are actively exploiting two vulnerabilities, one critical and one medium-severity, in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners. These vulnerabilities, still unpatched in some versions, are being used to gain unauthorized access to systems typically managed by managed service providers and system integrators, with further coverage provided by Bleeping Computer.

The attacks chain two vulnerabilities: CVE-2026-105133, an authentication bypass with a public exploit, and CVE-2026-105134, which allows for OS command injection. Although reported as fixed in AhsayCBS 10.3.2, researchers found they also affect the latest version, 10.3.4. After bypassing authentication, attackers deploy Java Server Page (JSP) webshells and the XMRig cryptocurrency miner, disguised as edge.exe. Persistence is achieved through a service named ‘MicrosoftEdgeUpdateSvc’ running a modified copy of the Non-Sucking Service Manager (NSSM) utility. An AI-assisted PowerShell script, Taskgmr.ps1, conceals mining activity by stopping the service when Task Manager is opened and restarting it when closed. The script also terminates Task Manager at 6 p.m. or if left open overnight. In some cases, the WinRing0x64.sys driver was deployed to unlock more hardware resources for the miner. Until a patch is available, administrators are advised to restrict access to the AhsayCBS management interface to trusted IP addresses and investigate signs of compromise.

Source: Bleeping Computer

Sourced by

Originally reported by SC Media

NewsLayer coverage based on externally reported material.

The Daily Brief

The onchain economy, before your day starts.

Curated markets, onchain insights, and key headlines — delivered every weekday morning.

Weekdays · Free · ~5 minute read

0

Applause

Was this article helpful?

Article Intelligence

Topics

Sponsored

Ad
House — Advertise on NewsLayer
NewsLayerLearn more

NewsLayer Premium

Unlock deeper intelligence.

Ad-free reading, exclusive research, and real-time onchain insights.

Go Premium

Keep Reading

Ähnliche Artikel