#6
The Hacker News
general
October 09, 2026 at 12:47 UTC
Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge
By [email protected] (The Hacker News)
AI Summary
Threat actors are actively exploiting two unpatched flaws in AhsayCBS backup management software — CVE-2026-105133 (CVSS v4 5.5, improper authentication in checkSysPwd()) and CVE-2026-105134 (OS command injection) — to deploy webshells and XMRig cryptocurrency miners disguised as Microsoft Edge. Backup infrastructure is a high-value target since compromise can undermine disaster recovery capabilities; administrators running AhsayCBS should isolate affected systems pending vendor patches.
Relevance score: 82.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →