Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own

    October 10, 2026

    Payment fraud detection fell with newer AI in Coinbase test

    October 10, 2026

    Yemen says advancing against Houthis around key Bab al-Mandab strait

    October 10, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own
    • Payment fraud detection fell with newer AI in Coinbase test
    • Yemen says advancing against Houthis around key Bab al-Mandab strait
    • Humans Watched This Supernova Explode Nearly a Millennium Ago. Now You Can See It in High Definition
    • When the Safety Test Became the Threat: The Machine That Found Its Own Way Out
    • Bitcoin Core Developer Responds To AI & Quantum Risk
    • Crackdown reveals ‘industrial-scale’ wildlife and timber trafficking across Latin America
    • Real Madrid beat Villarreal 1-0 but Vinicius sent off for hair pull | Football
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, October 10
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 9, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers have been exploiting two unpatched vulnerabilities in the AhsayCBS backup solution for remote code execution (RCE), cybersecurity firm Huntress warns.

    A centralized cloud backup server management console developed by Ahsay Systems, AhsayCBS provides backup policy, storage, and user management and is popular among MSPs and system integrators.

    Tracked as CVE-2026-105133 and CVE-2026-105134, the exploited security defects allow attackers to manipulate arguments in certain functions of the tool to bypass authentication and inject OS commands.

    They were disclosed on October 4, when NIST warned that exploit code targeting them had been released, and that all AhsayCBS versions up to 10.3.2 were affected.

    On Thursday, Huntress warned that attackers have exploited the two flaws in the wild and that the latest AhsayCBS version, 10.3.4, is also affected.

    “Until a patch is available, we recommend restricting access to the management interface and investigating for signs of compromise,” Huntress says.

    Advertisement. Scroll to continue reading.

    According to Huntress, threat actors are chaining the two bugs to access vulnerable systems and execute arbitrary code on them. As of October 8, at least five organizations had been targeted.

    “Huntress observed threat actors exploiting the vulnerabilities to gain unauthenticated remote code execution and deploy webshells on exposed systems,” the cybersecurity firm notes.

    It also warns that CVE-2026-105134 can be exploited for unauthenticated RCE with System privileges through an API of the Replication Receiver component.

    “The API contains an authentication bypass that could allow for a random token to substitute valid credentials. After exploitation, a threat actor configured a malicious receiver and dropped a Java Server Page (JSP) webshell into the application directory served by the CBS application,” Huntress explains.

    After gaining initial access, the attackers conducted reconnaissance and deployed XMRig cryptominers disguised as Microsoft Edge. They also planted an AI-assisted PowerShell script to monitor Task Manager and terminate it if it remains open for too long.

    They also achieved persistence by creating a Windows service masquerading as Microsoft Edge Update to execute a modified copy of the legitimate NSSM utility named msedge.exe with System privileges.

    “NSSM can support other programs to ensure they stay running and restart after a crash or reboot, and threat actors in this incident likely used it to maintain persistence for edge.exe, while disguising the service-related binary as a legitimate-looking file,” Huntress notes.

    In one attack, the hackers deployed WinRing0x64.sys, a legitimate but vulnerable kernel driver that enabled the cryptocurrency miner to operate with kernel-level access.

    “Organizations should restrict AhsayCBS management interface web access, as the exploit targets the externally accessible web app service on the host. Access should be limited to trusted IP addresses only or require VPN,” Huntress recommends.

    Related: Citrix Urges Immediate Patching of Critical NetScaler Vulnerability

    Related: Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2Own

    Related: Cisco Patches a Dozen Critical Vulnerabilities

    Related: Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication

    AhsayCBS Exploited unpatched Vulnerabilities wild
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own

    GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys

    Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2Own

    US Disrupts Chinese State-Sponsored Hacking Tools

    Insider Cyber Extortion Plot Against Industrial Firm Lands Engineer in Prison

    ARTEX AI, Claude agents used in cyberattacks on South Korean banks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own

    October 10, 2026

    Payment fraud detection fell with newer AI in Coinbase test

    October 10, 2026

    Yemen says advancing against Houthis around key Bab al-Mandab strait

    October 10, 2026

    Humans Watched This Supernova Explode Nearly a Millennium Ago. Now You Can See It in High Definition

    October 10, 2026
    Latest Posts

    Trump media group racks up losses and pushes into nuclear fusion

    August 10, 2026

    Live: Russian missiles strike Kyiv, triggering fires in city centre

    August 10, 2026

    Dragon roars with record power in Faroe Islands: Minesto hits new tidal energy output milestone

    August 11, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own

    October 10, 2026

    Payment fraud detection fell with newer AI in Coinbase test

    October 10, 2026

    Yemen says advancing against Houthis around key Bab al-Mandab strait

    October 10, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.