Reported AhsayCBS attacks targeted five organizations by October 8, 2026, after exploitation began the previous day. The attackers reportedly chained two vulnerabilities in AhsayCBS, Ahsay’s backup-management server, to run code remotely, then installed web shells and XMRig mining components disguised with Microsoft Edge-like names.

How the two AhsayCBS flaws were chained

Reported exploitation began on October 7, 2026, at 23:20:15 UTC. The two flaws played different roles: CVE-2026-105133 was the authentication-bypass step, while CVE-2026-105134 enabled operating-system command injection in AhsayCBS’s Replication Receiver. Chained together, they allowed remote code execution on affected systems.

The first vulnerability involves improper authentication in checkSysPwd. The second is command injection through the Replication Receiver. In the reported attack sequence, bypassing authentication came first; command injection then let the attackers execute code.

Edge-like names concealed the mining components

AhsayCBS attacks reportedly targeted five organizations

The reported activity affected Windows hosts. Attackers placed JSP web shells and deployed XMRig, an open-source Monero miner. The miner was named edge.exe; a modified copy of the service utility NSSM was named msedge.exe. An attacker-created Windows service called MicrosoftEdgeUpdateSvc was configured to run the renamed utility as SYSTEM.

XMRig is legitimate mining software. Its covert installation and use for unauthorized mining on compromised computers made its role in this campaign malicious.

A PowerShell script named Taskgmr.ps1 managed the mining service around Windows Task Manager: it stopped the service while Task Manager was open and restarted it when the program closed. The script could also terminate Task Manager at 18:00 local time or when it remained open for more than an hour overnight.

In one incident, attackers downloaded WinRing0x64.sys, a vulnerable driver. The driver appeared intended to give the miner kernel-level access to the host’s hardware.

Reported scale and access guidance

By October 8, five organizations had been targeted. That figure describes the reported targets by that date.

The recommended way to reduce exposure was to restrict access to the AhsayCBS management interface to trusted IP addresses or require a VPN.