Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge
Summary
Threat actors are actively exploiting two vulnerabilities in the AhsayCBS backup utility to gain unauthorized access to systems. These attacks involve deploying web shells and XMRig cryptocurrency miners, with one of the flaws identified as CVE-2026-105133.
IFF Assessment
FOE
The exploitation of vulnerabilities to deploy cryptocurrency miners and web shells represents a direct threat to the security and integrity of affected systems, impacting defenders.
Severity
7.3
High
Defender Context
Defenders should prioritize patching or mitigating the identified AhsayCBS vulnerabilities to prevent unauthorized access and the deployment of malicious payloads. Monitoring for signs of XMRig miners and web shells on systems running AhsayCBS is crucial for early detection of compromise.