Attackers are exploiting two newly disclosed vulnerabilities in AhsayCBS, the management console for Ahsay’s cloud backup software, to take over servers and quietly run cryptocurrency miners, according to researchers at Huntress.
AhsayCBS (Cloud Backup Server) is mainly used by managed service providers (MSPs) and system integrators to create users and manage backup policies for their clients. As of 8 October, Huntress had seen five organisations targeted via the flaws.
From disclosure to exploitation in three days
The two vulnerabilities, CVE-2026-105133 and CVE-2026-105134, were published to the US National Vulnerability Database (NVD) on 4 October. Huntress began seeing exploitation attempts on 7 October at 23:20 UTC.
CVE-2026-105133 is a medium-severity flaw in the checkSysPwd function that can lead to improper authentication. CVE-2026-105134 is a critical-severity vulnerability in the /rps/api/json/UpdateReceivers.do endpoint of the Replication Receiver component. It contains an authentication bypass that allows a random token to stand in for valid credentials, leading to unauthenticated remote code execution as NT AUTHORITYSYSTEM.
Attackers chained the two flaws, first bypassing authentication and then gaining code execution. They configured a malicious replication receiver and dropped a JSP webshell into the application directory served by CBS. Huntress first spotted the activity through suspicious command lines spawned by the cbssvcX64.exe service.
Versions up to 10.3.2 are affected. Version 10.3.4, released on 5 August, is not vulnerable.
A miner in disguise
Once inside, the attackers downloaded a set of payloads from an Alibaba Cloud object storage host. These included an XMRig Monero miner disguised as Microsoft Edge (edge.exe), and a modified copy of the NSSM service utility (msedge.exe). The attackers used it to run the miner as a SYSTEM-level service named MicrosoftEdgeUpdateSvc, mimicking the genuine Edge update service. The miner connected to a Monero mining pool on port 8029.
A PowerShell script, Taskgmr.ps1, was used to help the miner avoid detection. If Task Manager was opened, the script stopped the fake Edge service to hide the mining activity. It also killed Task Manager at 18:00, as well as whenever it had been left open for more than an hour overnight, based on the endpoint’s local clock rather than UTC. Huntress said the script appears to be AI-assisted, given its commented code.
In one incident, the attackers also loaded WinRing0x64.sys, a legitimate but vulnerable kernel driver. Huntress noted that attackers often use vulnerable drivers to disable endpoint security tools. In this case, loading the driver gave the miner kernel-level access to the hardware.
[Optional: approved spokesperson quote to be inserted here]
What defenders should do
Huntress is urging organisations running AhsayCBS to:
- Upgrade to version 10.3.4 immediately.
- Restrict access to the AhsayCBS management web interface to trusted IP addresses only, or require VPN access.
- Fully re-image any compromised host from a trusted backup, as attackers may have left additional backdoors.
- Deploy the Sigma detection rules and block the indicators of compromise published by Huntress, including the mining pool, payload URLs and file hashes.
Huntress said it is working with potentially affected organisations across its customer base to apply these mitigations.
Full research, including indicators of compromise and detection rules: https://www.huntress.com/blog/ahsaycbs-flaws-exploit

