Threat actors have begun exploiting two recently disclosed vulnerabilities affecting the AhsayCBS backup utility, enabling them to gain unauthorized access to vulnerable systems and deploy malicious tools, including web shells and XMRig cryptocurrency miners. According to cybersecurity company Huntress, the campaign leverages CVE-2026-105133, an improper authentication vulnerability, together with CVE-2026-105134, an operating system command injection flaw, allowing attackers to bypass authentication and execute arbitrary commands on affected hosts. Although the vulnerabilities were assigned CVE identifiers on October 4, 2026, exploitation activity was observed only a few days later, highlighting the speed at which publicly disclosed security weaknesses can be incorporated into malicious campaigns. Huntress reported that exploitation attempts began on October 7, 2026, and by the following day at least five organizations were believed to have been affected.
Following successful access, the threat actors were observed carrying out multiple post exploitation activities designed to establish persistence and maximize the use of compromised systems. Huntress reported that affected devices were subjected to reconnaissance before web shells were deployed, enabling continued remote access. Attackers also installed XMRig cryptocurrency mining software while disguising it as the Microsoft Edge browser by naming the executable “edge.exe” to reduce suspicion during routine system monitoring. In addition, researchers identified a PowerShell script named “Taskgmr.ps1” that is downloaded using the built in certutil.exe utility and later executed to support mining operations. According to Huntress, the script appears to have been developed with assistance from an artificial intelligence tool and contains anti analysis features that pause mining activity whenever Windows Task Manager is opened. The script can also terminate Task Manager if it remains active for an extended period during a specified overnight time window, making the mining activity less noticeable to administrators.
Researchers also observed threat actors using the legitimate Windows utility certutil.exe to retrieve a known vulnerable driver, WinRing0x64.sys, into the temporary directory of compromised systems. This technique is believed to be intended to obtain kernel level access to system hardware, potentially improving mining performance while increasing the complexity of incident response efforts. Huntress further noted that although the National Vulnerability Database indicates the flaws were addressed in AhsayCBS version 10.3.4, testing has shown that this version also remains affected. As a result, the issues effectively continue to behave as zero day vulnerabilities until an updated fix becomes available. This development increases the importance of defensive measures for organizations relying on the backup platform, particularly those with internet accessible management interfaces.
With no fully effective patch currently available, security experts are recommending immediate mitigation measures to reduce the risk of compromise. Huntress advises organizations to restrict access to the AhsayCBS management interface by limiting connectivity to trusted IP addresses or requiring access through a virtual private network. Security teams are also encouraged to review their environments for indicators of compromise, including unexpected web shells, suspicious PowerShell scripts, unauthorized scheduled tasks, and mining processes impersonating legitimate applications such as Microsoft Edge. Organizations using AhsayCBS should closely monitor vendor updates for a permanent security fix while strengthening access controls and reviewing exposed services. The campaign demonstrates how quickly threat actors can adopt newly disclosed vulnerabilities and reinforces the importance of combining timely security monitoring with layered defensive measures to reduce operational risk.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.