[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fPrqlNaiWWg_4hemwNVoC_Cv9_lOO8BJW_6S273UMrcI":3},{"article":4,"iocs":48},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":30,"category":31,"article_tags":35},"47b9f966-b9fb-4fd1-ab56-1eb75c45da5f","Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge","attackers-exploit-ahsaycbs-flaws-to-deploy-xmrig-miners-disguised-as-microsoft-e-d33e86","Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners. Details of the flaws are below - CVE-2026-105133 (CVSS v4 score: 5.5) - An improper authentication vulnerability in the checkSysPwd() function in the \"com\u002Fahsay\u002Fobs\u002Fapi\u002FApiStructsAction.java\"","Threat actors are exploiting two vulnerabilities in the AhsayCBS backup utility to gain control of systems, deploy web shells, and install XMRig cryptocurrency miners. The miners are disguised as Microsoft Edge processes to evade detection. A PowerShell script, potentially AI-assisted, monitors and manipulates the Windows Task Manager to prevent mining activity from being discovered.","Attackers exploit AhsayCBS flaws to deploy XMRig miners disguised as Microsoft Edge.","Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge Ravie LakshmananOct 09, 2026Vulnerability \u002F Cryptojacking Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners. Details of the flaws are below - CVE-2026-105133 (CVSS v4 score: 5.5) - An improper authentication vulnerability in the checkSysPwd() function in the \"com\u002Fahsay\u002Fobs\u002Fapi\u002FApiStructsAction.java\" component. CVE-2026-105134 (CVSS v4 score: 9.3) - An operating system command injection vulnerability in the Replication Receiver component. A remote attacker could chain the two vulnerabilities to bypass authentication and execute arbitrary commands on affected systems. It's worth noting that CVE identifiers for these flaws were not published until October 4, 2026. According to Huntress, exploitation efforts aimed at the two flaws began on October 7, 2026, at 11:20 p.m. UTC, with unidentified threat actors weaponizing them to achieve remote code execution on impacted hosts. As of October 8, 2026, five organizations targeted are estimated to have been affected by these flaws. \"Post-exploitation, threat actors are conducting reconnaissance, dropping web shells, planting XMRig cryptominers masquerading as Microsoft Edge, and more,\" the cybersecurity company said. \"They also dropped what appears to be an AI-assisted PowerShell script that monitors the Windows Task Manager and shuts it down if it remains open for too long in the middle of the night.\" The cryptocurrency miners have been found to impersonate the Microsoft Edge browser by using the name \"edge.exe\" to fly under the radar. Also dropped is a PowerShell script (\"Taskgmr.ps1\") that facilitates cryptomining operations after it's launched via curl. The script, which is suspected to be written with assistance from an artificial intelligence (AI) tool, packs in anti-analysis checks that stop the mining activity as soon as a victim opens the Windows Task Manager app. It's also configured to terminate the Task Manager at 6 p.m. if it has been left open for more than one hour overnight. Although the advisories published in the National Vulnerability Database (NVD) state that the issues have been addressed in the latest version of the software (10.3.4), Huntress has since revealed that it's also impacted, essentially turning them to zero-days. In at least one incident, the threat actors are said to have used the built-in \"certutil.exe\" binary to download a legitimate-but-vulnerable driver (\"WinRing0x64.sys\") to the TEMP folder, likely with the aim of gaining kernel-level access to the underlying hardware and optimizing the mining process. In the absence of a patch, users are recommended to limit access to the management interface and hunt for signs of compromise. \"Organizations should restrict AhsayCBS management interface web access, as the exploit targets the externally accessible web app service on the host,\" Huntress said. \"Access should be limited to trusted IP addresses only or require VPN.\" Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  cryptojacking, Malware, Vulnerability, Web Security ⚡ Top Stories This Week ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members How Financial Services Companies Can Modernize Their Software Supply Chain US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access Zero Trust for AI Agents Starts With Fixing Zero Visibility ⭐ Featured Resources Discover Hidden AI Agents and Lock Down Their Access — Get a Demo The CISO Playbook for Board-Ready Security Reporting The Browser Attacks Your Security Stack Is Missing 41 Cybersecurity Courses. One Week to Level Up Your Skills","https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Fattackers-exploit-ahsaycbs-flaws-to.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEjMpbMY9pFBnt6TekKFIlEqpeqQoPBjBuhu8rYuYtU7ce5P3LTFKwlv_F_BUDzfuuMu0gRU645YStocoUQnNtS11MoEIRrfxrgPZtShsFgr8YH1VYTtjPr2l6aHPFDBYPHJKLT-fa-KqaHGSJHeiDPKzUgA12IJH5zhAHpMnoGZc5Qsz9sJhCOB_3gYHQar\u002Fs1600\u002Fedge.jpg","2026-10-09T12:47:26+00:00","2026-10-09T16:00:31.450102+00:00",8,[18,21,23,26,28],{"name":19,"type":20},"AhsayCBS","product",{"name":22,"type":20},"Microsoft Edge",{"name":24,"type":25},"PowerShell","technology",{"name":27,"type":25},"AI",{"name":29,"type":20},"WinRing0x64.sys","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":30,"icon":32,"name":33,"slug":34},null,"Malware","malware",[36,41,43],{"category":37},{"id":38,"icon":32,"name":39,"slug":40},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":42},{"id":30,"icon":32,"name":33,"slug":34},{"category":44},{"id":45,"icon":32,"name":46,"slug":47},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[49,53,56,59],{"type":50,"value":51,"context":52},"cve","CVE-2026-105133","Improper authentication vulnerability in AhsayCBS",{"type":50,"value":54,"context":55},"CVE-2026-105134","OS command injection vulnerability in AhsayCBS Replication Receiver",{"type":34,"value":57,"context":58},"XMRig","Cryptocurrency miner deployed by attackers",{"type":34,"value":60,"context":61},"Taskgmr.ps1","PowerShell script used to facilitate cryptomining operations"]