Executive Summary
In October 2026, threat actors exploited two unpatched vulnerabilities in AhsayCBS backup management platform - CVE-2026-105133 (authentication bypass) and CVE-2026-105134 (OS command injection) - to deploy webshells and cryptocurrency miners. The attackers chained these vulnerabilities to gain initial access, conduct reconnaissance, and install XMRig miners disguised as Microsoft Edge services across at least five organizations. The malware included sophisticated evasion techniques using AI-assisted PowerShell scripts that detect Task Manager activity and automatically suspend mining operations to avoid detection.
This incident highlights the growing trend of cryptomining attacks targeting unpatched enterprise software, particularly backup solutions used by managed service providers. The exploitation of critical infrastructure components like backup systems poses significant operational risks and demonstrates how attackers are increasingly using AI-enhanced tools for stealth and persistence.
Why This Matters Now
Backup infrastructure is increasingly targeted as attackers recognize its critical role in business continuity, while AI-enhanced malware tools are making attacks more sophisticated and harder to detect through traditional monitoring.
Attack Path Analysis
Threat actors exploited unpatched AhsayCBS vulnerabilities CVE-2026-105133 and CVE-2026-105134 to gain initial access through authentication bypass and command injection. After reconnaissance, attackers deployed JSP webshells for persistence and downloaded disguised XMRig cryptocurrency miners. The mining operation was concealed using AI-assisted PowerShell scripts that evaded detection by monitoring Task Manager activity. The attack resulted in unauthorized resource consumption for cryptocurrency mining across at least five targeted organizations.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited CVE-2026-105133 authentication bypass vulnerability in unpatched AhsayCBS backup management platform to gain unauthorized access
Related CVEs
CVE-2024-6062
CVSS 5.5An authentication bypass vulnerability in AhsayCBS backup management platform allows remote attackers to bypass authentication mechanisms.
Affected Products:
Ahsay Systems Corporation AhsayCBS – < 10.3.2
Exploit Status:
exploited in the wildCVE-2024-6063
CVSS 5.5An OS command injection vulnerability in AhsayCBS allows authenticated attackers to execute arbitrary commands on the underlying operating system.
Affected Products:
Ahsay Systems Corporation AhsayCBS – < 10.3.2
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Web Shell
Windows Command Shell
Windows Service
Obfuscated Files or Information
Disable or Modify Tools
Resource Hijacking
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security Vulnerabilities in System Components
Control ID: 6.3.1
NYDFS 23 NYCRR 500 – Incident Response Plan
Control ID: 500.08
DORA – Third-party Risk Management
Control ID: Article 8
CISA ZTMM 2.0 – Network Access Control
Control ID: ZT.AM-04
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21.2(a)
ISO 27001:2022 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
MSPs using AhsayCBS face critical authentication bypass and command injection vulnerabilities enabling webshell deployment and cryptomining attacks through unpatched backup platforms.
Computer Software/Engineering
Software companies utilizing AhsayCBS backup solutions vulnerable to chained CVE exploits allowing unauthorized access, reconnaissance, and persistent cryptocurrency mining malware installation.
Outsourcing/Offshoring
Service providers managing client infrastructure through AhsayCBS exposed to zero-trust violations, lateral movement risks, and compliance failures under HIPAA and PCI standards.
Management Consulting
Consulting firms dependent on managed backup services face egress security breaches and data exfiltration risks from compromised AhsayCBS platforms lacking proper segmentation.
Sources
- Unpatched AhsayCBS flaws exploited to deploy webshells, mine cryptohttps://www.bleepingcomputer.com/news/security/unpatched-ahsaycbs-flaws-exploited-to-deploy-webshells-mine-crypto/Verified
- AhsayCBS Flaws Exploit Analysishttps://www.huntress.com/blog/ahsaycbs-flaws-exploitVerified
- National Vulnerability Database - CVE-2024-6062https://nvd.nist.gov/vuln/detail/CVE-2024-6062Verified
- National Vulnerability Database - CVE-2024-6063https://nvd.nist.gov/vuln/detail/CVE-2024-6063Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius of this AhsayCBS exploitation by constraining lateral movement pathways and limiting east-west traffic flows between compromised systems and critical infrastructure.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero trust architecture would likely constrain the initial foothold by restricting network reachability to the compromised AhsayCBS platform from other network segments
Control: Zero Trust Segmentation
Mitigation: Microsegmentation policies would likely reduce the blast radius of privilege escalation by isolating workloads and constraining the scope of elevated access
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely constrain reconnaissance activities and reduce lateral movement pathways between the compromised backup system and other network resources
Control: Multicloud Visibility & Control
Mitigation: Enhanced visibility controls would likely detect anomalous webshell communications and constrain command execution pathways through improved traffic inspection and behavioral analysis
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely constrain cryptocurrency mining operations by restricting outbound connections to mining pools and limiting unauthorized software downloads
The constrained network pathways and limited blast radius would likely reduce the scale of cryptocurrency mining operations across the organization's infrastructure
Impact at a Glance
Affected Business Functions
- Backup and Recovery Services
- Data Protection Operations
- Managed Service Provider Operations
- System Integration Services
Estimated downtime: 3 days
Estimated loss: $25,000
Potential exposure of backup data repositories, system credentials, and customer backup configurations managed through compromised AhsayCBS instances. Cryptocurrency mining operations may have degraded system performance and increased operational costs.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Inline IPS (Suricata) to detect and block known exploit patterns targeting CVE-2026-105133 and CVE-2026-105134 before they reach vulnerable applications
- • Deploy Cloud Firewall (ACF) with egress filtering to prevent unauthorized cryptocurrency miner downloads and block mining pool communications
- • Enable Multicloud Visibility & Control to detect anomalous interactions and suspicious automation patterns indicative of webshell deployment
- • Implement Zero Trust Segmentation to limit blast radius and prevent lateral movement from compromised backup management systems
- • Deploy Threat Detection & Anomaly Response capabilities to baseline normal behavior and alert on cryptocurrency mining activities and covert tools



