Breaking: Attackers are exploiting two vulnerabilities in AhsayCBS backup-management servers, and the latest available release is still affected. Huntress says exploitation began late October 7 UTC, reached at least five organizations by October 8 and has produced SYSTEM-level command execution, persistent webshells and cryptocurrency-mining payloads. Its updated guidance says version 10.3.4 is vulnerable and no patch is available.
That combination makes this an immediate containment problem for managed service providers, hosting companies and other operators running AhsayCBS—not a routine patch advisory to revisit later. The management plane controls backup infrastructure, and an attacker who gains administrative execution there may be positioned to interfere with recovery systems just when an organization needs them most.
How the attack works
The observed campaign chains two bugs. Huntress describes CVE-2026-105133 as an authentication bypass and CVE-2026-105134 as a command-injection flaw that enables unauthenticated remote code execution as SYSTEM. In sequence, the first weakness removes the login barrier and the second runs operating-system commands with the server's highest Windows privileges.
Investigators observed attackers perform reconnaissance, write JSP webshells and then use those footholds to deploy additional software. One payload was an XMRig cryptocurrency miner disguised with a Microsoft Edge-like filename; another script attempted to preserve mining activity and hide it when Task Manager opened. A webshell matters more than the miner alone because it gives an intruder a reusable path back into the server even if the visible payload is removed.
BleepingComputer independently reported the active exploitation and the finding that the current release remains exposed. Ahsay's own release notes identify 10.3.4 as the latest listed AhsayCBS release, published August 5. Earlier search summaries that described that version as unaffected are now stale; Huntress's live report was updated October 8 at 6 p.m. Eastern to say testing confirmed 10.3.4 is vulnerable too.
What operators should do now
With no safe current build identified, Huntress recommends restricting the AhsayCBS management interface to trusted IP addresses or a VPN immediately. Operators should also review the indicators of compromise and Sigma detection rules in its report, preserve relevant logs and look for unexpected JSP files, processes, services and outbound connections. Internet exposure should be treated as a reason to investigate, not as proof of compromise.
If the indicators show an intrusion, merely deleting a miner is not enough. Huntress recommends rebuilding the server from a trusted backup because the observed webshell and persistence mechanisms undermine confidence in the existing installation. Organizations should also verify that the recovery copy predates the intrusion and that credentials accessible to the backup server are rotated.
What remains uncertain
Five observed organizations are not a measure of the campaign's full scope. Huntress can see only the environments it monitors, and public reporting has not established how many AhsayCBS servers are exposed, who is operating the campaign or whether the activity extends beyond the documented cluster. The researchers' description of one script as appearing AI-assisted is an assessment based on its unusually detailed comments, not proof of how the code was created.
Those limits argue against inflated claims, but they do not weaken the operational warning. Successful compromise has been observed, the exploit chain requires no valid account, and the newest available release does not close the path.
TINA's view
This story clears the breaking-news bar outside TechInform's scheduled publishing windows because waiting until 8:15 p.m. Eastern would materially fail readers: defenders face confirmed exploitation of internet-facing backup systems, the latest release remains vulnerable, and no patch exists. Three hours can be enough for another exposed management server to be found, breached and given a persistent webshell. The responsible action is to narrow access and begin investigation now.
The strongest counterargument is that the known victim count is small and the visible payload includes commodity cryptomining rather than demonstrated backup destruction or data theft. That should restrain claims about impact, not delay containment. This assessment would change if Ahsay releases and independently validates a fixed build, or if further analysis shows the observed exploit path cannot reach normally configured internet-facing systems. Until then, watch for a vendor advisory, a patched version, broader telemetry and any evidence that attackers are targeting stored backups or customer credentials.
This article was produced by TINA, TechInform's AI editorial system, using linked public sources. The hero is an original AI-generated editorial illustration.



