- Huntress saw attackers chain two AhsayCBS flaws to run code on backup servers, then install a crypto miner that hides when someone opens Task Manager.
- Huntress lists all versions through 10.3.4 as affected, and it saw five organizations targeted by October 8. The campaign shows how malware can plan for human checks.
- Huntress advises limiting the management interface to trusted IP addresses or a VPN, and re-imaging any host where indicators of compromise appear.
Few people open a backup console until something goes wrong. That is what makes this week's AhsayCBS attacks worth reading closely. Along with the break-in, the attackers shipped a script aimed at the person who investigates a slow server. The lesson is narrow but useful: the first check we reach for in a bad hour can be anticipated by the people we are checking for.
What Huntress found
Security firm Huntress reports that two vulnerabilities in AhsayCBS were disclosed through NVD on October 4, 2026. AhsayCBS is the management console for Ahsay's backup software. Managed service providers and system integrators mainly use it. Administrators use it to create users and set backup policies.
Huntress saw exploitation begin on October 7 at 23:20:15 UTC. That is three days after the October 4 disclosure, counted by calendar date. By October 8, it had seen five organizations targeted.
Huntress later corrected its own write-up. Earlier reporting said version 10.3.4 was not affected. Its further investigation found that it is. Huntress says it has contacted Ahsay. Until a patch is available, it recommends restricting access to the management interface.
How the break-in works
The attackers chain two bugs. First, CVE-2026-105133 bypasses authentication. Huntress describes it as medium severity. It affects a password-checking function called checkSysPwd.
Second, CVE-2026-105134 delivers code execution. Huntress describes it as critical severity. It affects the Replication Receiver component, at the path /rps/api/json/UpdateReceivers.do. A random token can stand in for real credentials there.
The result is that an outsider with no login can run commands as NT AUTHORITY/SYSTEM. That is a top-level Windows account.
In some cases, the intruders set up a rogue receiver. They then placed a JSP webshell in the folder the application serves. A webshell is a small file that lets an attacker type commands from afar. In other cases, the AhsayCBS service process, cbssvcX64.exe, started curl and certutil. Both are built-in download tools.
A miner dressed as a browser
The downloads came from Alibaba Cloud storage. They included XMRig, an open-source program that mines the Monero cryptocurrency. The attackers named it edge.exe.
They also renamed a copy of NSSM, a tool that keeps programs running, to msedge.exe. They then created a Windows service called MicrosoftEdgeUpdateSvc. The name is close to the real edgeupdate service. The service ran as SYSTEM and restarted the miner after a crash or reboot.
In one incident, the attackers also fetched WinRing0x64.sys. It is a legitimate but vulnerable driver that gives low-level hardware access. Such drivers are often used to turn off security software. Huntress judged that here the driver gave the miner more direct access to the hardware.
The script that watches the watcher
One file, Taskgmr.ps1, stands out. Huntress says its commented code suggests it was written with AI help. The script keeps checking whether Task Manager is running. When someone opens Task Manager, it stops the mining service. When Task Manager closes, it starts the miner again.
It also closes Task Manager at 18:00. It does the same if the window stays open for over an hour overnight. It reads the machine's local clock to decide.
Picture a person who logs in at night because a server feels slow. They open Task Manager and see nothing odd. The miner stopped the moment they looked.
This is one evasion feature in one campaign. The break-in itself relied on two chained bugs. Still, it shows that the miner's operators planned for the human who investigates. A quick look at a busy server is not proof of a clean one.
What to ask your team
Huntress says the exploit targets the web service reachable from outside. Its advice is to allow the management interface only from trusted IP addresses, or to require a VPN. Put these questions to your team and to any provider that runs backups for you.
First, do we run AhsayCBS, directly or through a vendor? Second, can its web console be reached from the internet? Third, would we be alerted if cbssvcX64.exe or cbssvcX86.exe started an unexpected child process? Fourth, has anyone searched for a service named MicrosoftEdgeUpdateSvc, or for edge.exe and msedge.exe in Temp folders?
Huntress published Sigma detection rules for this campaign. Sigma is a shared format for writing detection logic. One rule covers the unexpected child process. Another looks for scripts that pair a Task Manager check with a service stop. Because it matches that pairing, renaming the service does not evade it.
If any listed indicator turns up, Huntress advises wiping the host and rebuilding it from a trusted backup. It notes that attackers have hidden extra backdoors for long-term access. The catch is plain. The backup must predate the intrusion, and the tool involved is the one that makes backups.
This is one campaign, seen by one vendor. It does not show a wider pattern. It does show where to look first: the quiet tools that nobody opens until something goes wrong.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Huntress.





