negativeSYS.SOURCE: The Hacker News• 2026-10-09T18:17:26+05:30
AhsayCBS Vulnerabilities Exploited for XMRig Mining and Web Shell Deployment
Threat actors are exploiting two newly disclosed vulnerabilities in AhsayCBS to deploy XMRig cryptocurrency miners and web shells, with one flaw rated CVSS 5.5. The vulnerabilities include an improper authentication issue in the checkSysPwd() function of the AhsayCBS backup utility.
Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners.
Details of the flaws are below -
CVE-2026-105133 (CVSS v4 score: 5.5) - An improper authentication vulnerability in the checkSysPwd() function in the "com/ahsay/obs/api/ApiStructsAction.java"
*** END OF TRANSMISSION ***