language
Detectat automat

Am preselectat Română și Romanian Leu (lei) pentru tine.

Autentificare
softwarebay.de
softwarebay.de
AhsayCBS Security Vulnerabilities Exploited for Crypto Minin
News › Cybersecurity › AhsayCBS Security Vulnerabilities Exploited for Cr...
Cybersecurity

AhsayCBS Security Vulnerabilities Exploited for Crypto Mining

AhsayCBS Security Vulnerabilities Exploited for Crypto Mining

Attackers have exploited vulnerabilities in the backup software AhsayCBS to gain control over affected systems. These security flaws allow for the installation of XMRig cryptocurrency miners disguised as Microsoft Edge. The attacks have been observed in recent weeks and pose a serious threat to companies using this software. The vulnerabilities are documented in two recently released security reports. One of the main vulnerabilities is CVE-2026-105133, which concerns improper authentication in the checkSysPwd() function in the ApiStructsAction.java file.

This vulnerability has a CVSS v4 score of 5.5, making it a significant risk. By exploiting this vulnerability, attackers can not only take control of the systems but also install web shells that provide them with further access and control. The use of web shells is a common method to maintain persistent access to compromised systems and conduct further attacks. The attackers disguise the XMRig miners as Microsoft Edge to evade detection by security software. This technique is particularly dangerous as it allows attackers to utilize the computing power of the affected systems for cryptocurrency mining without the users noticing.

The vulnerabilities in AhsayCBS affect a variety of companies using this backup solution. Experts warn that exploiting these vulnerabilities can lead to significant financial losses, especially if systems are not patched in a timely manner. IT security experts recommend promptly updating the software and checking all affected systems for signs of compromise. Implementing additional security measures, such as intrusion detection systems, can also help prevent such attacks. The AhsayCBS developers have already responded to the vulnerabilities and are working on an update to address the issues.

Companies should ensure they are using the latest versions of the software to protect themselves against these threats. The vulnerability CVE-2026-105133 has been identified by several security researchers and is part of a growing list of vulnerabilities discovered in enterprise software. A swift response to such threats is crucial to maintaining the integrity of systems. The attacks on AhsayCBS are part of a larger trend where cybercriminals increasingly target vulnerabilities in backup and enterprise software.

According to recent reports, such attacks have increased by 30% in recent months. The vulnerability was officially disclosed on October 1, 2026, and the first attacks were recorded shortly thereafter. Companies are urged to review their security protocols and ensure they are up to date to prepare against such threats.

Tags: AhsayCBS Cybersecurity XMRig CVE-2026-105133 Malware IT Security Cryptocurrencies Webshells

💬 Comentarii (0)

Scrie un comentariu

info Va fi publicat dupa moderare
chat_bubble_outline

Inca nu exista comentarii. Fii primul!