Unpatched AhsayCBS Backup Flaws Let Attackers Hide Crypto Miners as Microsoft Edge
Threat actors are exploiting two recently disclosed vulnerabilities in AhsayCBS, a backup utility, to take control of affected devices. Chained together, the flaws let a remote attacker bypass authentication and run commands on a system. According to security firm Huntress, exploitation began on 7 October 2026, and by 8 October an estimated five targeted organisations had been affected.
After gaining access, the attackers carry out reconnaissance, drop web shells and install XMRig cryptocurrency miners. The miners are named "edge.exe" so they look like the Microsoft Edge browser. Attackers also dropped a PowerShell script, suspected to be written with AI assistance, that stops mining when someone opens Windows Task Manager. It also closes Task Manager if it has been left open for more than an hour overnight. In at least one incident, the attackers used the built-in certutil.exe tool to download a legitimate but vulnerable driver, likely to gain deeper hardware access and improve mining.
The National Vulnerability Database advisories say the issues were fixed in version 10.3.4. Huntress has since found that this version is also affected, which effectively makes the flaws zero-days. With no patch available, users are advised to limit access to the management interface and hunt for signs of compromise.