Threat Intelligence

Unpatched AhsayCBS Backup Flaws Let Attackers Hide Crypto Miners as Microsoft Edge

The Hacker News · 9 Oct 2026
Key Takeaway If you run AhsayCBS, restrict access to its management interface now and check your systems for unexpected files such as an "edge.exe" process, since no patch is currently available.

Threat actors are exploiting two recently disclosed vulnerabilities in AhsayCBS, a backup utility, to take control of affected devices. Chained together, the flaws let a remote attacker bypass authentication and run commands on a system. According to security firm Huntress, exploitation began on 7 October 2026, and by 8 October an estimated five targeted organisations had been affected.

After gaining access, the attackers carry out reconnaissance, drop web shells and install XMRig cryptocurrency miners. The miners are named "edge.exe" so they look like the Microsoft Edge browser. Attackers also dropped a PowerShell script, suspected to be written with AI assistance, that stops mining when someone opens Windows Task Manager. It also closes Task Manager if it has been left open for more than an hour overnight. In at least one incident, the attackers used the built-in certutil.exe tool to download a legitimate but vulnerable driver, likely to gain deeper hardware access and improve mining.

The National Vulnerability Database advisories say the issues were fixed in version 10.3.4. Huntress has since found that this version is also affected, which effectively makes the flaws zero-days. With no patch available, users are advised to limit access to the management interface and hunt for signs of compromise.

AhsayCBS cryptomining zero-day XMRig backup security

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.