HackerFeeds

CyberSecurity News

Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge

The Hacker News
· October 9, 2026

AI summary

Threat actors are exploiting two vulnerabilities in the AhsayCBS backup utility to gain control of devices and deploy malware. The vulnerabilities are being used to install web shells and XMRig cryptocurrency miners, with the miners disguised as Microsoft Edge. One of the flaws is an improper authentication vulnerability in the checkSysPwd() function, which has a CVSS v4 score of 5.5 and is identified as CVE-2026-105133. This vulnerability is located in the ApiStructsAction.java file. The exploitation of these flaws allows attackers to seize control of affected devices.

Vulnerabilities mentioned

Read the full article at The Hacker Newsthehackernews.com/2026/10/attackers-exploit-ahsaycbs-flaws-to.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.