Find notable cyber news and cases, enriched with sources, timelines, and signals.

AhsayCBS backup utility active exploitation wave (CVE-2026-105133, CVE-2026-105134)

Exploitation Wave
First reported
Last updated
Happening score
H score 51
1 unique sources, 1 articles

Summary

Hide ▲

Active exploitation of CVE-2026-105133 and CVE-2026-105134 in AhsayCBS backup utility is enabling remote code execution and post-compromise deployment of web shells and XMRig miners. The wave began on 2026-10-07 and had reached five organizations by 2026-10-08. Externally accessible AhsayCBS management interfaces face immediate abuse risk until access is restricted.

Related Happenings

AhsayCBS backup utility actively exploited authentication bypass and command injection flaws (multiple vulnerabilities)

Vulnerability
H score49 First: 09.10.2026 15:47 Last: 09.10.2026 15:47 Sources 1

How related: CVE-2026-105133 (CVSS v4 score: 5.5) - An improper authentication vulnerability in the checkSysPwd() function in the "com/ahsay/obs/api/ApiStructsAction.java" component. CVE-2026-105134 (CVSS v4 score: 9.3) - An operating system command injection vulnerability in the Replication Receiver component.

About this happening: CVE-2026-105133 and CVE-2026-105134 in AhsayCBS are being actively exploited, enabling attackers to bypass authentication and run arbitrary commands on exposed systems...

AhsayCBS XMRig and web shell post-exploitation activity

Malware Activity
H score33 First: 09.10.2026 15:47 Last: 09.10.2026 15:47 Sources 1

How related: "Post-exploitation, threat actors are conducting reconnaissance, dropping web shells, planting XMRig cryptominers masquerading as Microsoft Edge, and more," the cybersecurity company said.

About this happening: Post-exploitation activity on compromised AhsayCBS hosts is dropping web shells and XMRig miners, extending attacker control and adding cryptomining after initial acce...

Warlock SharePoint multi-sector ransomware campaign

Campaign
H score29 First: 02.10.2026 21:33 Last: 02.10.2026 21:33 Sources 1

About this happening: The Warlock ransomware campaign is using SharePoint vulnerabilities to break into a water utility, telecom provider, regional government body, and university...

Arista mitigation guidance for Arista VeloCloud Orchestrator compensating controls for CVE-2026-93952

Advisory/Mitigation
H score53 First: 22.09.2026 15:29 Last: 22.09.2026 15:29 Sources 1

About this happening: Arista issued temporary mitigation steps for exposed VeloCloud Orchestrator (VCO) deployments while a fixed release is pending, limiting the risk from actively exploited...

PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave

Exploitation Wave
H score53 First: 05.09.2026 10:31 Last: 05.09.2026 10:31 Sources 1

About this happening: PaperCut exploitation tied to CVE-2026-81578 and CVE-2026-82078 remains an active exploitation wave against PaperCut NG/MF servers. Arctic Wolf previously...

Timeline

  1. 09.10.2026 15:47 2 articles · 4h ago

    AhsayCBS backup utility active exploitation wave (CVE-2026-105133, CVE-2026-105134)

    Initial Disclosure

    Chained exploitation of CVE-2026-105133 and CVE-2026-105134 in AhsayCBS began on 2026-10-07, when attackers started using the flaws to gain remote code execution on exposed hosts.

    Show sources