Find notable cyber news and cases, enriched with sources, timelines, and signals.

AhsayCBS backup utility actively exploited authentication bypass and command injection flaws (multiple vulnerabilities)

Vulnerability
First reported
Last updated
Happening score
H score 49
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-105133 and CVE-2026-105134 in AhsayCBS are being actively exploited, enabling attackers to bypass authentication and run arbitrary commands on exposed systems. The chained flaws affect the checkSysPwd() authentication path and the Replication Receiver component, turning a backup utility weakness into remote code execution risk. Exploitation began on October 7, 2026 and quickly expanded to multiple organizations, with post-exploitation activity including web shells and XMRig miners.

Related Happenings

AhsayCBS backup utility active exploitation wave (CVE-2026-105133, CVE-2026-105134)

Exploitation Wave
H score51 First: 09.10.2026 15:47 Last: 09.10.2026 15:47 Sources 1

How related: Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners.

About this happening: Active exploitation of CVE-2026-105133 and CVE-2026-105134 in AhsayCBS backup utility is enabling remote code execution and post-compromise deployment of web she...

AhsayCBS XMRig and web shell post-exploitation activity

Malware Activity
H score33 First: 09.10.2026 15:47 Last: 09.10.2026 15:47 Sources 1

How related: "Post-exploitation, threat actors are conducting reconnaissance, dropping web shells, planting XMRig cryptominers masquerading as Microsoft Edge, and more," the cybersecurity company said.

About this happening: Post-exploitation activity on compromised AhsayCBS hosts is dropping web shells and XMRig miners, extending attacker control and adding cryptomining after initial acce...

Warlock SharePoint multi-sector ransomware campaign

Campaign
H score29 First: 02.10.2026 21:33 Last: 02.10.2026 21:33 Sources 1

About this happening: The Warlock ransomware campaign is using SharePoint vulnerabilities to break into a water utility, telecom provider, regional government body, and university...

Phantom Mantis shifts The Gentlemen into an independent ransomware partnership program

Threat Actor Meta
H score24 First: 11.06.2026 19:50 Last: 11.06.2026 19:50 Sources 1

About this happening: Phantom Mantis moved The Gentlemen from dependence on other ransomware ecosystems into an independent partnership program, expanding its operational autonomy and affil...

Everest Forms Pro CVE-2026-3300 active exploitation wave

Exploitation Wave
H score87 First: 05.06.2026 11:38 Last: 05.06.2026 11:38 Sources 1

About this happening: Active exploitation of CVE-2026-3300 in Everest Forms Pro is driving complete site compromise risk for WordPress sites. Attackers have been using the flaw for arbitrar...

Timeline

  1. 09.10.2026 15:47 2 articles · 4h ago

    AhsayCBS backup utility actively exploited authentication bypass and command injection flaws (multiple vulnerabilities)

    Initial Disclosure

    The flaws were assigned CVE-2026-105133 and CVE-2026-105134 on October 4, 2026, establishing a chained weakness in AhsayCBS that could bypass authentication and enable command execution. Early guidance described the latest software release, 10.3.4, as addressing the issues.

    Show sources