HomeCyber BalkansTwo AhsayCBS Zero-Day Vulnerabilities Exploited for Backup Server Takeover

Two AhsayCBS Zero-Day Vulnerabilities Exploited for Backup Server Takeover

Published on

spot_img

Rising Threats: Exploitation of Ahsay Cloud Backup Server Vulnerabilities

In a significant development within the cybersecurity landscape, threat actors have been leveraging two zero-day vulnerabilities in the Ahsay Cloud Backup Server (AhsayCBS). These vulnerabilities have enabled attackers to compromise exposed backup servers without the need for authentication, allowing them to execute commands with SYSTEM privileges. The vulnerabilities are a stark reminder of potential weaknesses that exist in infrastructure systems that manage critical backup operations.

The exploitation of these vulnerabilities was first observed on October 7, 2026, with researchers from Field Effect Publishing disclosing the findings the following day. In a rapid response, they identified at least five organizations affected within the initial 24 hours of reporting. This presents a concerning trend for businesses reliant on AhsayCBS for their backup and data recovery processes.

Understanding the Vulnerabilities

The primary vulnerabilities in question are cataloged as CVE-2026-105133 and CVE-2026-105134. The former is described as an improper authentication vulnerability related to the checkSysPwd function, carrying a CVSS score of 5.5. Meanwhile, the more critical flaw, CVE-2026-105134, is identified as an operating system command injection vulnerability located within the Replication Receiver component, rated significantly higher at 9.3.

These vulnerabilities work in tandem, empowering remote attackers to attain privileged execution without requiring any credentials or user interactions. The AhsayCBS platform plays a crucial role in managing various backup-related operations, including storage destinations, user accounts, policies, and replication services. The Replication Receiver itself is responsible for accepting replicated backup data from other systems, while various application programming interfaces allow administrators to configure necessary settings and manage trusted replication partners effectively.

Attack Methods and Impact

The researchers reported that through the exploitation of these vulnerabilities, an unauthenticated attacker could configure a malignant replication receiver and deploy a Java Server Pages web shell. This ultimately allows them to execute commands as NT AUTHORITY\SYSTEM, significantly increasing their control over the compromised systems.

Successful exploitation requires network access to a vulnerable AhsayCBS interface, thus placing those systems that are externally accessible at a greater risk. Preliminary observations indicate that attackers conducted thorough reconnaissance, consequently installing XMRig cryptocurrency miners while disguising them as legitimate Microsoft Edge processes. To maintain persistence on infected systems, attackers reportedly created a fraudulent Edge update service and employed PowerShell scripts designed to obscure mining activity from defenders. The deployment of web shells facilitated further command executions on the compromised hosts.

While much of the documented attacks have concentrated on cryptomining specifically, the implications of achieving SYSTEM-level access extend far beyond that scope. Depending on the specific deployment permissions and integrations, attackers could potentially access sensitive credentials, backup repositories, storage systems, and even administrative functions. Fortunately, current reports do not indicate any instances of credential theft or manipulation of backup data during these intrusions, which is somewhat reassuring amidst the broader threats posed by the vulnerabilities.

However, the situation remains precarious, especially if a single deployment is responsible for managing backups across multiple clients, geographical locations, or distinct business units. Compromising such a central administration point carries the potential to jeopardize interconnected resources and erode the fundamental infrastructure necessary for effective incident response and ransomware recovery.

Recommendations for Mitigation

Field Effect’s report highlighted that versions of AhsayCBS up to 10.3.4 remained vulnerable at the time of disclosure. Administrators are advised to undertake immediate actions, which include thoroughly inventorying production, disaster recovery, test, and secondary deployments, verifying software versions, and restricting management access to trusted networks or secure VPNs. It is also essential to install any vendor-released fixes as they become available.

Ongoing investigations should focus on identifying unexpected JSP files, monitoring suspicious child processes spawned by cbssvcX64.exe, and scrutinizing unauthorized receiver configurations, PowerShell executions, and outbound connections linked to cryptocurrency mining activities. Furthermore, compromised hosts require stringent checks for malicious services and persistence mechanisms. In many instances, the most effective remedy will involve rebuilding systems from known-good media and redeploying AhsayCBS to eliminate any modifications made by attackers.

In summary, the exploitation of vulnerabilities within the Ahsay Cloud Backup Server highlights significant security gaps that organizations must urgently address to safeguard their critical data infrastructure and mitigate the risks posed by threat actors in the evolving cyber landscape.

Source link

Latest articles

Midnight Mimosa Malware for Budget Android Devices

Widespread Malware Campaign "Midnight Mimosa" Targets Budget Android Smartphones Recent revelations by security researchers have...

DarkBlinders Hackers Leverage Fake Meeting App to Deploy Backdoor and Steal Government Data

DarkBlinders Hackers Utilize Fake Meeting Application in Cyberespionage Campaign Targeting Israel and Iraqi Kurdistan In...

IDC Frontier Ransomware Attack Disrupts 495 Customers

Cyberattack on IDC Frontier Disrupts Services for Nearly 500 Customers On October 7, IDC Frontier...

Iranian VPN-over-DNS Activity Produces 40 Billion DNS Observations Amid Military Conflict

Surge in Suspected Iranian VPN-over-DNS Activity Generates Unprecedented Data Observations A recent investigation has revealed...

More like this

Midnight Mimosa Malware for Budget Android Devices

Widespread Malware Campaign "Midnight Mimosa" Targets Budget Android Smartphones Recent revelations by security researchers have...

DarkBlinders Hackers Leverage Fake Meeting App to Deploy Backdoor and Steal Government Data

DarkBlinders Hackers Utilize Fake Meeting Application in Cyberespionage Campaign Targeting Israel and Iraqi Kurdistan In...

IDC Frontier Ransomware Attack Disrupts 495 Customers

Cyberattack on IDC Frontier Disrupts Services for Nearly 500 Customers On October 7, IDC Frontier...