Security
Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge
The Hacker News·October 9, 2026·1 min read
Threat actors exploited two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners. The vulnerabilities include CVE-2026-105133, an improper authentication issue in the checkSysPwd() function in the com/ahsay/obs/api/ApiStructsAction.java file, carrying a CVSS v4 score of 5.5.
Read at The Hacker NewsDaily crypto arcade
Read the news, then play it.
Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.
