Skip to content
LatestSecure AhsayCBS Servers Against Active Exploitation of Unpatched Flaws
Vulnerabilities

Secure AhsayCBS Servers Against Active Exploitation of Unpatched Flaws

Attackers are exploiting unpatched vulnerabilities in AhsayCBS to install webshells and cryptocurrency miners, requiring immediate isolation of affected systems.

Secure AhsayCBS Servers Against Active Exploitation of Unpatched Flaws
Illustration: Vector Update

Key points

  • Huntress researchers identified active exploitation of two AhsayCBS vulnerabilities.
  • Threat actors deploy webshells and disguised cryptocurrency miners on compromised servers.
  • The exploited flaws include one critical and one medium-severity issue.

System administrators must immediately assess their AhsayCBS backup management platforms for signs of compromise. Researchers at Huntress reported that threat actors are actively exploiting two newly disclosed vulnerabilities in the software. These attackers use the flaws to gain control of servers and deploy malicious tools. The activity includes installing webshells and running cryptocurrency mining operations without the owner's knowledge.

In plain English

AhsayCBS is the management console for Ahsay’s cloud backup software. Managed service providers and system integrators primarily use this platform. They rely on it to create user accounts and manage backup policies for their clients. The software handles sensitive data and administrative controls for many organizations. When attackers compromise this server, they can potentially access backup data. They can also move laterally into other connected systems. The current threat involves unauthorized code execution on these servers.

The attackers are using two specific weaknesses in the AhsayCBS platform. According to BleepingComputer, one of these vulnerabilities is rated as critical severity. The other vulnerability is rated as medium severity. Neither of these flaws has a confirmed patch available yet. This lack of a fix leaves systems exposed to active exploitation. Attackers are taking advantage of this window to compromise servers globally.

Once inside the system, the threat actors deploy webshells. These webshells allow the attackers to maintain persistent access to the server. They can execute commands and manage the system remotely. Additionally, the attackers install cryptocurrency miners. According to IT Security Guru, these miners are disguised to avoid detection. They run quietly in the background, using server resources to mine crypto. This activity can degrade performance and increase energy costs.

The background

Huntress researchers first disclosed these vulnerabilities and the associated exploitation campaign. Their report highlighted the active nature of the attacks. They observed that the attackers are methodical in their approach. They target the management console specifically because it controls backup operations. Compromising this central point gives them broad access. The use of disguised miners suggests an attempt to remain undetected for longer periods. This allows them to harvest more cryptocurrency before being noticed.

BleepingComputer reported that the vulnerabilities remain unpatched. This status is critical for system administrators. Without a vendor-provided fix, administrators must rely on compensating controls. They must monitor their systems closely for unusual activity. The combination of a critical flaw and active exploitation creates a high-risk scenario. Organizations using AhsayCBS for client backups are particularly vulnerable. A breach could expose multiple client environments simultaneously.

What changes now

Security teams must treat all AhsayCBS instances as potentially compromised. The active exploitation means that attackers are scanning for vulnerable systems. Any system connected to the internet is at risk. Administrators should review their logs for signs of webshell activity. They should also look for unusual CPU usage patterns. These patterns may indicate the presence of cryptocurrency miners. Isolation of affected systems is necessary to prevent further spread.

The lack of a patch requires immediate defensive action. Administrators cannot wait for a software update. They must implement network segmentation and strict access controls. Monitoring for outbound connections to known mining pools is essential. Detecting the disguised miners requires careful analysis of running processes. Identifying and removing the webshells is also critical. Failure to act quickly could result in long-term compromise.

What to do and how to stay safe: AhsayCBS

  • Isolate any AhsayCBS server showing unusual CPU usage or unexpected network connections from the rest of the network immediately.
  • Review server logs for evidence of webshell deployments or unauthorized administrative access attempts during the last thirty days.
  • Monitor outbound traffic for connections to known cryptocurrency mining pools or suspicious external IP addresses.
  • Restrict administrative access to the AhsayCBS console to trusted IP addresses and enforce multi-factor authentication where possible.

Step-by-step guide: Risk-Based Vulnerability Management: Benefits, Limits, and Reality

General security guidance from the Vector Update newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

Are there patches available for the AhsayCBS vulnerabilities?

No, according to BleepingComputer, the critical and medium-severity vulnerabilities remain unpatched as of the latest reports.

What do attackers do after exploiting AhsayCBS?

Attackers deploy webshells for persistent access and install disguised cryptocurrency miners to use server resources.

Who typically uses the AhsayCBS platform?

Managed service providers and system integrators use AhsayCBS to manage backup policies and user accounts.

Sources

  1. IT Security Guru
  2. BleepingComputer
AhsayCBSHuntresswebshellcryptocurrency minerunpatched

Related stories