Canadian Cyber Security Journal
SOCIAL:
Filed under: TechTalk

AhsayCBS Backup Server Flaws Are Under Attack: What Canadian IT Teams and MSPs Must Do

What Happened

Attackers are chaining two AhsayCBS flaws to take over backup servers. The Hacker News reports Huntress traced exploitation to October 7. CVE-2026-105133 is an improper authentication flaw rated 5.5 in CVSS v4. CVE-2026-105134 is an OS command injection flaw in the Replication Receiver component rated 9.3. Together they bypass authentication and run commands on the host.

Attackers performed reconnaissance, dropped web shells, and installed XMRig cryptominers disguised as Microsoft Edge. In at least one case they downloaded the vulnerable WinRing0x64.sys driver to tune mining hardware. Huntress counted five affected organizations by October 8. Advisories list version 10.3.4 as the fix, yet Huntress says 10.3.4 is also vulnerable.

Why This Matters for Canadian Organizations

Backup servers hold copies of everything. AhsayCBS is common among managed service providers, which use it to back up many small clients from one console. Canadian MSPs serving clinics, law firms, and municipalities carry the same exposure. One compromised console reaches every client behind it.

The miner is the visible symptom. A web shell on a backup server also gives access to stored data and credentials. Stolen personal information triggers PIPEDA breach reporting, and Quebec organizations face Law 25 duties. A server with no clear patch needs compensating controls today.

What to Do

Find every AhsayCBS instance, including ones run by your service providers. Restrict the management interface to trusted IP addresses or place it behind a VPN. Hunt for edge.exe in unusual paths, a Taskgmr.ps1 script, WinRing0x64.sys in the TEMP folder, and new web shells. Rotate credentials stored on the server if you find signs of compromise. Ask your MSP in writing whether it runs AhsayCBS and how it protects the console. Follow related stories in our TechTalk archive.

Enjoy this article? Don’t forget to share.