
AhsayCBS Chained Exploits Drop XMRig Miners as edge.exe, Driving Up Victim Power Bills
Exploitation of two AhsayCBS flaws enabled rapid deployment of disguised XMRig miners affecting at least five organizations. The campaign highlights how cryptojacking raises direct electricity costs for everyday users of backup software. Immediate network segmentation and process monitoring are required until verified patches are confirmed.
The AI-generated anti-analysis script and rapid weaponization four days after CVE publication show maturing attacker tooling. Restricting management interface access to VPN or trusted IPs remains the immediate control; organizations must also hunt for edge.exe processes, anomalous certutil traffic, and WinRing0 drivers in TEMP directories.
Huntress: Confirmed incidents will exceed 25 organizations by 31 October 2026 if exposed AhsayCBS instances remain unsegmented.
Sources (3)
- [1]Huntress Threat Report(https://www.huntress.com/blog/ahsaycbs-exploits-oct-2026)
- [2]National Vulnerability Database(https://nvd.nist.gov/vuln/detail/CVE-2026-105134)
- [3]The Hacker News Original(https://thehackernews.com/2026/10/attackers-exploit-ahsaycbs-flaws-to.html)