Backup software attacks continue after researchers revise patch advice
Source announcement: 8 October 2026; corrected later that day
Activity observed: From 7 October 2026
Huntress has observed attackers exploiting two flaws in AhsayCBS, software that helps IT providers manage customer backups. In five organisations it had seen targeted by 8 October, attackers used the flaws to run commands on exposed servers. They installed *web shells*—small files that provide remote control—and cryptocurrency miners disguised as Microsoft Edge components.
The two weaknesses can work together. One lets an attacker get past an authentication check; the other lets them run commands through the backup server. That matters because a backup system may hold access to many customers’ data and recovery arrangements. The mining software can consume computing power, while the web shell may let an intruder return later. Huntress has not said that every AhsayCBS installation has been attacked.
There is an important correction to earlier patch advice. Huntress initially reported that version 10.3.4 was unaffected. After further investigation, it said versions through 10.3.4 are affected and that a fix was not yet available when it updated its report. Operators should restrict access to the management interface to trusted addresses or a VPN, then investigate for the indicators Huntress published. If compromise is found, Huntress recommends rebuilding the host from a trusted backup because hidden access may remain. Businesses that outsource backups should ask their provider whether it uses AhsayCBS and what checks it has made.








Comments