ZUBIQO.
AI & MLCryptoFinanceBig TechAI Models
CybersecurityGamingEVs & Clean EnergyRoboticsAerospaceBiotech & HealthConsumer Hardware
Enterprise
ZUBIQO.

High-magnitude intelligence briefs for the tech and finance sectors. Zero fluff. Maximum signal.

contact@zubiqo.com
X (Twitter)ThreadsTelegramBlueskyMastodon

Sections

  • AI & ML
  • Crypto
  • Finance
  • Big Tech
  • Cybersecurity
  • Gaming
  • EVs & Clean Energy
  • Robotics
  • Aerospace
  • Biotech & Health

Publication

  • Evening Newsletter
  • About Us
  • Editorial Ethics
  • Partner With Us
  • Contact Us

Tools

  • AI Models Pricing

Legal

  • Privacy Policy
  • Terms of Service
  • Fair Use & DMCA

Disclaimer:Zubiqo Intelligence operates as an automated technology and market intelligence publication providing AI-assisted synthesis with source attribution. The news briefs, market analysis, “Magnitude Scores”, and “Community Sentiment” metrics provided on this platform are strictly for informational and educational purposes only. They do not constitute financial, legal, investment, or trading advice. Cryptocurrencies and financial markets are highly volatile; always conduct your own research and consult with a licensed professional before making any investment decisions. By using this site, you agree to our Terms of Service.

© 2026 Zubiqo Intelligence. All rights reserved.

  1. Home
  2. /
  3. Cybersecurity
  4. /
  5. Hackers Chain Two Zero-Days to Hijack AhsayCBS Backup Servers with SYSTEM Access
CybersecurityMAG 7AI: Bearish
•
2026-10-10•2 min read

Hackers Chain Two Zero-Days to Hijack AhsayCBS Backup Servers with SYSTEM Access

Zubiqo Take
QuoteThreads

“Burning two zero-days on a centralized backup server just to deploy crypto miners is a baffling waste of potential, but the resulting SYSTEM-level access leaves organizations completely exposed to mass credential theft.”

Hackers Chain Two Zero-Days to Hijack AhsayCBS Backup Servers with SYSTEM Access
📷 Image Source: Cyber Press

Executive Summary

  • •Threat actors are exploiting two chained zero-day vulnerabilities in Ahsay Cloud Backup Server to gain unauthenticated SYSTEM access.
  • •The exploit chain combines a 5.5 CVSS authentication flaw and a 9.3 CVSS command injection vulnerability, affecting versions through 10.3.4.
  • •Attackers are currently using the access to deploy web shells and hidden cryptocurrency miners, though the privileged access exposes entire backup repositories.

Community Sentiment

1-Tap Vote
NordVPN
AFFILIATE PARTNER30-Day Money-Back Policy • Encrypted Traffic

Encrypt your connection and network traffic with NordVPN

Get NordVPN
Affiliate disclosure: We may earn a commission if you subscribe through this link.

Key Developments & Data

Threat actors are exploiting two zero-day vulnerabilities in Ahsay Cloud Backup Server (AhsayCBS) to compromise exposed servers without authentication, according to an October 9 report by Field Effect. The attack chain links an improper authentication flaw (CVE-2026-105133, CVSS 5.5) with an operating system command injection vulnerability (CVE-2026-105134, CVSS 9.3) in the Replication Receiver component. By combining these flaws, attackers can configure a malicious replication receiver, deploy a Java Server Pages web shell, and execute arbitrary commands with NT AUTHORITY\SYSTEM privileges. Observed intrusions have so far focused on deploying XMRig cryptocurrency miners disguised as Microsoft Edge processes, alongside fraudulent Edge update services for persistence. AhsayCBS versions through 10.3.4 remain vulnerable, prompting researchers to advise restricting management interfaces to trusted networks and rebuilding compromised hosts from known-good media to eliminate hidden persistence mechanisms.

Zubiqo Strategic Assessment

Primary Impact

Enterprise IT environments and managed service providers (MSPs) utilizing Ahsay Cloud Backup Server for centralized disaster recovery across multiple customers and business units.

Strategic Shift

Threat actors are increasingly targeting centralized backup and replication infrastructure, transforming disaster recovery systems into high-privilege attack vectors.

The Ripple Effect

Although current observed payloads are limited to cryptomining, persistent SYSTEM-level access to central backup repositories creates an immediate risk for mass credential theft or coordinated ransomware deployment across downstream replication partners.

This intelligence assessment is generated by Zubiqo's AI for informational purposes only.

Intelligence Quality Rating

Grade this brief: Slide & release to submit rating, or tap a preset.

🔥High Impact75/100
Slide & release to voteImmune to accidental scroll
Zubiqo Briefing

The daily signal, delivered every weekday.

A concise weekday briefing on AI, technology and business. Zero PR fluff.

Subscribe directly on Substack↗

Subscription completes on Substack • Free • 1-click unsubscribe anytime

✓ Free on Substack•✓ Official Substack enrollment•✓ 1-click unsubscribe
#ahsaycbs#zero-day#vulnerability#malware#cve
Read original on Cyber Press
Zubiqo MethodologyAI Synthesis

Synthesized from linked market reporting using AI extraction under Zubiqo's editorial standards. Have a correction? Contact our desk.

Event Magnitude7 / 10
Share

Read Next

XRP Ledger Patches Decade-Old Bug That Allowed Infinite Token Minting
Crypto

XRP Ledger Patches Decade-Old Bug That Allowed Infinite Token Minting

SonicWall SMA1000 Max-Severity Flaw Under Active Attack Days After Patch
Cybersecurity

SonicWall SMA1000 Max-Severity Flaw Under Active Attack Days After Patch

Stay on the wire

Breaking tech, AI, and market intelligence the moment it happens. Zero fluff.

Live Broadcasts
TelegramXThreadsBlueskyMastodon
Hackers Chain 98 Zero-Days to Break Pixel 10 and OpenAI Codex at Pwn2Own 2026
Cybersecurity

Hackers Chain 98 Zero-Days to Break Pixel 10 and OpenAI Codex at Pwn2Own 2026

FBI Exposes China-Linked Hackers Running Web Portal for Stolen Government Emails
Cybersecurity

FBI Exposes China-Linked Hackers Running Web Portal for Stolen Government Emails

Zubiqo Methodology

AI Synthesis

Synthesized from linked market reporting using AI extraction under Zubiqo's editorial standards. Have a correction? Contact our desk.

Event Magnitude7 / 10

Related Briefs

Crypto

XRP Ledger Patches Decade-Old Bug That Allowed Infinite Token Minting

Oct 10
Cybersecurity

SonicWall SMA1000 Max-Severity Flaw Under Active Attack Days After Patch

Oct 9
Cybersecurity

Hackers Chain 98 Zero-Days to Break Pixel 10 and OpenAI Codex at Pwn2Own 2026

Oct 9
Cybersecurity

FBI Exposes China-Linked Hackers Running Web Portal for Stolen Government Emails

Oct 8
Cybersecurity

Tensorlake npm SDK Compromised With Shai-Hulud Worm That Punishes Credential Revocation

Oct 8
Cybersecurity

Malicious npm Packages Deliver Overlord RAT in Supply Chain Attack

Oct 7