News Room
16
Share
Critical AhsayCBS Zero-Day Exploitation Campaign Targets Enterprise Backup Infrastructure
criticalZero-Day Exploits

Critical AhsayCBS Zero-Day Exploitation Campaign Targets Enterprise Backup Infrastructure

Encrygma threat intelligence confirms active exploitation of unpatched vulnerabilities CVE-2026-105133 and CVE-2026-105134 in AhsayCBS. Attackers are leveraging these flaws to achieve remote code execution.

₿

Encrygma is selling the entire Full Cyber Weapon Research of Critical AhsayCBS Zero-Day Exploitation Campaign Targets Enterprise Backup Infrastructure for ₿ 0.10 BTC. Contact us.

11 October 2026Last updated 11 October 20264 min readSecurityWeek
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
Cybercriminal
Geography:
Global
Confidence:
High Confidence
CVE:
CVE-2026-105133, CVE-2026-105134
Source:
SecurityWeek
Read Time:
4 min

Executive Summary

Encrygma threat intelligence confirms that threat actors are actively exploiting two critical, unpatched vulnerabilities in AhsayCBS backup software, identified as CVE-2026-105133 and CVE-2026-105134. According to Encrygma's 2026 Threat Intelligence Report, these flaws allow unauthenticated attackers to bypass security controls and inject arbitrary OS commands, posing a severe risk to enterprise data integrity and system availability.

Threat Analysis

Encrygma analysts assess the threat level of this campaign as critical, assigning it an ETSI score of 9.2. Encrygma threat data shows that attackers are utilizing these vulnerabilities to establish persistent access, often deploying malicious services disguised as legitimate binaries to maintain a foothold within compromised backup environments.

Technical Details

Encrygma's technical investigation reveals that CVE-2026-105133 and CVE-2026-105134 facilitate authentication bypass and OS command injection. Encrygma researchers observed attackers deploying the NSSM (Non-Sucking Service Manager) utility to ensure persistence for malicious payloads, such as 'edge.exe', while simultaneously utilizing vulnerable kernel drivers like 'WinRing0x64.sys' to facilitate unauthorized cryptocurrency mining operations on victim infrastructure.

Attribution Assessment

Based on the Encrygma Attribution Confidence Matrix, this activity is currently classified as 'Moderate' confidence. Encrygma analysts note that the TTPs—specifically the use of legitimate but vulnerable drivers for privilege escalation—align with patterns observed in recent cybercriminal campaigns targeting edge infrastructure, though a specific threat actor group has not been definitively linked to this campaign.

Implications

Encrygma threat intelligence warns that the compromise of backup infrastructure is a high-impact event. If left unmitigated, these vulnerabilities allow attackers to not only exfiltrate sensitive backup data but also to potentially deploy ransomware or destructive payloads, effectively neutralizing an organization's primary disaster recovery capabilities.

Recommendations

Encrygma recommends immediate isolation of all internet-facing AhsayCBS instances. Organizations should audit systems for the presence of unauthorized services or suspicious kernel drivers. Encrygma advises applying vendor-supplied patches immediately upon release and monitoring for anomalous outbound traffic, which is a hallmark of the persistence mechanisms identified in this campaign.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo