The correction changes the remediation decision

For a backup administrator, the most important line in Huntress's AhsayCBS investigation may be its correction. Earlier information suggested version 10.3.4 was safe. After further testing, Huntress said that version is vulnerable too. A team that updated to 10.3.4 and closed its ticket should reopen the exposure review.

Do not treat 10.3.4 as a fix

Huntress updated its report on 8 October to say versions through 10.3.4 are affected. Its updated guidance emphasizes restricting access to the management interface and investigating possible compromise while a verified patch is unavailable.

The attacker did more than mine cryptocurrency

Huntress observed exploitation beginning 7 October and reported five organizations targeted as of 8 October. It describes attackers chaining CVE-2026-105133 and CVE-2026-105134 to gain code execution, followed by reconnaissance, JSP webshells and XMRig miners disguised as Microsoft Edge components. Five is Huntress's observed sample, not a global victim count.

The miner is conspicuous, but the backup server's management role is the larger concern. Such a server may control users, policies and recovery workflows. An apparently quiet endpoint does not establish that a webshell or secondary access is absent. Huntress also observed an Edge-like Windows service and files staged in temporary directories, offering more precise investigation leads than CPU usage alone.

Reduce reachability, then establish whether access occurred

  1. 1

    Find every instance. Record the running AhsayCBS build, host owner, internet exposure and administrative access path. Include managed-service and standby installations.

  2. 2

    Restrict management access. Limit the web interface to trusted addresses or a controlled VPN. Treat this as exposure reduction while following new vendor and researcher updates, not as a software fix.

  3. 3

    Hunt on the server. Review unexpected child processes of the AhsayCBS service, new JSP files, suspicious Edge-named files in temporary directories and unfamiliar services. Huntress publishes campaign-specific detection rules and indicators.

  4. 4

    Recover trust if compromised. Preserve evidence, assess the server's reachable systems and credentials, and follow incident-response guidance for rebuilding from a trusted state. Updating software alone cannot remove persistence already placed on the host.

A closed patch ticket is not proof of safety

Re-check any remediation record closed on the assumption that 10.3.4 was unaffected. A useful closure statement names the running version, the management interface's reachability, who reviewed the exposure window, and whether suspicious activity was found. Keep that assessment separate from the question of when a verified fixed release becomes available.