AhsayCBS backup-platform zero-days exploited
Threat actors are actively exploiting two AhsayCBS zero-days for unauthenticated SYSTEM-level access, with public proof-of-concept code, web shells, persistence, reconnaissance, and cryptomining reported. The backup-management context creates significant ransomware-enablement risk; responders should restrict exposure, preserve evidence, investigate persistence, and validate backup integrity.
Sources (2)
Updated Oct 11, 2026