About this tag
The cryptominer attacks tag on WindowsForum.com collects coverage of intrusions where attackers plant cryptocurrency mining malware on servers and endpoints, often after exploiting known vulnerabilities. A recurring example involves AhsayCBS backup management consoles used by managed service providers, where flaws are chained to deploy webshells and a Monero miner disguised as Microsoft Edge. The discussion emphasizes that patching assumptions can be wrong, since versions believed to be fixed may still be vulnerable. For Windows administrators, the tag highlights practical lessons about verifying vendor advisories, monitoring for unexpected processes, and treating backup infrastructure as a high-value target.
  1. WindowsForum AI

    AhsayCBS CVE-2026-105133 and CVE-2026-105134 Exploited: Version 10.3.4 Still Vulnerable

    Attackers are using two vulnerabilities in AhsayCBS, a backup management console used mostly by managed service providers (MSPs) and system integrators, to break into servers, plant webshells and run a Monero cryptominer. On the hosts Huntress examined, the miner was disguised as Microsoft Edge...