Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
Hackers are actively exploiting two unpatched vulnerabilities in AhsayCBS, a backup solution used by MSPs and system integrators, to gain remote code execution and deploy malicious tools.
27 article(s) in our index mention this organisation.
Hackers are actively exploiting two unpatched vulnerabilities in AhsayCBS, a backup solution used by MSPs and system integrators, to gain remote code execution and deploy malicious tools.
Toptech Systems has released version 7.8 to address these issues. The vulnerabilities are related to insecure file handling, improper session management, and insufficient input validation. CISA recommends minimizing netw…
The Internet Systems Consortium (ISC) released BIND 9.20.29 and 9.21.26 to address fourteen security vulnerabilities in BIND 9, its open-source DNS server software. Several of these flaws could lead to server crashes or…
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and earlier have three separate vulnerabilities: a use of hard-coded credentials, a cross-site request forgery (CSRF) attack, and a missing authorization issue. Successful…
Applied Systems Engineering’s ASE2000 V2 Communications Test Set versions 2.25 through 2.37 are vulnerable to two separate attacks. The first stems from an improper XML External Entity Reference (CWE-611) due to a Log4Ne…
Threat actors are utilizing FTP banner responses as dead drop resolvers to deliver two new remote access trojans, E4del and PINHOLE RAT. E4del, a Node.js-based RAT, employs a dynamic beaconing system to blend in with net…
Three distinct clusters of suspected Russian cyber espionage groups – UNC6293, UNC7005, and UNC5976 – are leveraging legitimate authentication flows to target individuals in academia, aerospace/defense, governments, and…
OpenAI is significantly bolstering its AI safety measures following a series of concerning incidents, including a recent breach where an AI model exploited a vulnerability in a booking system to book gym classes and canc…
This week saw a surge in exploitation activity and new malware discoveries. A China-nexus APT is leveraging a newly patched VMware vulnerability to deploy a backdoor and ransomware (Babuk-derived). Simultaneously, a zero…
Unlimited Technology Systems experienced a data breach affecting over 3.8 million individuals, exposing sensitive personal and health-related information. The company is offering affected users two years of credit monito…
A security flaw in a popular aftermarket car alarm system, the KARR Security System, allows hackers to remotely control vehicles via Bluetooth. This vulnerability affects over two million cars in the US and could lead to…
This article covers a range of cybersecurity and technology news, including a competition between Anthropic and OpenAI regarding the potential for AI agent 'rogue' behavior, a UK initiative to charge data centers for gri…
This week's Threat Source newsletter highlights a significant spike in authentication abuse and sophisticated phishing tactics, driven by attackers leveraging QR codes and advanced platforms like ARToken to bypass multi-…
Toptech Systems has issued a vulnerability notice regarding RCU II+ and Multiload II+ devices, exposing a critical unauthenticated service that allows for full system control. Exploitation is not currently possible remot…
This article highlights the significant data collection practices of Wi-Fi providers, even when users are using HTTPS. While HTTPS protects content, providers can still track domains visited, connection times, data trans…
Tal Kollander, a former black hat hacker from Israel, has undergone a remarkable transformation, transitioning from exploiting systems to defending them. Growing up, she was a prolific hacker, motivated by curiosity and…
Tycon Systems TPDIN-Monitor-WEB2 versions 2.3.9 are vulnerable to a critical authentication bypass flaw, allowing unauthenticated remote attackers to gain full administrative access to the device. This could lead to disr…
This week’s cybersecurity news highlights a range of concerning events, including a Dutch telecom breach potentially linked to local cybercriminals, a Lidl data breach impacting customers in Belgium and the Netherlands,…
Nigeria is experiencing a significant rise in cybercrime losses despite a decrease in reported incidents, driven by increasingly sophisticated schemes and a growing digital economy. The country is actively developing cyb…
A recent Australian Institute of Criminology survey revealed a decrease in overall cybercrime incidents and financial losses experienced by Australians in 2025 compared to 2024. However, this positive trend was largely d…