A cybersecurity threat has emerged targeting Burger King Spain's AhsayCBS backup system. A threat actor known as #LongNight is selling remote code execution (RCE) access to the system for $4,000. This vulnerability targets a critical component of the company’s data management infrastructure, handling sensitive corporate information across multiple storage platforms. Approximately 2.6 terabytes of sensitive information is at risk, making it an attractive target for cybercriminals seeking valuable information or planning ransomware operations.
Source: https://cybersecuritynews.com/burger-king-backup-system-rce-vulnerability/
TPRM report: https://www.rankiteo.com/company/burgerkingiberia
"id": "bur325052525",
"linkid": "burgerkingiberia",
"type": "Vulnerability",
"date": "5/2025",
"severity": "100",
"impact": "",
"explanation": "Attack threatening the organization’s existence"
{'affected_entities': [{'industry': 'Fast Food',
'location': 'Spain',
'name': 'Burger King Spain',
'type': 'Company'}],
'attack_vector': 'Exploiting vulnerability in AhsayCBS backup system',
'data_breach': {'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Sensitive corporate information'},
'date_detected': '2025-05-23',
'date_publicly_disclosed': '2025-05-23',
'description': 'A threat actor known as #LongNight has put up for sale remote '
'code execution (RCE) access to Burger King Spain’s AhsayCBS '
'backup system for $4,000. The vulnerability targets the '
'company’s AhsayCBS backup system, which handles sensitive '
'corporate information across multiple storage platforms.',
'impact': {'data_compromised': '2.6 terabytes of sensitive information',
'systems_affected': 'AhsayCBS backup system'},
'initial_access_broker': {'entry_point': 'AhsayCBS backup system',
'high_value_targets': 'Sensitive corporate '
'information'},
'motivation': 'Financial gain',
'references': [{'date_accessed': '2025-05-23',
'source': 'KrakenLabs',
'url': 'https://twitter.com/KrakenLabs_Team'}],
'threat_actor': '#LongNight',
'title': 'Burger King Spain Backup System RCE Vulnerability',
'type': 'Remote Code Execution',
'vulnerability_exploited': 'Remote Code Execution (RCE) in AhsayCBS backup '
'system'}