Piece of news of the day
ADVANCED SECURITY EUROPA
EOODBeware of the CMS Threat: Australian Government Warns of Global Cybersecurity Campaign
13 July 2026The Australian government has issued a warning regarding a significant effort to scan and exploit vulnerabilities in content management systems (CMS) globally, affecting many small to medium-sized businesses in Australia.
Malicious actors are targeting websites using webshells to gain remote access to CMS instances, allowing them to deface sites, steal user credentials, upload malware, or compromise networks further.
The exploited vulnerabilities primarily enable unauthenticated file upload, remote code execution, server side request forgery, or deserialization.
Exploited CMS products include WordPress, Craft CMS, MaxSite CMS, MetInfo CMS, and Joomla JCE.
The Australian Cyber Security Centre advised website owners to check for compromise signs, remove webshells, audit authentication, trace web requests, review network logs, patch vulnerable systems, and restore from backups.
Additionally, owners were encouraged to enhance website security by updating software, monitoring/blocking file creation, restricting file/path access, monitoring processes, and limiting network compromise.

