ACSC warns of global CMS exploitation campaign
This digest was compiled by AI from multiple sources — links to the originals are below.
The Australian Cyber Security Centre (ACSC) warned on July 9 of a highly scaled global campaign targeting content management systems (CMS) and plugins. The campaign exploits vulnerabilities from 2025 and 2026, deploying webshells for credential theft, defacement, and malware distribution. The ACSC noted the rapid scanning may indicate offensive AI-powered tooling.
Campaign Scope
The ACSC said many Australian SMBs are affected, but the campaign is global. Attackers scan websites for vulnerabilities enabling unauthenticated file upload, remote code execution, server-side request forgery, or deserialization. Affected platforms include WordPress, Craft CMS, MaxSite CMS, MetInfo CMS, and Joomla JCE.
Threat Actor Capabilities
Webshells provide persistent remote access, allowing threat actors to deface websites, capture user credentials, upload malware, or compromise broader networks. The ACSC assessed that the speed of scanning and exploitation may involve offensive AI-powered tooling. This aligns with a recent Five Eyes joint statement warning that frontier AI will fundamentally transform the threat landscape within months.
Mitigation Guidance
The ACSC urged website owners to inspect CMS for webshells and vulnerable plugins, examine web access logs for suspicious GET/POST requests, and treat compromised servers as fully breached. Recommended actions include isolating affected systems, auditing authentication, patching vulnerabilities, restoring from clean backups, and monitoring for persistence or lateral movement. Proactive measures include keeping software updated, restricting file creation, and limiting network access.
What's Next
Website owners are advised to implement the ACSC's remediation steps immediately. It remains unclear how many sites have been compromised globally or whether the campaign will expand to target additional CMS platforms.
1 source
ACSC warns of global CMS exploitation campaign
