Australian Cyber Agency Warns of Global CMS Exploitation Campaign

The Australian Cyber Security Centre (ACSC) issues a warning about an ongoing global exploitation campaign that targets vulnerable content management systems and plugins. The agency reports that numerous small- to medium-sized Australian businesses already suffer compromises from the attacks. Threat actors actively scan websites for known flaws and deploy webshells, which grant them persistent access to infected servers.

The campaign leverages dozens of vulnerabilities across multiple CMS platforms, with WordPress plugins making up the bulk of the targeted products. Affected software includes Simple File List, WPvivid Backup, Gravity Forms, Craft CMS, and Joomla JCE, among many others. The ACSC suspects that artificial intelligence accelerates the attackers' efforts, enabling them to scale exploitation rapidly as new flaws emerge.

Website administrators face urgent pressure to patch their CMS installations, themes, and plugins to the latest versions. The ACSC also recommends removing unused components, enabling automatic updates, and making web directories read-only where possible. Additional safeguards include monitoring for unauthorized file creation, restricting access to sensitive directories, and blocking unexpected child processes on web servers.

Read More at the original source →