Find notable cyber news and cases, enriched with sources, timelines, and signals.

ACSC CMS remediation guidance

Advisory/Mitigation
First reported
Last updated
Happening score
H score 33
2 unique sources, 2 articles

Summary

Hide ▲

The ACSC issued remediation guidance for CMS operators under active exploitation pressure, telling administrators to install the latest security updates for themes and plugins to reduce webshell deployment risk. The advisory also calls for removing unused components and enabling automatic updates where possible. These steps target exposed sites that can otherwise be used for persistence, credential theft, and deeper network compromise.

Related Happenings

Global CMS webshell exploitation campaign

Campaign
H score35 First: 13.07.2026 11:30 Last: 13.07.2026 11:30 Sources 1

How related: As part of this campaign, malicious cyber actors are actively scanning websites for opportunities to deploy webshells, leveraging various vulnerabilities affecting CMS software and plugins,

About this happening: A global CMS exploitation campaign is actively scanning websites for vulnerable software and plugins, creating immediate risk of webshell deployment and broader compromi...

Five Eyes frontier AI cyber resilience advisory

Advisory/Mitigation
H score25 First: 23.06.2026 11:30 Last: 23.06.2026 11:30 Sources 1

About this happening: Five Eyes cybersecurity agencies issued a June 22 advisory urging organizations to strengthen cyber resilience as frontier AI shortens the gap between vulnerabilit...

Timeline

  1. 11.07.2026 17:18 3 articles · 14d ago

    ACSC advises patching vulnerable CMS plugins amid global webshell campaign

    Mitigation Patch Update

    The Australian Cyber Security Centre (ACSC) warns that a global exploitation campaign is targeting vulnerable CMS platforms and plugins, with many small- to medium-sized Australian businesses already impacted by webshell deployment. The activity is actively scanning websites for opportunities to deploy webshells across WordPress, Craft CMS, MaxSite CMS, MetInfo CMS, and Joomla JCE, and the ACSC recommends applying the latest security updates for CMS software, themes, and plugins, removing unused components, enabling automatic updates where possible, making web directories read-only where possible, monitoring for unauthorized file creation, restricting access to sensitive directories, and blocking unexpected child-process spawning on web servers.

    Show sources