A Global Campaign of Cyber Attacks Targets Vulnerable Websites Worldwide, with Australian Businesses Hit Hardest
The Australian Cyber Security Centre (ACSC) has sounded the alarm about a massive global campaign aimed at exploiting weaknesses in content management systems (CMS) and plugins. This coordinated attack is not only targeting businesses in Australia but also spreading its reach to other parts of the world. According to the ACSC, many small- to medium-sized Australian companies have already fallen victim to this malicious activity.
At the heart of this campaign lies the use of webshells – essentially, a backdoor that allows hackers to maintain persistent access to compromised websites. This enables them to carry out various malicious activities such as disrupting services, stealing sensitive information, installing additional malware, and moving further into the network. The attackers are exploiting vulnerabilities in popular CMS platforms like WordPress, Craft CMS, MaxSite CMS, MetInfo CMS, and Joomla JCE.
The ACSC has identified several specific products that have been targeted by this campaign, including plugins for WordPress such as Simple File List, WavePlayer, BerqWP, and WPBookit. These plugins are often used to enhance the functionality of websites, but they can also introduce vulnerabilities if not properly maintained or updated. The full list of affected products is extensive, with many other CMS platforms and plugins being targeted.
It’s worth noting that the ACSC suspects AI-powered tools may be aiding these attackers in their efforts to scale up their campaigns and exploit emerging vulnerabilities more quickly. This is a concerning trend, as it implies that hackers are becoming increasingly sophisticated in their methods.
To mitigate this risk, website administrators are advised to prioritize security updates for their CMS, themes, and plugins. Removing unused components and enabling automatic updates where possible can also help prevent these attacks. Additionally, taking steps such as making web directories read-only, monitoring for unauthorized file creation, restricting access to sensitive directories, and blocking unexpected child processes on the web server can further enhance website security.
In conclusion, this global campaign highlights the importance of staying vigilant in the face of emerging threats. As cybersecurity professionals and administrators, it’s essential that we test every layer of our defenses before attackers do. This means regularly scanning for vulnerabilities, updating software promptly, and implementing robust security measures to prevent these types of attacks from succeeding.
Source: Bleeping Computer — 2026-07-11