Security News

Cybersecurity news aggregator

CRITICAL Attacks SC Media

Australian businesses targeted in global content management system exploitation campaign

A widespread campaign is exploiting vulnerabilities in popular CMS platforms and plugins, including WordPress, Craft CMS, and Joomla JCE, to deploy webshells for persistent access, service disruption, and data theft. The article notes the campaign may be AI-accelerated but does not specify a singular CVE, CVSS score, or affected version ranges for the CMS platforms themselves. Administrators are advised to apply all available security updates, remove unused plugins, and implement stricter file system monitoring.
Read Full Article →

Threat Intelligence Australian businesses targeted in global content management system exploitation campaign July 13, 2026 Share By SC Staff A widespread exploitation campaign is targeting content management systems (CMS) and their plugins globally, with numerous Australian businesses already impacted. The Australian Cyber Security Centre (ACSC) has issued an alert detailing how threat actors are deploying webshells on compromised websites, leading to potential service disruptions, data theft, and further network infiltration, according to a recent report by Bleeping Computer. The ACSC reports that malicious actors are actively scanning websites for vulnerabilities in various CMS platforms and plugins, including WordPress, Craft CMS, MaxSite CMS, MetInfo CMS, and Joomla JCE. Exploited vulnerabilities are linked to specific plugins such as Simple File List, WavePlayer, Ninja Forms, and Craft CMS, among others. These exploits allow for the deployment of webshells, which grant persistent access for attackers to disrupt services, steal credentials, and deploy additional malware. The campaign may be accelerated by AI, enabling threat actors to scale their attacks more effectively. Website administrators are strongly advised to apply the latest security updates for all CMS components, remove unused plugins, enable automatic updates, and implement stricter security measures like read-only directories and monitoring for unauthorized file creation. Source: Bleeping Computer SC Staff Related Threat Intelligence China and India-linked threat actors target Pakistani law enforcement SC Staff July 13, 2026 The compromised assets included servers hosting web applications that manage critical police and citizen data, such as criminal and biometric records, hotel and tenant registrations, and personnel files. Threat Intelligence Inmate charged with stealing seized cryptocurrency while serving prison sentence SC Staff July 10, 2026 A Bulgarian national, already serving a lengthy prison sentence for laundering millions stolen from American fraud victims, has been charged with stealing $290,000 in government-seized cryptocurrency. Threat Intelligence Suspected Chinese spies target universities with Roundcube exploit SC Staff July 9, 2026 The threat actor, tracked by Proofpoint as UNK_MassTraction, exploits CVE-2024-42009, a cross-site scripting vulnerability in Roundcube, to gain initial access. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Account Harvesting Backdoor Deauthentication Attack Deepfake Distributed Scans Domain Hijacking Dumpster Diving Google Hacking Password Cracking Reconnaissance You can skip this ad in 5 seconds

Share this article