logo

Australia warns of global campaign targeting vulnerable CMS platforms

ID: 930048d7-2054-52bf-aa6a-aac832ec2c37

STIX ID: report--930048d7-2054-52bf-aa6a-aac832ec2c37

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-07-11

Date Updated: 2026-07-19

Author: Bill Toulas

...
...

The Australian Cyber Security Centre warns of a global campaign exploiting multiple CMS and plugin vulnerabilities (WordPress, Craft, MaxSite, MetInfo, Joomla JCE) to deploy webshells that provide persistent access for credential theft, malware deployment, and lateral movement; numerous CVEs are listed and administrators are advised to patch, remove unused components, enable updates, and monitor for unauthorized files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.