Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    When AI agents cheated at math, other AI agents blew the whistle on them

    September 15, 2026

    ‘I Like My Big Rat Wife’: Meet the People Using Chatbots to Write Custom Fiction

    September 15, 2026

    Donated livers can be made biologically younger

    September 15, 2026
    Facebook X (Twitter) Instagram
    Trending
    • When AI agents cheated at math, other AI agents blew the whistle on them
    • ‘I Like My Big Rat Wife’: Meet the People Using Chatbots to Write Custom Fiction
    • Donated livers can be made biologically younger
    • Responsible AI for Higher Education
    • The Real AI Disruption Isn’t the Technology. It’s the Company.
    • New York Seizes a Dozen Celebrity Deepfake Websites
    • The AI industry has taken a doomer turn. What now?
    • Countries Seek to Curb Social Media Addiction for Kids.
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Australia warns of global campaign targeting vulnerable CMS platforms
    Cybersecurity

    Australia warns of global campaign targeting vulnerable CMS platforms

    kirklandc008@gmail.comBy kirklandc008@gmail.comJuly 11, 2026No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Australia warns of global campaign targeting vulnerable CMS platforms
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Australian Cyber Security Centre (ACSC) issued an alert about a global exploitation campaign targeting vulnerable content management systems (CMS) and plugins.

    The government agency says that many Australian businesses have already been affected by the malicious activity, with webshells being deployed on their sites.

    Webshells provide persistent access to the compromised sites and allow threat actors to disrupt services, steal credentials, plant additional malware, and move deeper into the network.

    “A large-scale exploitation campaign is targeting various vulnerabilities in content management systems (CMS) globally, including in Australia, with many small- to medium-sized Australian businesses impacted,” the ACSC warns.

    “As part of this campaign, malicious cyber actors are actively scanning websites for opportunities to deploy webshells, leveraging various vulnerabilities affecting CMS software and plugins.”

    According to the agency, the activity leverages flaws in several CMS platforms and plugins, including WordPress, Craft CMS, MaxSite CMS, MetInfo CMS, and Joomla JCE. ACSC lists the following products exploited in the campaign:

    • Simple File List (WordPress) – CVE-2025-34085/CVE-2020-36847
    • WavePlayer (WordPress) – CVE-2025-12057
    • BerqWP (WordPress) – CVE-2025-7443
    • WPBookit (WordPress) – CVE-2025-7852
    • Ninja Forms (WordPress) – CVE-2026-0740
    • ThemeREX Addons (WordPress) – CVE-2026-1969
    • Breeze Cache (WordPress) – CVE-2026-3844
    • pay-uz (WordPress) – CVE-2026-31843
    • ACF Extended (WordPress) – CVE-2025-13486
    • Sneeit Framework – CVE-2025-6389
    • WPvivid Backup (WordPress) – CVE-2026-1357
    • Gravity Forms (WordPress) – CVE-2025-12352
    • GutenKit/Hunk Companion (WordPress) – likely CVE-2024-9234
    • Craft CMS – CVE-2025-32432
    • MaxSite CMS – CVE-2026-3395
    • MetInfo CMS – CVE-2026-29014
    • Joomla JCE – CVE-2026-48907

    The ACSC noted that the campaign might be supported by AI, which typically helps threat actors accelerate attacks and scale the exploitation of emerging flaws.

    Website administrator are recommended to apply the latest security updates for their CMS, themes, and plugins, remove unused components, and enable automatic updates where possible.

    It is also recommended to make web directories read-only when possible, monitor for unauthorized file creation, restrict access to sensitive directories, and block unexpected spawning of child processes on the web server.

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    Australia Campaign CMS Global platforms targeting Vulnerable warns
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Efficient and Accurate Prediction of Cosite Isolation on Large Platforms

    August 15, 2026

    A fundamental flaw leaves LLMs strikingly vulnerable to attack

    July 31, 2026

    Global AI Digital Divide Shapes Who Builds AI

    July 29, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • When AI agents cheated at math, other AI agents blew the whistle on them
    • ‘I Like My Big Rat Wife’: Meet the People Using Chatbots to Write Custom Fiction
    • Donated livers can be made biologically younger
    • Responsible AI for Higher Education
    • The Real AI Disruption Isn’t the Technology. It’s the Company.

    When AI agents cheated at math, other AI agents blew the whistle on them

    September 15, 2026

    ‘I Like My Big Rat Wife’: Meet the People Using Chatbots to Write Custom Fiction

    September 15, 2026

    Donated livers can be made biologically younger

    September 15, 2026

    Responsible AI for Higher Education

    September 15, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.