Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Security alert graphic for ACSC CMS webshell exploitation campaign targeting Australian websites July 2026

The Australian Cyber Security Centre (ACSC) has issued a critical alert warning of a large-scale exploitation campaign targeting websites running WordPress, Craft CMS, Joomla, and other content management systems. Attackers are scanning for 17 known vulnerabilities — all with patches already available — and deploying webshells for persistent remote access.

This is the second CMS-related alert the ACSC has issued in two months. The May warning flagged compromised Australian WordPress sites distributing Vidar Stealer malware to visitors. The pattern is clear: unpatched websites are being weaponised at scale, and Australian small businesses are confirmed among those hit.

Why this matters for your business

Most small businesses think of cybersecurity as protecting email and endpoints. But your website — especially if it was built years ago and nobody is actively maintaining the plugins — is part of your attack surface too. We see this constantly across client environments: the site was set up by a developer who has moved on, and nobody is checking whether plugins are current or the CMS itself is patched.

Some of the vulnerabilities in this campaign date back to 2020. That means affected sites have been sitting exposed for years. And it gets worse: Insurance Business Magazine reports this alert is putting website patching obligations under the cyber insurance spotlight. Insurers are now encoding patch timelines directly into policy terms — an unpatched CMS could give your insurer grounds to challenge a claim.

What to do right now

  • Check your CMS version and update all plugins immediately
  • Ask your web host or developer whether they are monitoring for webshells
  • Review the ACSC’s full vulnerability list and confirm every patch is applied
  • If nobody is actively maintaining your website’s security, talk to us — your website should not be the weakest link in your defences

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →