This Australian Signals Directorate (ASD) Australian Cyber Security Centre (ACSC) Alert is relevant to website owners and website managers. It is being provided to assist agencies and organizations in guarding against the persistent malicious actions of cybercriminals.
A large-scale exploitation campaign is targeting various vulnerabilities in content management systems (CMS) globally, including in Australia, with many small to medium sized Australian businesses impacted.
As part of this campaign, malicious cyber actors are actively scanning websites for opportunities to deploy webshells, leveraging various vulnerabilities affecting CMS software and plugins. These vulnerabilities primarily allow unauthenticated file upload, remote code execution, server side request forgery or deserialization.
Once deployed, webshells can allow malicious cyber actors to remotely access and control targeted web servers. Malicious cyber actors may leverage compromised web servers for several purposes, including:
• Website defacement or disruption
• Capturing credentials entered by website users or other data stored on web servers
• Uploading additional malware to target and scam legitimate website users
• Using web server access as a pathway for broader network compromise
This highly scaled global exploitation campaign demonstrates the rapidly evolving cyber risk facing organizations. The heads of the Five Eyes cyber security agencies recently released a joint statement highlighting how advances in AI are accelerating the speed and scale of cyber operations, reducing the time between vulnerability disclosure and exploitation
ASD’s ACSC recommends that website owners confirm whether their servers have been impacted and remediate accordingly.