The Australian Government has issued warning of a large-scale exploitation campaign. If you run a website built on WordPress, Craft CMS, Joomla, or a similar platform, there’s a new security alert worth knowing about, and it’s hitting small and medium Australian businesses indiscriminately. Attackers are actively scanning the internet for websites running vulnerable plugins and software, then deploying what’s called a “webshell”, a small piece of malicious code that gives them remote control over the compromised server.

Once a webshell is in place, attackers can potentially:

  • Deface or disrupt a website
  • Capture login details or other data entered by visitors
  • Upload further malware to infect people who visit the site
  • Use the compromised server as a stepping stone into a wider network

Speak to BEVIN

At BEVIN Creative, staying on top of exactly this kind of thing is part of what our website maintenance service is for; keeping software patched, monitoring for anomalies, and making sure a known vulnerability doesn’t turn into a real incident on your site.

If you’re on a maintenance plan, you’re covered. If you have any concerns, stay secure and get in touch with the BEVIN team.