
A recent advisory from the Australian Signals Directorate (ASD) warned of a large-scale exploitation campaign targeting web content management systems (CMS), with many Australian businesses already impacted. For many small and mid-sized organizations, the business website is no longer just a digital brochure — it is part of the operating front door of the business, and increasingly, a point of cyber risk. Accountability for business risk still sits with leadership. If a website is compromised, the impact can quickly become commercial: customer trust, brand reputation, operational disruption, scam exposure, and in some cases a stepping stone into broader business systems.
A Content Management System (CMS) is the platform behind many business websites. If your organization can update pages, publish articles, manage products, or add functionality through plugins, your website likely runs on a CMS — common examples include WordPress, Joomla and Craft CMS.
That convenience comes with a catch. A CMS is software. Plugins are software. Themes are software. And software needs patching, maintenance and oversight. When vulnerabilities appear, attackers can deploy webshells — hidden tools that allow remote access and control of the web server — enabling them to steal information, upload malicious content, scam your customers, or use the website as a pathway into other parts of your environment.
The Australian Signals Directorate is Australia's national intelligence and cyber security agency, responsible for cyber defence and protecting Australian government and critical infrastructure. When ASD says something deserves attention, it is worth listening. This is not vendor hype, social media theatre or recycled fear marketing. It is a warning from one of Australia's primary cyber authorities.
ASD's Known Exploited Vulnerabilities (KEV) catalog and public advisories exist precisely because cyber threats affect private organizations, supply chains, customer data, online services and public trust. An alert aimed at website owners is really a business risk advisory in cyber clothing.
Five Eyes (FVEY) is an intelligence-sharing partnership between Australia, Canada, New Zealand, the United Kingdom and the United States of America. When agencies from these countries are aligned in their cyber messaging, it signals that the threat is broad, credible and moving quickly. A recent Five Eyes cyber security agencies statement made it clear that artificial intelligence is rapidly transforming cyber risk by increasing the speed, scale and sophistication of attacks — and the timeline is not years, it is months. The window between a vulnerability becoming known and criminals exploiting it is shrinking fast. The Five Eyes statement also reinforces that cyber risk is no longer just an IT issue. It is a leadership, continuity and resilience issue — especially relevant for smaller organizations with limited in-house technical capability.
Many small to mid-sized Australian businesses have already been impacted. Smaller organizations are targeted precisely because they are easier to breach, slower to patch, and more likely to assume they are too small to attract attention. Cyber criminals have never shared that assumption. A compromise can trigger a chain reaction: site goes offline, customer trust drops, scam risk rises, internal time gets chewed up, and management ends up dealing with something expensive, distracting and entirely avoidable.
Attackers are exploiting vulnerabilities in CMS platforms and plugins, installing webshells and gaining remote control of servers. This can lead to website defacement, credential capture, uploading additional malware, scamming legitimate users, and broader network compromise. ASD's official guidance includes inspecting CMS environments for suspicious files, reviewing logs for abnormal requests, isolating compromised servers, patching vulnerable systems, and restoring from known-good backups where compromise is identified.
AI is lowering the barrier for attackers and accelerating the pace at which vulnerabilities can be discovered, weaponized and exploited. Delays that once seemed tolerable — a missed plugin update, an unreviewed security notice, an old website nobody has touched for months — can now create real risk much faster than before. You do not need to be careless to be exposed. You just need to be busy, reliant on third parties, and a little too trusting that routine maintenance is happening somewhere in the background.
Business owners and executives do not need to become web developers overnight, but they do need to ask better questions. If you have an internal IT team, managed service provider, web agency or hosting partner, now is the time to act.
Ask your provider directly whether your platform is WordPress, Joomla, Craft CMS or any other system flagged in ASD's advisory. Get a clear, written answer — not a vague reassurance.
Ask whether logs have been reviewed for abnormal requests and whether there is any sign of suspicious file creation or compromise. Do not accept "we think so" as an answer.
If your website were compromised today, who would know first? Who would respond? How quickly could you restore service? Has that process ever been tested? These are continuity questions — and continuity questions are management questions.
If your organization has a website and you are not completely sure how it is maintained, patched, monitored and backed up, now is a good time for a calm, structured review. Not a panic. Not a drama. Just a proper look under the hood before someone else does it for you. TCD is offering a free initial exploration and consultation for organizations that
When ASD Issues a Website Security Alert, Australian Small Businesses Should Pay Attention