Website security vulnerabilities don’t always make the news.
Sometimes they’re quietly patched by developers before anyone notices.
Other times, attackers move quickly.
That’s what makes the latest warning from the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) particularly relevant to Australian businesses.
The ACSC has identified a large-scale exploitation campaign targeting vulnerabilities in content management systems globally, including websites in Australia. The campaign is targeting vulnerable CMS software and plugins, with malicious actors actively scanning websites for opportunities to gain access and deploy webshells.
For businesses running websites on platforms such as WordPress, this is a useful reminder that website security is an ongoing responsibility, not something that is completed when a website launches.
What’s happening?
The campaign is targeting known vulnerabilities across a range of CMS platforms and plugins.
The vulnerabilities include weaknesses that can allow unauthenticated file uploads, remote code execution, server-side request forgery and other forms of unauthorised access.
The affected software identified by the ACSC includes a number of WordPress plugins, as well as Craft CMS, MaxSite CMS, MetInfo CMS and Joomla JCE.
Once attackers gain access, they may deploy a webshell.
A webshell is essentially a malicious file that gives an attacker a way to interact with a compromised web server remotely.
That can potentially allow them to alter a website, capture information entered by users, upload additional malware or use the compromised server as a pathway towards other systems.
The ACSC specifically warns that this campaign has impacted small and medium-sized Australian businesses.
Why known vulnerabilities are still dangerous
One of the important things to understand is that these aren’t necessarily brand-new vulnerabilities.
Many have already been publicly disclosed and patches are available.
That’s exactly what makes ongoing maintenance so important.
Once a vulnerability becomes public, attackers don’t need to discover it themselves. They can study the vulnerability, identify websites running affected software and automate attempts to exploit them.
The ACSC has specifically advised organisations to ensure website software and associated plugins are rapidly patched and kept up to date.
What should website owners do?
The ACSC recommends that affected organisations investigate their environments for signs of compromise, including abnormal files and suspicious web requests.
If a compromise is identified, the affected system should be treated as compromised, investigated and remediated before being returned to service.
The guidance also recommends patching vulnerable systems and restoring websites from a recent known-good backup where appropriate.
For most business owners, however, the bigger question is simpler:
Who is actually responsible for doing this?
This is why ongoing maintenance matters
Knowing that a vulnerability exists isn’t enough.
Someone needs to know whether your website is affected.
Someone needs to assess the available patch.
Someone needs to apply the update safely.
Someone needs to check that the website still works afterwards.
And someone needs to be watching for new vulnerabilities tomorrow, next month and next year.
That’s the difference between simply owning a website and having a website that is actively managed.
At Codex, ongoing website maintenance includes keeping the underlying platform and supported components maintained as part of the broader responsibility of keeping a website secure, stable and operational.
If your website isn’t covered by an ongoing maintenance agreement, there is no guarantee that newly disclosed vulnerabilities will be identified and addressed as they emerge.
That doesn’t mean a maintenance agreement makes a website immune to attack. No responsible provider can make that promise.
It means there is a defined process and accountable team responsible for keeping the website maintained and responding to emerging risks.
Security doesn’t stop at WordPress
It’s also important to remember that a website is more than its CMS.
Hosting infrastructure, server configuration, user accounts, access controls, backups, monitoring and third-party services all form part of the security picture.
A secure website therefore needs more than a single security plugin.
It needs ongoing attention across the environment.
The bigger lesson
This latest ACSC alert is a good example of why website maintenance should be viewed as part of your business’s security posture.
Vulnerabilities will continue to be discovered.
Attackers will continue looking for exposed systems.
The technology behind your website will continue to change.
The question isn’t whether another vulnerability will eventually affect something in your environment.
It’s whether you’ll know about it, understand the risk and have someone responsible for dealing with it.
Is your website actively maintained?
If you’re not sure who is responsible for monitoring vulnerabilities, applying security updates and checking that your website remains secure and operational, it’s worth finding out.
If your website is already covered by a Codex maintenance agreement, our team manages these ongoing responsibilities as part of the service.
If it isn’t, talk to us about putting an ongoing maintenance and security arrangement in place.