ASD header Alert status Critical

What the ASD’s latest security alert means for your organisation

On 9 July 2026, the Australian Signals Directorate issued a critical alert on a large-scale cybersecurity campaign exploiting content management systems, including WordPress and Joomla, across organisations of every size. We can’t recall ever seeing a specific alert from the ASD specifically about CMS platforms we’ve worked with for years, so it definitely stood out.

The vulnerabilities being exploited are already known, and patches have already been released. Some of what happens behind the scenes when a vulnerability like this is found is genuinely reassuring: this excellent article by Aaron D. Campbell outlines the coordination that goes into a responsible disclosure, where hosting providers can be pre-equipped with mitigations before a patch is even public.

In this case, though, the vulnerabilities named in the ASD alert are largely in third-party plugins that never went through anything like that process, which is a large part of why they’re now being exploited at scale. The organisations affected are primarily those who do not have oversight of their environment.

TechCrunch reported that even a conservative estimate puts the number of vulnerable WordPress sites in the tens of millions. The ASD alert also references a joint statement from the Five Eyes cyber security agencies on how AI is shortening the gap between a vulnerability becoming public and someone exploiting it.

The alert itself sets out detailed immediate mitigation advice, along with additional steps to protect your website. We recommend reviewing this with whoever manages your technical environment. If you’d like a hand working through what applies to your organisation, get in touch and we can talk it through.

Technical detail isn’t a leadership job

Knowing which CVE was exploited, or how a particular exploit chain works, is a job for whoever manages your systems day to day. Leadership needs to know the answer to a different, simpler question: who does what, when?

The fact is, software maintenance isn’t exciting and doesn’t raise revenue, and often an organisation doesn’t know they have a problem until they’re in the middle of it. Not all organisations have a documented process in place around digital accountability and risk mitigation.

What happens when this goes unanswered

We’ve seen what this looks like. A few years ago we worked with a client whose platform was running many versions behind current release, with known vulnerabilities sitting on the public exploit list. One day, the website was compromised – unauthorised content appeared on the homepage and members couldn’t log in.

We worked through the technical recovery to get the site cleaned and back online. However, the underlying problem was one of governance. Administrator access sat with one person, documentation was minimal, and the Board had no real oversight of infrastructure they were ultimately responsible for. The full story is in our case studies, including how we closed the security gaps, built a new technology governance model and rebuilt the platform, which not only improved the organisation’s cyber resilience but resulted in a reduction in annual operating costs of 75%.

We’ve written before about why cyber resilience should be about prevention, not just a good crisis response plan, and what happens when a technology investment gets treated as a one-off purchase rather than something requiring ongoing attention. The ASD alert is a current example of these patterns playing out at large scale.

Questions for your next leadership meeting

It’s worth asking a few questions of your tech staff, even if nothing has gone wrong yet:

  • Who is accountable for confirming that your website, plugins and any connected systems are kept updated?
  • How would your organisation find out about an alert like this one, and how quickly?
  • If that person left tomorrow, would anyone else know where to look?

If the answer to any of these is “we’re not sure,” that’s the gap to close.

A Technology Governance review covers exactly this: who has access to what, who’s accountable when something needs attention, and whether that was decided deliberately or simply grew that way over time. For a broader picture across your whole technology environment, an IT Current State Assessment covers security alongside six other connected areas.