Two significant cybersecurity warnings landed this week, and together they describe exactly where the threat landscape sits in mid-2026. ...
Neither of these is a theoretical future threat. The EU's action covers operations that have been running since at least 2010. The ACSC is warning about attacks that are happening right now. And the week's broader breach roundup from Kaseya adds two more data points: AssuranceAmerica disclosed a breach affecting nearly 7 million individuals, and hackers have claimed to have breached Deutsche Bank. If your organization has a website or does business in Europe, this week's news is directly relevant to your security posture.
What the EU Actually Exposed About Russia's FSB Operations
The EU's July 13 action is notable for its specificity. The bloc named Russia's FSB 16th Centre as the directing authority behind operations that have included infiltrating government networks, sabotaging critical infrastructure, and conducting cyber espionage against strategic targets across Europe. The FSB 16th Centre has carried out cyber espionage against French government bodies since 2010 and has been active against the French defence industry since 2016. France's Foreign Ministry announced plans to summon the Russian ambassador in Paris over the campaign targeting ten European countries.
The Turla group also known as Snake, Uroburos, and Waterbug is the most well-documented of the FSB 16th Centre's associated groups. Turla has been operational since at least the late 1990s and is one of the most sophisticated cyber-espionage actors tracked by Western intelligence. Its targets historically include government ministries, embassies, military organizations, research institutions, and pharmaceutical companies. The EU's public attribution and sanctions represent the most explicit official European response to Turla's operations to date.
The broader context is important. Russia has enlisted cybercriminals, self-proclaimed hacktivists, and private companies to carry out these operations alongside FSB-directed groups. CISA joined NSA, FBI, DC3, and international partners this week in a separate advisory warning of Russian cyber threat activity targeting communications, energy, government, and other critical infrastructure sectors specifically calling out router hygiene as a key defense gap being exploited. These two actions together paint a picture of Russian cyber operations that are broad, sustained, and currently active across both European government targets and Western infrastructure.
The CMS Attack Wave and Why AI Is Making It Worse
The ACSC's warning describes a large-scale exploitation campaign targeting vulnerabilities in CMS platforms and plugins globally. The specific platforms named are WordPress, Craft CMS, MaxSite CMS, MetInfo CMS, and Joomla JCE. The specific plugins named include Simple File List, WavePlayer, Ninja Forms, and Craft CMS plugins. Most of the CVEs being exploited are from 2025 or 2026 meaning these are recent vulnerabilities, not ancient unpatched issues. The attack method is webshell deployment: attackers gain access to a website, plant a webshell that gives them persistent backdoor access, and use that access to steal credentials, disrupt services, deploy additional malware, or move deeper into connected networks.
The AI angle in the ACSC advisory is the part that deserves direct attention. The ACSC stated that the rapid scanning and exploitation of CMS vulnerabilities "could indicate use of offensive AI-powered tooling." This aligns with a rare joint statement released by Five Eyes intelligence agencies late last month warning that frontier AI will "fundamentally" transform the threat landscape "within months." When government intelligence agencies are publicly saying AI-accelerated attacks are arriving imminently, the timeline for organizations to update CMS installations is not "when we get around to it."
BleepingComputer's coverage includes the ACSC's direct language: "A large-scale exploitation campaign is targeting various vulnerabilities in content management systems globally, including in Australia, with many small- to medium-sized Australian businesses impacted. Malicious cyber actors are actively scanning websites for opportunities to deploy webshells, leveraging various vulnerabilities affecting CMS software and plugins." The phrase "actively scanning" means this is not speculative. Automated scanners are hitting sites right now looking for unpatched versions.
AssuranceAmerica and Deutsche Bank The Week's Other Two Stories
AssuranceAmerica a US insurance provider covering auto, renters, and commercial auto insurance across 14 states disclosed a breach affecting 6,998,886 individuals. The company filed with Maine's Office of the Attorney General after detecting unauthorized access to its systems on March 17. Attackers stole a broad range of customer information. The disclosure timeline detected March 17, disclosed in July is within statutory requirements but represents months during which affected individuals had no notification that their data had been stolen.
The Deutsche Bank claim is unverified as of the Kaseya roundup publication. Hackers claiming a breach of a major financial institution is a category of announcement that requires careful evaluation these claims range from genuine access to exaggerated or fabricated. Deutsche Bank has not publicly confirmed a breach. It is included here as reported, with the caveat that confirmation from the bank or regulators has not appeared in reporting reviewed for this post.
What to Actually Do This Week
The ACSC's remediation guidance is specific and actionable. For website administrators: apply the latest security updates for all CMS platforms and plugins immediately. Remove unused plugins every inactive plugin with an unpatched vulnerability is an attack surface. Enable automatic updates where possible. Implement read-only directories for CMS file systems where write access is not operationally required. Set up continuous monitoring for unauthorized file creation webshell deployment creates new files in predictable locations.
For organizations that may already be compromised: inspect your CMS for webshells and vulnerable plugins. Examine web access logs for IP addresses making GET or POST requests to unexpected paths. If you find a webshell, treat the entire server as compromised isolate it, audit all authentication credentials associated with it, and check network logs for evidence of lateral movement. The ACSC's language is clear: do not simply remove the webshell and consider the issue resolved. The webshell is evidence of access, not the totality of what an attacker may have done.
For the Russian FSB/Turla threat specifically, the CISA advisory on router hygiene is the most immediately actionable guidance for organizations operating network infrastructure. The advisory is available at cisa.gov and covers specific mitigation steps for the router targeting campaign. For organizations in the sectors named communications, energy, government reviewing that advisory this week rather than next month is the appropriate response given the current threat activity level.
Frequently Asked Questions
Q: What did the EU expose and sanction Russia for in July 2026?
On July 13, 2026, the EU sanctioned 9 individuals and 4 organisations connected to Russia's FSB 16th Centre for directing multi-year cyber operations including Turla against France, Germany, Poland, and 7 other member states. The FSB has conducted cyber espionage against French government bodies since 2010 and the French defence industry since 2016.
Q: Which CMS platforms are being targeted in the global attack campaign?
WordPress, Craft CMS, MaxSite CMS, MetInfo CMS, and Joomla JCE plus plugins including Simple File List, WavePlayer, and Ninja Forms. Most CVEs exploited are from 2025-2026. The ACSC warned that AI-powered tooling may be accelerating the campaign's scanning and exploitation scale.
Q: What should website administrators do immediately?
Apply all CMS and plugin updates now. Remove unused plugins. Enable automatic updates. Implement read-only directories. Monitor for unauthorized file creation. If you find a webshell treat the entire server as compromised, isolate it, audit all credentials, and check network logs for lateral movement.
Q: How many people were affected by the AssuranceAmerica breach?
6,998,886 individuals. Detected March 17, 2026, disclosed in July 2026 via Maine's Office of the Attorney General. AssuranceAmerica covers auto, renters, and commercial auto insurance across 14 US states. A broad range of customer information was stolen.
References
- Kaseya. The Week in Breach News: July 15, 2026. kaseya.com
- BleepingComputer. Australia warns of global campaign targeting vulnerable CMS platforms. July 10, 2026. bleepingcomputer.com
- European Pravda. EU exposes multi-year Russian cyber campaign, imposes sanctions. July 13, 2026. pravda.com.ua
- CISA. CISA Joins NSA, FBI, DC3 and International Partners Warning of Russian Cyber Threat Activity. July 2026. cisa.gov
- Infosecurity Magazine. Australian Cyber Agency Warns of Global CMS Exploitation Campaign. July 2026. infosecurity-magazine.com
