A national alert about a large-scale CMS exploitation campaign points to a familiar but stubborn problem: internet-facing websites are only as safe as their weakest patch, plugin, or admin control.