vulnerability iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days Two zero-day vulnerabilities in Joomla extensions – iCagenda and Balbooa Forms – are being actively exploited in a global campaign targeting vulnerable CMS systems. Both flaws allow for remote code execution via file uploads, and CISA has added them to its Known Exploited Vulnerabilities (KEV) catalog. Federal Civilian… The Hacker News · Jul 13, 2026 Critical CVE-2026-48939CVE-2026-56291CVE-2025-6389AUjoomlavulnerabilityzero-day
threat-intel Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites A cybercrime crew exposed its operations – including tools, logs, and target lists – after leaving a server open for three weeks. The WP-SHELLSTORM operation, which involved planting webshells on vulnerable WordPress and… The Hacker News · Jul 10, 2026 High CVE-2026-3844CVE-2021-29441CVE-2026-3300CHwebshellvulnerabilityexploit