vulnerability iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days Two zero-day vulnerabilities in Joomla extensions – iCagenda and Balbooa Forms – are being actively exploited in a global campaign targeting vulnerable CMS systems. Both flaws allow for remote code execution via file upl… The Hacker News · Jul 13, 2026 Critical CVE-2026-48939CVE-2026-56291CVE-2025-6389AUjoomlavulnerabilityzero-day
threat-intel Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites A cybercrime crew exposed its operations – including tools, logs, and target lists – after leaving a server open for three weeks. The WP-SHELLSTORM operation, which involved planting webshells on vulnerable WordPress and… The Hacker News · Jul 10, 2026 High CVE-2026-3844CVE-2021-29441CVE-2026-3300CHwebshellvulnerabilityexploit
vulnerability 15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google A 15-year-old Linux kernel vulnerability, dubbed ‘GhostLock,’ has been exploited to earn a security researcher $92,000. The flaw allows for local privilege escalation and container escapes, highlighting the long-term ris… SecurityWeek · Jul 9, 2026 High CVE-2026-43499linuxkernelvulnerability