iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
2026-07-13T07:24:06Z•c55907f02b59d9220a4a803507eb39eac3163d797e4a72eb220cfa358f984da9
Balbooa-FormsCISA-KEVcritical-vulnerabilitiescryptocurrency-theftdosfirmware-bootloadergitHub-compromiseiCagendainfostealerjoomlanpm-compromiseprivilege-escalationremote-code-executionsupply-chainxringszimbra
What happened
Multiple high-impact incidents reported: CISA added two 10.0-CVSS Joomla extension zero-days (including CVE-2026-48939) affecting iCagenda and Balbooa Forms to its Known Exploited Vulnerabilities list; a malicious jscrambler@8.14.0 npm release contained a preinstall hook that drops a Rust-based infostealer; and Microsoft patched a Defender privilege-escalation bug (CVE-2026-50656). The feed also describes other serious supply-chain and exploitation activity — GitHub/package registry compromises that push wallet-key-stealing packages, destructive/backdoor families (GigaWiper, GodDamn), firmware
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- c55907f02b59d9220a4a803507eb39eac3163d797e4a72eb220cfa358f984da9
- Enrichment time
- 2026-07-13T07:24:06Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.