iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days

2026-07-13T07:24:06Zc55907f02b59d9220a4a803507eb39eac3163d797e4a72eb220cfa358f984da9
Balbooa-FormsCISA-KEVcritical-vulnerabilitiescryptocurrency-theftdosfirmware-bootloadergitHub-compromiseiCagendainfostealerjoomlanpm-compromiseprivilege-escalationremote-code-executionsupply-chainxringszimbra

What happened

Multiple high-impact incidents reported: CISA added two 10.0-CVSS Joomla extension zero-days (including CVE-2026-48939) affecting iCagenda and Balbooa Forms to its Known Exploited Vulnerabilities list; a malicious jscrambler@8.14.0 npm release contained a preinstall hook that drops a Rust-based infostealer; and Microsoft patched a Defender privilege-escalation bug (CVE-2026-50656). The feed also describes other serious supply-chain and exploitation activity — GitHub/package registry compromises that push wallet-key-stealing packages, destructive/backdoor families (GigaWiper, GodDamn), firmware

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
c55907f02b59d9220a4a803507eb39eac3163d797e4a72eb220cfa358f984da9
Enrichment time
2026-07-13T07:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.