Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Joomla website administrators
Incident: Active zero-day exploitation of critical file upload vulnerabilities in Joomla extensions.
Impact: Full system compromise via unauthenticated remote code execution.
Attacker: Unidentified threat actors
Analysis: Two maximum-severity vulnerabilities allow unauthenticated attackers to upload malicious PHP files, resulting in full remote code execution. These flaws were exploited as zero-days, meaning attacks occurred before patches were available. The activity appears to be part of a larger, AI-accelerated global campaign targeting content management systems.
Recommendations: Update iCagenda to version 4.0.8/3.9.15 and Balbooa Forms to 2.4.1 immediately.; Scan the attachments and uploads folders for unauthorized PHP files or web shells.; Audit Joomla administrator accounts for any recently created or suspicious users.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source