INTEL_REPORT
The Hacker News · published 7/13/2026, 5:36:02 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild. The vulnerabilities, both rated 10.0 on the CVSS scoring system, are below - CVE-2026-48939 - A vulnerability in the iCagenda and …
https://thehackernews.com/2026/07/icagenda-and-balbooa-forms-joomla-flaws.html
sha256:558ee31f8532b0039c37e39789f667e16110827f0a602aa9da9065f02e3c6836
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| CVE-2026-48939 |
| Open → |
| cve | CVE-2026-56291 | Open → |
| cve | CVE-2025-6389 | Open → |
| cve | CVE-2025-12352 | Open → |
| cve | CVE-2025-32432 | Open → |
| cve | CVE-2026-3395 | Open → |
| cve | CVE-2026-29014 | Open → |