SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefTuesday, July 14, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Active Exploitation of Joomla RCE and Zimbra Flaws | CRITICAL |
|
5 C2 IPs | 3 OTX IOCs | 38 ARTICLES |
|
■ ANALYST TLDR This daily brief highlights active exploitation of remote code execution flaws in Joomla extensions (iCagenda and Balbooa Forms) and a critical code execution vulnerability in Zimbra. Additionally, threat actors are leveraging sophisticated techniques like the Forg365 Phishing-as-a-Service targeting Microsoft 365, alongside the emergence of macOS-focused CrashStealer malware bypassing Gatekeeper. Organizations must also address supply chain risks, exemplified by the backdoored Jscrambler npm package and the malicious ModHeader browser extension. |
|
■ CRITICAL STORIES CISA warns of actively exploited RCE flaws in Joomla extensions Attackers are actively exploiting arbitrary file upload vulnerabilities in iCagenda and Balbooa Forms extensions to achieve remote code execution, threatening web application integrity. |
Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns Progress Software has instructed customers to manually shut down ShareFile Storage Zone Controllers due to an active, credible threat, indicating an imminent risk of compromise. |
Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found A highly popular browser extension was discovered containing a hidden browsing-history collector, demonstrating the persistent danger of browser extension supply-chain compromises. |
Hackers backdoor Jscrambler npm package with infostealer malware Threat actors successfully published a malicious version of the widely used Jscrambler client-side security package on the npm registry, exposing downstream applications to credential theft. |
|
■ CVEs IDENTIFIED [CVE-TBD] Joomla iCagenda Extension — Remote Code Execution |
[CVE-TBD] Joomla Balbooa Forms Extension — Remote Code Execution |
[CVE-TBD] Zimbra Collaboration Suite — Remote Code Execution |
[CVE-TBD] RabbitMQ — Information Disclosure (OAuth Client Secret) |
|
■ THREAT ACTORS ShinyHunters | Cybercrime Group |
Abusing Microsoft Entra ID OAuth and conducting voice phishing (vishing) targeting SaaS applications. |
Russian GRU (Unit TBD) | State-Sponsored |
Sanctioned by EU/UK for coordinating cyberattacks and yearslong cyber spying campaigns against European governments. |
WorldLeaks | Extortion Group |
Claimed responsibility for a data breach at Centers Laboratory, stealing 720 GB of healthcare data. |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Attackers exploiting vulnerabilities in Joomla extensions (iCagenda, Balbooa Forms) |
| T1566 | | Phishing | Forg365 PhaaS using device code phishing and AitM tactics; ShinyHunters using voice phishing (vishing) |
| T1195 | | Supply Chain Compromise | Malicious Jscrambler npm package and backdoored ModHeader browser extension |
| T1539 | | Steal Web Session Cookie | Forg365 using Adversary-in-the-Middle (AitM) session theft |
| T1553.001 | | Subvert Trust Controls: Gatekeeper Bypass | CrashStealer macOS malware using notarized droppers |
| T1059.001 | | PowerShell | Threat actor using AI-generated PowerShell script for Active Directory mapping |
|
■ PATCH PRIORITY Progress ShareFile Storage Zone Controller — Active threat actor targeting product, vendor recommends immediate shutdown — [SW] |
Joomla iCagenda & Balbooa Forms Extensions — Actively exploited RCE vulnerabilities — [BC] |
Zimbra Collaboration Suite — Critical code execution vulnerability via malicious emails — [SW] |
RabbitMQ — Unauthenticated access to OAuth client secrets — [SW] |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Immediately shut down Progress ShareFile Storage Zone Controllers manually in response to the active security threat identified by Progress Software. |
| 2 | [P1] Apply patches or disable the affected Joomla extensions (iCagenda and Balbooa Forms) to mitigate active exploitation of [CVE-TBD] RCE vulnerabilities. |
| 3 | [P1] Patch Zimbra Collaboration Suite immediately to resolve the critical code execution vulnerability [CVE-TBD] triggered by malicious emails. |
| 4 | [P2] Audit npm dependencies for the Jscrambler package and ensure any installations of the compromised malicious versions are removed and replaced with clean versions. |
| 5 | [P2] Force-uninstall the ModHeader browser extension from all enterprise Google Chrome and Microsoft Edge deployments following its removal from official stores due to spyware behavior. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |