Daily Security Intel

Archives
Log in
Subscribe
July 14, 2026

[SecurityIntel] 14 Jul | Active Exploitation of Joomla RCE and Zimbra Flaws

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Tuesday, July 14, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Active Exploitation of Joomla RCE and Zimbra Flaws

CRITICAL

5

C2 IPs

3

OTX IOCs

38

ARTICLES

■ ANALYST TLDR

This daily brief highlights active exploitation of remote code execution flaws in Joomla extensions (iCagenda and Balbooa Forms) and a critical code execution vulnerability in Zimbra. Additionally, threat actors are leveraging sophisticated techniques like the Forg365 Phishing-as-a-Service targeting Microsoft 365, alongside the emergence of macOS-focused CrashStealer malware bypassing Gatekeeper. Organizations must also address supply chain risks, exemplified by the backdoored Jscrambler npm package and the malicious ModHeader browser extension.

■ CRITICAL STORIES

CRITICAL#1

CISA warns of actively exploited RCE flaws in Joomla extensions

Attackers are actively exploiting arbitrary file upload vulnerabilities in iCagenda and Balbooa Forms extensions to achieve remote code execution, threatening web application integrity.

CRITICAL#2

Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns

Progress Software has instructed customers to manually shut down ShareFile Storage Zone Controllers due to an active, credible threat, indicating an imminent risk of compromise.

HIGH#3

Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found

A highly popular browser extension was discovered containing a hidden browsing-history collector, demonstrating the persistent danger of browser extension supply-chain compromises.

HIGH#4

Hackers backdoor Jscrambler npm package with infostealer malware

Threat actors successfully published a malicious version of the widely used Jscrambler client-side security package on the npm registry, exposing downstream applications to credential theft.

■ CVEs IDENTIFIED

[CVE-TBD]

Joomla iCagenda Extension — Remote Code Execution

Critical

[CVE-TBD]

Joomla Balbooa Forms Extension — Remote Code Execution

Critical

[CVE-TBD]

Zimbra Collaboration Suite — Remote Code Execution

Critical

[CVE-TBD]

RabbitMQ — Information Disclosure (OAuth Client Secret)

High

■ THREAT ACTORS

ShinyHunters

Cybercrime Group

Abusing Microsoft Entra ID OAuth and conducting voice phishing (vishing) targeting SaaS applications.

Russian GRU (Unit TBD)

State-Sponsored

Sanctioned by EU/UK for coordinating cyberattacks and yearslong cyber spying campaigns against European governments.

WorldLeaks

Extortion Group

Claimed responsibility for a data breach at Centers Laboratory, stealing 720 GB of healthcare data.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Attackers exploiting vulnerabilities in Joomla extensions (iCagenda, Balbooa Forms)
T1566
Phishing | Forg365 PhaaS using device code phishing and AitM tactics; ShinyHunters using voice phishing (vishing)
T1195
Supply Chain Compromise | Malicious Jscrambler npm package and backdoored ModHeader browser extension
T1539
Steal Web Session Cookie | Forg365 using Adversary-in-the-Middle (AitM) session theft
T1553.001
Subvert Trust Controls: Gatekeeper Bypass | CrashStealer macOS malware using notarized droppers
T1059.001
PowerShell | Threat actor using AI-generated PowerShell script for Active Directory mapping

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Progress ShareFile Storage Zone Controller — Active threat actor targeting product, vendor recommends immediate shutdown — [SW]

[P1 PATCH NOW]≤24h

Joomla iCagenda & Balbooa Forms Extensions — Actively exploited RCE vulnerabilities — [BC]

[P1 PATCH NOW]≤24h

Zimbra Collaboration Suite — Critical code execution vulnerability via malicious emails — [SW]

[P2 PATCH NOW]≤72h

RabbitMQ — Unauthenticated access to OAuth client secrets — [SW]

■ RECOMMENDED ACTIONS TODAY

1[P1] Immediately shut down Progress ShareFile Storage Zone Controllers manually in response to the active security threat identified by Progress Software.
2[P1] Apply patches or disable the affected Joomla extensions (iCagenda and Balbooa Forms) to mitigate active exploitation of [CVE-TBD] RCE vulnerabilities.
3[P1] Patch Zimbra Collaboration Suite immediately to resolve the critical code execution vulnerability [CVE-TBD] triggered by malicious emails.
4[P2] Audit npm dependencies for the Jscrambler package and ensure any installations of the compromised malicious versions are removed and replaced with clean versions.
5[P2] Force-uninstall the ModHeader browser extension from all enterprise Google Chrome and Microsoft Edge deployments following its removal from official stores due to spyware behavior.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 15 Jul | Record Microsoft Patch Tuesday Fixes Active Zero-Days Older → [SecurityIntel] 13 Jul | RedHook Android Malware Abuses Wireless ADB Shell
Powered by Buttondown, the easiest way to start and grow your newsletter.