♡Follow0 Critical CVEs iCagenda and Balbooa Forms Joomla Flaws Exploited as Zero-Days; CISA Adds to KEV Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity vulnerabilities affecting iCagenda and Balbooa Forms extensions for Joomla to… ACSC arbitrary file upload Australia Balbooa Forms July 13, 2026
♡Follow0 Critical CVEs CVE-2025-12057: WavePlayer WordPress Plugin Vulnerability A vulnerability in the WavePlayer WordPress plugin exploited in a global CMS campaign for web shell deployment. CMS CVE-2025-12057 WavePlayer web shell July 10, 2026
♡Follow0 Cyber News Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites A cybercrime crew left its server exposed for three weeks, revealing the inner workings of a mass site-hacking operation tracked as WP-SHELLSTORM.… backdoor BestShell Breeze caching plugin CISA July 10, 2026