Cybersecurity researchers have identified active exploitation of critical vulnerabilities in Joomla extensions, while Microsoft struggles to patch a zero-day flaw affecting on-premises SharePoint server environments.
Key Points
- Attackers are targeting Joomla websites by exploiting extension vulnerabilities that carry perfect 10 severity scores.
- The affected extensions include iCagenda and Balbooa Forms, which are widely used across the open-source content management system.
- Microsoft has failed to fully remediate a zero-day vulnerability in on-premises SharePoint, leaving systems exposed to ongoing attacks.
- Russian threat actors are currently impersonating Signal support staff to conduct sophisticated phishing campaigns against users.
- EQT has acquired a majority stake in the Swiss cybersecurity firm Acronis, valuing the company at approximately $3.5 billion.