Active exploitation against iCagenda and Balbooa Forms shows how a routine upload feature can become a dangerous server-side trust boundary when controls are too loose.
CISA’s KEV catalog now includes iCagenda and Balbooa Forms, a reminder that upload features can become code-execution territory when dangerous files are not tightly controlled.
A fresh warning about exploited flaws in two Joomla extensions shows how the quietest part of a website can become the most dangerous one.
CISA’s latest KEV additions show how quickly a mix of web platforms and extensions can become an operational problem, not just a routine update item.