CISA has added two CVSS 10.0 arbitrary file upload flaws in the iCagenda and Balbooa Forms Joomla extensions to its Known Exploited Vulnerabilities catalog after confirmed in-the-wild exploitation. Federal agencies must patch by July 13 while all Joomla administrators are advised to update to the fixed versions released in June and July.

Attackers can upload arbitrary files, including PHP scripts, through the file attachment feature, leading to data theft, web shell installation, and full website compromise.
The vulnerability permits upload of dangerous file types such as executables, resulting in remote code execution and complete site takeover.
These maximum-severity RCEs via unauthenticated uploads highlight why extension inventories and rapid patching remain non-negotiable for any Joomla deployment.
Tap a lens to see what this story means for you.
Reader-supported · The Brief
Liked this? The Brief brings you the whole day in tech, verified, every morning. Two minutes, free forever.
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
NVIDIA has partnered with SB Energy to secure an initial 4.25 IT-GW of AI capacity at the PORTS-Pike campus in Ohio, with OpenAI as the customer for the full 8 IT-GW site under a 20-year lease. The agreement features a $1.5B NVIDIA investment in SB Energy, credit support for the buildout, creation of tens of thousands of jobs and an $80M community benefits fund.
The fifth beta of iOS 27 arrived this week alongside an alleged iPhone 18 Pro Max battery leak showing 5,391 mAh capacity, screen protector images confirming asymmetric corners on the foldable iPhone Ultra, and Mark Gurman's report on radical Apple Watch redesigns that may include round faces and screenless trackers.
ShinyHunters obtained and later leaked personal data belonging to 1.6 million RingCentral accounts after a July breach. The incident touched only a limited portion of the cloud communications provider’s customers and left core services untouched.