THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Joomla zero-days: iCagenda and Balbooa Forms hit the KEV catalog after in-the-wild exploitation

Two maximum-severity Joomla extension flaws—added to CISA’s Known Exploited Vulnerabilities (KEV) catalog—signal active, real-world targeting rather than theoretical risk. Attackers are exploiting iCagenda and Balbooa Forms weaknesses to achieve remote code execution (RCE), which can quickly escalate from compromise to webshell deployment and persistence. Organizations running affected Joomla versions should prioritize patching and verify there are no indicators of webshell activity or abnormal outbound connections.

Source: The Hacker News


Progress tells ShareFile customers to shut down internet-facing Storage Zone controllers

Progress Software issued emergency guidance urging customers to manually shut down ShareFile Storage Zone Controllers while it investigates a credible threat. The incident highlights the operational risk of exposing admin/control components to the internet, especially in hybrid storage setups where a single compromised controller can facilitate broader access. Teams should review exposure, validate whether any suspicious traffic or authentication anomalies occurred, and ensure segmentation and least-privilege controls are enforced around storage infrastructure.

Source: SecurityWeek


Australia warns of ongoing CMS exploitation campaigns using webshells

Australia’s Signals Directorate (ASD) has alerted organizations to a large-scale campaign targeting common content management systems, including WordPress and Joomla, with the goal of deploying webshells. These attacks follow a familiar pattern: scan for known CMS weaknesses, exploit, then establish stealthy access for follow-on activity. If patching has been delayed, defenders should treat this as urgent—hunt for webshells, confirm plugin/theme integrity, and review server file changes and new scheduled tasks.

Source: Security Affairs


Unpatched AI vulnerabilities remain the norm: “99.9% of fixable” issues still open

Orca Security’s 2026 State of AI Security Report suggests that even when vulnerabilities are known and fixable, patching and remediation are not keeping pace with AI adoption. The report highlights that many organizations deploy agent frameworks and AI tooling into production while missing basic hygiene around dependency risk and vulnerability management. Security teams should extend scanning to AI infrastructure (agents, toolchains, model/runtime dependencies) and enforce release governance and update SLAs similar to traditional software.

Source: Help Net Security


Researchers propose an “AI safety rail” for cloud security research agents (Cynative)

Cynative, an open-source deep research agent, is designed to reduce the danger of LLMs holding real cloud credentials and making destructive changes during security testing. Instead of writing by default, it enforces restrictive behavior and checks the refusal on every call, aiming to prevent accidental deletions, permission flips, or secret leakage. For teams adopting AI-assisted security workflows, this is a reminder that “capability” must be paired with guardrails, constrained tooling, and robust guard-by-design controls.

Source: Help Net Security


ISC: Active scanning targets MCP servers and AI assistant credential exposure

The SANS Internet Storm Center reports ongoing scanning aimed at MCP (Model Context Protocol) servers and attempts to identify exposed AI assistant credentials. This suggests attackers are shifting attention from traditional web and email vectors toward AI-adjacent services where misconfiguration or leaked tokens can provide immediate access. Organizations should inventory MCP/AI integrations, audit network exposure, rotate credentials and tokens, and add monitoring for anomalous requests to AI-related endpoints.

Source: SANS Internet Storm Center (ISC)


Debian 13.6 (“trixie”) ships security corrections plus a Secure Boot certificate authority update

Debian 13.6 point release addresses security corrections across numerous advisories and includes a fix for a Secure Boot-related certificate authority issue. Specifically, it ties remediation to fwupd and the updated upstream component, reducing risk that systems relying on Secure Boot chain-of-trust could encounter reliability or validation problems. If you manage Debian fleets, treat this as a standard patch priority and validate Secure Boot/fedora-style boot validation in test environments before broad rollout.

Source: Help Net Security


You May Also Be Interested In...
UK and Allies urge critical sectors to improve defenses against Russian intelligence targeting
Zimbra patches critical code execution vulnerability
AI-generated code has made security debt a governance problem
Cybersecurity — July 13, 2026 | Briefing24