EACA Summit 2026 was July 2–3, 2026 — see you next year!
East Africa Cyber & AI Summit
All news
SECURITY BRIEFINGJULY 13, 20263 min read

Security Briefing | July 13, 2026 - Two CVSS 10.0 Joomla Extension Zero-Days in KEV, Misconfigured Server Exposes Three Evilginx Phishing Ops, EU Sanctions Russian Intelligence Officers

CISA added two maximum-severity Joomla extension zero-days (iCagenda CVE-2026-48939 and Balbooa Forms, both CVSS 10.0) to its KEV catalog following active exploitation. A misconfigured Python web server with directory listing exposed an attacker's full Evilginx toolkit, leading to the discovery of three Microsoft 365 phishing operations. The European Union has sanctioned Russian intelligence officers responsible for a years-long cyber espionage campaign targeting governments and critical infrastructure.

By EACA Summit Content Team

Security Briefing | July 13, 2026 - Two CVSS 10.0 Joomla Extension Zero-Days in KEV, Misconfigured Server Exposes Three Evilginx Phishing Ops, EU Sanctions Russian Intelligence Officers

1. CISA Adds Two Joomla Extension Zero-Days to KEV Catalog

CISA added two maximum-severity vulnerabilities in the iCagenda and Balbooa Forms Joomla extensions to its Known Exploited Vulnerabilities catalog, following reports of zero-day exploitation in the wild. Both flaws are rated CVSS 10.0 and allow remote code execution. This expands on the Joomla entries first added to KEV on July 08.

Verified Facts

  • CISA added CVE-2026-48939 (iCagenda) and a Balbooa Forms vulnerability to the KEV catalog
  • Both vulnerabilities are rated CVSS 10.0 and are actively exploited in the wild
  • SecurityWeek and The Hacker News both reported the CISA advisory

Evidence

  • CVE-2026-48939
  • CISA KEV catalog entry

Impact

Organizations using Joomla with these extensions are at high risk of remote code execution. Immediate patching is critical.

Confidence Level: High

Sources The Hacker News | SecurityWeek

2. Misconfigured Server Exposes Three Evilginx Phishing Operations

Illustration of an exposed phishing server with a misconfigured directory revealing malicious infrastructure used to target Microsoft 365 accounts.

French security firm Lexfo discovered a live Microsoft 365 phishing operation due to a misconfigured Python web server with directory listing enabled. The attacker's bash history revealed the entire toolkit, leading to the identification of two additional Evilginx operations. All three campaigns targeted Microsoft 365 credentials.

Verified Facts

  • A misconfigured Python HTTP server with directory listing exposed an attacker's toolkit
  • Lexfo identified three distinct Evilginx phishing operations targeting Microsoft 365
  • The incident was reported by The Hacker News

Evidence

  • Lexfo analysis
  • Attacker's bash history

Impact

Organizations using Microsoft 365 should be vigilant against Evilginx-based phishing attacks. This incident highlights the risk of misconfigured servers exposing adversary infrastructure.

Confidence Level: High

Sources The Hacker News

3. EU Sanctions Russian Intelligence Officers for Yearslong Cyber Spying Campaign

The European Union imposed sanctions on Russian intelligence officers accused of running a yearslong cyber espionage campaign targeting governments and critical infrastructure. The operation involved sustained online espionage and sabotage activities against European targets.

Verified Facts

  • EU sanctioned Russian intelligence officers for a cyber spying campaign
  • The campaign targeted governments and critical infrastructure
  • Reported by SecurityWeek

Evidence

  • EU sanctions list

Impact

Defenders should remain vigilant against Russian state-sponsored cyber activities, particularly targeting critical infrastructure and government networks.

Confidence Level: High

Sources SecurityWeek

Also Noted

Progress Software's urgent directive to ShareFile customers to shut down Storage Zone Controllers, first reported July 11, remains ongoing. Organizations that have not yet isolated affected systems should do so immediately pending further guidance from Progress.

All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.

Next step

Continue with the official EACA Summit 2026 program.

View All Briefings