EACA Summit 2026 was July 2–3, 2026 — see you next year!
East Africa Cyber & AI Summit
All news
SECURITY BRIEFINGJUNE 17, 20263 min read

Security Briefing | June 17, 2026 - CVSS 10.0 Joomla Flaw Exploited, JetBrains Plugins Steal AI Keys, 144 npm Packages Compromised

CISA adds a max-severity Joomla JCE plugin flaw (CVE-2026-48907, CVSS 10.0) to its KEV catalog with a federal patching deadline of June 19, 2026. A coordinated campaign plants 15 malicious plugins on the JetBrains Marketplace to steal AI API keys from developers. Meanwhile, a supply chain attack compromises 144 npm packages in the Mastra ecosystem via a hijacked contributor account.

By EACA Summit Content Team

Security Briefing | June 17, 2026 - CVSS 10.0 Joomla Flaw Exploited, JetBrains Plugins Steal AI Keys, 144 npm Packages Compromised

1. CISA Adds Actively Exploited Joomla JCE Plugin Flaw to KEV Catalog

CISA has added CVE-2026-48907, a maximum-severity improper access control vulnerability in the Widget Factory Joomla Content Editor (JCE) plugin, to its Known Exploited Vulnerabilities catalog. The flaw, with a CVSS score of 10.0, allows arbitrary PHP code execution and is being actively exploited in the wild. Federal agencies are required to patch by June 19, 2026.

Verified Facts

  • CVE-2026-48907 is a CVSS 10.0 vulnerability in Widget Factory Joomla Content Editor (JCE) plugin
  • CISA added the flaw to its KEV catalog on June 16, 2026, citing active exploitation
  • Federal agencies must patch by June 19, 2026

Evidence

  • CVE-2026-48907
  • CISA KEV catalog entry
  • BleepingComputer article: CISA orders feds to patch max severity Joomla plugin flaw by Friday

Impact

Organizations using Joomla with the JCE plugin are at immediate risk of remote code execution. Defenders should prioritize patching and monitor for exploitation attempts.

Confidence Level: High

The Hacker News | BleepingComputer | SecurityWeek

2. Malicious JetBrains Marketplace Plugins Steal AI API Keys

Researchers have identified 15 malicious plugins on the JetBrains Marketplace posing as AI coding assistants. These plugins exfiltrate AI provider API keys from developers. The campaign is described as coordinated and targets developers using DeepSeek and other LLMs.

Verified Facts

  • 15 malicious plugins were published on the JetBrains Marketplace
  • The plugins pose as AI coding assistants and steal AI API keys
  • The campaign is described as coordinated by cybersecurity researchers

Evidence

  • The Hacker News report: Malicious JetBrains Plugins Steal AI API Keys
  • BleepingComputer report: Malicious JetBrains Marketplace plugins steal AI API keys from developers

Impact

Developers using JetBrains IDEs with AI plugins are at risk of API key theft, potentially leading to unauthorized AI service usage and data exposure. Organizations should audit installed plugins and enforce marketplace trust policies.

Confidence Level: High

The Hacker News | BleepingComputer

3. 144 Mastra npm Packages Compromised in Supply Chain Attack

A Trojan horse labeled as a trusted software update carrying malware, backdoor, and exploit threats into an organization representing a software supply chain attack.

A supply chain attack codenamed 'easy-day-js' compromised 144 npm packages in the @mastra/* namespace. A single npm account (ehindero) mass-published malicious versions. The attack was detected by multiple security firms including JFrog, SafeDep, Socket, and StepSecurity.

Verified Facts

  • 144 npm packages under @mastra/* were compromised
  • The attack is attributed to a hijacked contributor account (ehindero)
  • Multiple security firms (JFrog, SafeDep, Socket, StepSecurity) reported the incident

Evidence

  • The Hacker News report: 144 Mastra npm Packages Compromised via Hijacked Contributor Account
  • Multiple security vendor confirmations

Impact

Organizations using Mastra packages in their AI application development should immediately check for compromised versions and rotate any exposed credentials. This attack highlights the risk of supply chain attacks in the npm ecosystem.

Confidence Level: High

The Hacker News

All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.

Next step

Continue with the official EACA Summit 2026 program.

View All Briefings