Your website might have just been caught in a digital dragnet, and you wouldn't even know it.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently flagged two serious security problems. These problems affect websites that use "Joomla," a popular tool for building and managing websites, and specifically two add-on programs called "iCagenda" and "Balbooa Forms." Think of Joomla as the operating system for your website, and these add-ons as apps you install to give it extra features, like an event calendar (iCagenda) or contact forms (Balbooa Forms).
What makes this news urgent is that these security problems, called "vulnerabilities," were already being secretly used by hackers. In cybersecurity, these are known as "zero-day exploits" [a zero-day is a security flaw that hackers discover and use before the software maker knows about it or can fix it]. It's like a thief finding an unlocked back door to your house that you didn't even know existed, and they're already inside before you can even think about locking it. Both of these specific flaws were rated a perfect 10 out of 10 on the danger scale, which is as bad as it gets.
Essentially, if you run a Joomla website and use either the iCagenda or Balbooa Forms extensions, there's a good chance hackers might have already slipped through these holes. CISA added these flaws to its "Known Exploited Vulnerabilities" (KEV) catalog [a list of security weaknesses that CISA knows are being actively used by hackers]. This catalog is a critical resource for government agencies and private organizations to prioritize what security issues they need to fix right now.
Unlike some security scares that are just theoretical, this one is very real and actively happening. If you manage a Joomla site with these extensions, the immediate step is to check for updates from iCagenda and Balbooa Forms. Apply any available patches [software updates designed to fix a bug or security flaw] right away. If updates aren't available, you might need to temporarily disable or remove these extensions until a fix is released.
This incident highlights a growing trend where attackers target third-party add-ons and extensions, rather than just the core software itself. Many websites rely on a patchwork of different tools and plugins, and each one can become a potential weak point. It's a reminder that your website's security is only as strong as its weakest link, often found in the smaller components you use.
If you use Joomla with iCagenda or Balbooa Forms, update immediately or disable those extensions.