Zero-Day Attacks Reportedly Target iCagenda and Balbooa Forms on Joomla Sites

Zero-Day Attacks Reportedly Target iCagenda and Balbooa Forms on Joomla Sites

A new report says two popular Joomla extensions, iCagenda and Balbooa Forms, are being exploited before patches are available. Website owners should check their installations immediately.

The Hacker News has reported that security flaws in two Joomla extensions, iCagenda and Balbooa Forms, have been exploited as zero-day vulnerabilities. Joomla is a widely used content management system (CMS) that lets people build and manage websites without writing code from scratch. Extensions are add-on software packages that provide extra features, such as event calendars in the case of iCagenda or online form builders in the case of Balbooa Forms. When a flaw is exploited as a zero-day, it means attackers are actively using the weakness before the software developer has had a chance to release a fix, leaving site owners with no patch to install at the moment of attack.

This situation highlights a persistent risk for any website that runs on a CMS with third-party extensions. Core Joomla software is maintained by a central team and generally receives regular security updates, but extensions come from many different developers, some of whom may not have the resources or security expertise to audit their code thoroughly. As a result, a single vulnerable extension can provide a doorway into an otherwise well-maintained website. While the specific technical details of the iCagenda and Balbooa Forms flaws were not disclosed in the alert, the fact that they are being exploited as zero-days means that malicious actors have already figured out how to take advantage of them, possibly to steal data, install malware, or redirect visitors to harmful pages.

For website owners, the immediate concern is whether their site uses either of these extensions. Joomla administrators should log into their site's admin panel and check the extension manager to see if iCagenda or Balbooa Forms is installed. If either is present, the safest action is to disable it until a security update is released, unless a patch is already available from the developer. Keeping a site running with a known exploited extension is an open invitation to attackers. This is especially important for businesses that handle customer information, login credentials, or payment details, because a compromised site can lead to data breaches and loss of visitor trust.

Beyond this specific incident, the report serves as a reminder that security is not just about the core software but about every piece of code that runs on a server. Hosting providers and site administrators often focus on keeping the CMS core up to date, but extension updates lag behind. Automated update systems can help, but not all extension developers push updates promptly or clearly. A Web Application Firewall (WAF), which filters incoming traffic and blocks known attack patterns, can provide some protection even before a patch is available, because it can detect and stop malicious requests that try to exploit the flaw. Regular backups are also essential, because if a site is compromised, a clean backup allows a quick restoration while the root cause is addressed.

For businesses that rely on Joomla or other content management systems, security must be layered. Working with a security-focused infrastructure provider such as AEU-I can help ensure that the underlying server environment is hardened and that security monitoring is in place, reducing the chance that a zero-day flaw in a third-party extension turns into a full site takeover. AEU-I offers security-first IT and infrastructure consulting that can guide you through patching, extension audits, and proactive defenses for your website.

How to Protect Yourself

  1. Log into your Joomla website's admin area and look for iCagenda or Balbooa Forms in the list of installed extensions; if you see either one, turn it off until the developer releases a fix.
  2. Turn on automatic updates for Joomla and all extensions if available, or set a weekly reminder to check for updates manually.
  3. Ask your hosting provider if they offer a Web Application Firewall (a security filter that blocks harmful traffic before it reaches your site), and enable it if available.
  4. Make a full backup of your website files and database now and schedule regular backups so you can restore quickly if needed.
  5. Remove any extensions you no longer use, because old code can still contain security holes.

Related AEU services

  • AEU Panel Managed hosting control panel
  • AEU-I IT and security consulting