What Business Owners Need to Know This Week

Week 29 (5–12 July 2026) produced no new confirmed South African breach, intrusion or leak-site listing — the sixth consecutive quiet week — while the exploitation tempo outside our borders tripled. CISA added six actively exploited vulnerabilities in seven days, every one rated CVSS 9.8 or higher, each on a roughly three-day remediation clock under BOD 26-04 rather than the old three-week BOD 22-01 fuse. Four of the six are file-upload flaws in third-party Joomla extensions — precisely the content-management stack sitting under a large share of South African SME, NGO and municipal websites. Separately, analysis published on 6 and 7 July put 3,219 breach notifications to the Information Regulator in FY2025/26 at an estimated R141.96 billion of economic drag, or 1.81% of GDP — published while the Regulator itself has issued nothing since 2 June.

The Bottom Line: The exposure this week is not your SOC’s servers — it is the brochure website marketing outsourced in 2019 and nobody has patched since. Four of six new KEV entries target Joomla page-builder extensions on an asset class most boards have never been shown. Meanwhile the operative number for every security business case changed: at R44.1 million, the average South African breach now costs more than four times POPIA’s R10 million maximum fine. If you have been sizing security spend against the penalty, you have been sizing it against the wrong number by a factor of four.

The Week in Numbers

  • 109 cumulative SA ransomware victims — unchanged from W28, with zero new SA leak-site postings for a sixth consecutive week; HIGH threat level for the 9th consecutive week.
  • 6 new CISA KEV additions — four on 7 July, two on 10 July; triple the prior week’s volume and none rated below CVSS 9.8.
  • ~3 days — the remediation clock now running under BOD 26-04, down from the three weeks most internal patch SLAs were copied from.
  • 4 of 6 — new KEV entries that are third-party Joomla extension file-upload flaws: SP Page Builder, Page Builder CK, iCagenda and Balbooa Forms.
  • Under 2 hours — time from public disclosure to in-the-wild exploitation of Adobe ColdFusion CVE-2026-48282 (CVSS 10.0).
  • 3,219 breach notifications — reported to the Information Regulator in FY2025/26, about 268 a month, against 2,374 the prior year.
  • R141.96 billion / 1.81% of GDP — estimated annual economic cost of SA data breaches, derived from the IBM 2025 SA average of R44.1 million per breach.
  • R6 million — ICASA penalty against Session Telecoms for SIM-boxing and CLI manipulation, confirmed 9 July.
  • Day 15 — Oracle EBS Payments CVE-2026-46817 exploited in the wild and still not KEV-listed.
  • 5,811 arrests / USD 293 million — INTERPOL Operation First Light 2026 results across 97 countries.

Major Incidents: Who Was Hit and How

Joomla Mass Exploitation — The SA SME and Municipal Web Stack

Four of the six vulnerabilities CISA added this week are file-upload flaws in third-party Joomla extensions, and the pattern is coordinated rather than coincidental: JoomShaper SP Page Builder CVE-2026-48908 (CVSS 10.0) was exploited as a zero-day before any patch existed, and Joomlack Page Builder CK CVE-2026-56290 (10.0) was hit on 27 June within hours of its fix shipping. iCagenda CVE-2026-48939 and Balbooa Forms CVE-2026-56291 (both 9.8) followed on 10 July. The attack chain is uniform — upload a PHP file through a component that fails to validate type, execute it, then create a Joomla Super User account so the shell is redundant. The persistence account survives the patch. No South African victim has been named, but the exposed asset class is the one organisations do not think of as an asset: the brochure website, the events page, the contact form — frequently sharing hosting with, or holding credentials into, systems that do matter. Patch to SP Page Builder 6.6.2+ and Page Builder CK 3.6.0, then hunt for the web shell at /media/com_pagebuilderck/gfonts/bhup.php and for POSTs to index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon.

Adobe ColdFusion — Exploited Two Hours After Disclosure

CVE-2026-48282 (CVSS 10.0) is a path traversal in the ColdFusion RDS FILEIO handler giving unauthenticated arbitrary file write and remote code execution on ColdFusion 2025.9, 2023.20 and earlier. It was exploited in the wild less than two hours after public disclosure, and its KEV deadline of 10 July has already lapsed. Change-approval cycles are now demonstrably slower than the attack. Apply the 30 June Adobe update, disable RDS in production, and — critically — if the server was internet-facing and unpatched between 30 June and 7 July, run a compromise assessment rather than assuming the patch closed the door. A patch applied after exploitation remediates the vector, not the intrusion.

Exploited but Unlisted — Gitea and Oracle EBS

Two CVSS 9.8 flaws are under active exploitation with no KEV listing at all. Gitea CVE-2026-20896: official Docker images at or below 1.26.2 ship with REVERSE_PROXY_TRUSTED_PROXIES set to a wildcard, so any source IP can send an X-WEBAUTH-USER header and authenticate as any user — including an administrator — exposing source code and CI secrets. Upgrade to 1.26.3 or 1.26.4, restrict trusted proxies, strip the header at the edge and rotate repository secrets. Oracle EBS Payments CVE-2026-46817 has now been exploited for over two weeks and remains absent from the catalogue. The KEV is a floor, not a work queue: rebuild your patch SLA around exploitation evidence, not catalogue membership.

ICASA — R6m Penalty for SIM-Boxing and CLI Manipulation

The week’s only concrete South African regulatory action came from ICASA, whose Council approved Complaints and Compliance Committee findings against Session Telecoms on 18 June, reported 9 July: R3 million under Regulation 6(3)(f) and R3 million under 6(3)(g), cease-and-desist orders, barring and withdrawal of numbering resources, and 24 months of monthly compliance reporting covering call records and international traffic. The underlying MTN complaint alleged CLI manipulation, call refiling and SIM-boxing. Session Telecoms is taking the finding on review and alleges the practice is industry-wide — an untested claim, but one worth tracking: if borne out, caller-ID spoofing capability is more widely available inside SA networks than currently assumed.

POPIA and Regulatory

The Information Regulator has published nothing since 2 June — a sixth week of public silence, and that silence is itself the regulatory story, because it sits directly alongside the 3,219-notification figure. The TransUnion SA and Experian SA section 59 responses were due around 6 July; that date passed with no statement from the Regulator, neither bureau, and no coverage — a second consecutive week of silence on the highest-profile open POPIA matter. Do not read the absence of news as resolution, and do not read regulatory silence as regulatory tolerance: enforcement capacity is constrained, not absent, and unpaid infringement notices (Blouberg Municipality R500,000, FT Rams R100,000) are being pursued through the courts. On the FIC side, the cross-border cash conveyance regime that went live 1 July with its R100,000 declaration threshold produced no published seizures or forfeitures in its first fortnight; the second-batch Risk and Compliance Return deadline of 31 July still stands for legal practitioners, estate agents, high-value goods dealers and non-casino gambling — file rather than wait for FIC messaging.

Full Intelligence Report

The complete Week 29 technical report covers the full KEV batch analysis and BOD 26-04 clock change, the Joomla ecosystem exploitation chain with IOCs and hunt queries, the ColdFusion RDS compromise-assessment guidance, the Gitea and Oracle EBS unlisted-exploitation gap, the sector threat heatmap, the breach-cost economics in full, the ICASA findings, the FIC and POPIA regulatory position, structured hunt missions and the complete OSINT source list.

What Your Business Should Do Right Now

  • Inventory and patch every Joomla site you own — including the ones you forgot: Pull your DNS zone and certificate-transparency records, fingerprint every .co.za and .gov.za property your organisation owns or sponsors, and identify Joomla installations running SP Page Builder, Page Builder CK, iCagenda or Balbooa Forms. Patch, remove or take offline — then hunt for the bhup.php web shell, for new PHP files under media directories, and for Super User accounts created outside a change window.
  • Treat exposed ColdFusion as compromised until proven otherwise: CVE-2026-48282 was exploited under two hours after disclosure and its KEV deadline lapsed on 10 July. Apply the 30 June update, disable RDS in production, and run a compromise assessment on any instance that was internet-facing and unpatched between 30 June and 7 July.
  • Close the exploited-but-unlisted gap: Upgrade Gitea to 1.26.3/1.26.4, restrict trusted proxies, strip X-WEBAUTH-USER at the edge and rotate CI secrets. For Oracle EBS, sweep /OA_HTML/ibytransmit POSTs from 27 June, patch at the 21 July CPU and de-expose. Neither is in the KEV catalogue; both are being exploited now.
  • Recalibrate your KEV clock: Remediation deadlines under BOD 26-04 are running at roughly three days, not three weeks. Any internal SLA that says “patch KEV entries within 21 days” is now three weeks behind the federal standard it was copied from. Re-baseline, and re-check the Ubiquiti UniFi OS and Lantronix entries — they were due 26 June and are overdue.
  • Replace R10 million with R44.1 million in every business case: The average South African breach now costs more than four times POPIA’s maximum administrative fine. Reframe security investment on total breach cost — remediation, churn, downtime, reputational drag — and use the 3,219 notifications and 268-per-month run rate as your base rate.
  • Ask who owns the company’s websites: Ask for the list. If nobody can produce one within a day, that is the finding. Sites without an owner should be decommissioned, not patched.
  • Get third-party patch attestation in writing this week: One email, three answers — your web-hosting agency (Joomla extension versions), your MSP (SimpleHelp patched and tokens rotated) and your development partners (Gitea version and secret rotation). It should not take a week to get them.