Security researchers have identified critical vulnerabilities in websites running the Novarain/Tassos Framework (plg_system_nrframework), exposing them to unauthenticated file read, file deletion, and SQL injection attacks. The flaws stem from an insecure AJAX handler (task=include) that allows attackers to invoke internal PHP classes remotely. Exploiting these weaknesses, threat actors can read sensitive files accessible to the webserver, delete arbitrary files, and execute malicious database queries. When chained together, these issues enable attackers to steal administrator session data, access the Joomla backend, and deploy malicious extensions, ultimately achieving remote code execution (RCE) and full site takeover. The vulnerabilities exist because the framework exposes internal helper classes without proper validation or authentication controls. One gadget mishandles CSV loading, enabling arbitrary file reads; another allows deletion of attacker-specified paths; and a third permits SQL injection through unsanitized parameters. Since the framework is bundled with widely used Joomla extensions including Convert Forms, EngageBox, Google Structured Data, Advanced Custom Fields, and Smile Pack many sites inherit the risk indirectly. Because exploitation requires only unauthenticated AJAX requests, internet-facing sites are particularly vulnerable. Administrators must immediately update the Tassos Framework and affected extensions to patched versions or temporarily disable the vulnerable plugin until updates are applied. Additionally, organizations should restrict or filter com_ajax traffic via web server rules or a WAF and monitor logs for suspicious task=include requests or unexplained file deletions. Regular security hardening, least-privilege configurations, and timely patch management are essential to prevent exploitation and maintain website integrity.
Cloud Imperium Games (CIG), the developer behind Star Citizen and Squadron 42, has disclosed a cybersecurity incident that occurred in January 2026. The California-based studio, fo...
The University of Hawaii (UH) has confirmed a major cybersecurity incident in which a ransomware group breached systems within the UH Cancer Center’s Epidemiology Division and st...
LexisNexis Legal & Professional has confirmed that hackers breached its servers and accessed a portion of customer and business information, following the leak of approximately 2GB...