Tamper-Proof core updates for Joomla - TUF making it into 5.1


Joomla is built by many talented individuals, carefully reviewing every code contribution made to the project to ensure that a secure system is built.

But what would happen if an attacker is able to manipulate the Joomla update server? Or if a successful attack is made against the CDN that Joomla uses for update distribution? Or to ask a more generic question: how can we be sure that an update presented in Joomla backend is actually legitimate?

Continue reading
  950 Hits

Extended Security Support for Joomla 3.x - giving an old friend another chance


August 17, 2023 marks an historic date for the Joomla project: after more than 10 years, the project’s support for the 3.x version comes to an end. However there are still plenty of 3.x sites in the wild, some of them unable to migrate to 4.x in the remaining time frame. Do these sites need to be switched off in a couple of weeks?

Continue reading
  17948 Hits

Joomla TUF sprint june 2022 - Keeping the trojan horse outside of Joomla’s walls


Have you ever heard the story of the ancient city Troy? It had massive walls, keeping attackers outside and the city safe. However, the greek army, attacking the city, had a genius idea: they pretended to stop their attack and travel back home, while leaving a gift for the people of Troy: a huge wooden horse. The people of Troy were thankful for that gift and pulled the horse inside the city's walls - not knowing that greek soldiers have hidden themselves in the horse, crawling out at night, opening the doors for the rest of their army and thereby dooming the city.

Continue reading
  30908 Hits

J and Beyond 2020 - Bridging the Corona Gap


When our team kicked off organizing an international Joomla conference in May 2020, we had no idea that a global pandemic would ruin all our plans. However, as a community born in the online world, nothing seemed more obvious than turning our beloved family meeting into an online event, bringing people from around the globe together in these crazy times.

Continue reading
  1949 Hits

J and Beyond 2020 will take place online


After JandBeyond, the international Joomla conference, took a break in 2019, finally having a JAB on the horizon again in 2020 was an extremely enjoyable thought.

Continue reading
  4888 Hits

Security Strike Team - 2019 Report


The Joomla Security Strike Team, JSST, is working tirelessly to keep the Joomla CMS secure and protect the millions of sites around the globe that are based upon it.

Continue reading
  2338 Hits

Secure all the things - Joomla Security Team Sprint, Cologne, May 2018

Secure all the things - Joomla Security Team Sprint, Cologne, May 2018

Joomla Security Team Sprint, Cologne, May 2018. I guess we all agree that it's one of Joomla's key priorities to offer a software that is as secure as possible, as this plays a crucial role in the user's experience running Joomla - a hacked user, is a very unhappy user.

Continue reading
  9859 Hits

CMS-Garden 2014 - It's growing!

CMS-Garden 2014 - It's growing!

Today the first "Christmas Market" in my hometown opened its doors – and each and every year that's the time when I realize, that another year is almost over. 2014 was a very successful year for Joomla – and I want to show you what the CMS-Garden has contributed to this success.

Continue reading
  11366 Hits

Joomla! at CeBIT 2014 - Big Business!

Joomla! at CeBIT 2014 - Big Business!

From March 10 - 14, CeBit, the world's largest IT fair opened its doors in Hannover, Germany. CeBIT is by far the most important IT related fair in Europe and also has a big international impact, which is underlined by the fact that this year’s CeBIT was visited by people from more than 100 different countries. Like last year, the Joomla! project, represented by a team of well known volunteers from the local community, was part of the CMS Garden booth in Hall 6 at the event.


Continue reading
  17428 Hits

CMS-Garden - Why Open Source CMS's Are Not Opponents

CMS-Garden - Why Open Source CMS's Are Not Opponents

Every so often I have some tweets in my timeline where I can watch people from Joomla! talking really bad about Wordpress. Or Drupal. Or another CMS. And most of the times, people do this because they see all the opensource CMS as opponents on something that they call "the CMS market". Now, take a seat, because here comes a shocking truth: neither Drupal nor Wordpress nor any other opensource CMS is an opponent for Joomla. 

Continue reading
  22668 Hits

By accepting you will be accessing a service provided by a third-party external to https://magazine.joomla.org/