Security News

Drupal Update Fixes 10 Vulnerabilities, One Critical (Threatpost)
2016-02-25 17:30

Drupal addressed 10 vulnerabilities in the CMS this week, including a critical access bypass issue and another issue that could lead to remote code execution.

Drupal moves to fix flaws in update process (Help Net Security)
2016-01-11 16:28

After IOActive researcher Fernando Arnaboldi publicly revealed three crucial vulnerabilities in Drupal's update process last Thursday, the Drupal Security Team published a response on the Drupal Group...

Bugs in Drupal's update process could lead to backdoored updates, site compromise (Help Net Security)
2016-01-07 11:06

Drupal's update process is deeply flawed, says IOActive researcher Fernando Arnaboldi. He recently discovered three separate flaws in it, the worst of which could be exploited by attackers to swap ...