SShortSingh.
Back to feed

Over 430,000 Drupal Sites Exposed; High-Risk Security Advisory Issued

0
·1 views

A security scan on September 24, 2026, found over 436,000 Drupal sites accessible on the public internet. On September 23, Germany's CERT-BUND issued a high-risk advisory covering 36 vulnerabilities in multiple popular Drupal add-on modules. The affected modules include Webform, Commerce Decoupled Checkout, and several others used for site functions. Fixed versions for all vulnerable modules have been released by their developers. Site administrators are urged to audit their installations, apply patches, and restrict unauthorized access to administrative routes.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

CSS @starting-style rule simplifies entry animations for web elements.

The CSS @starting-style rule allows developers to define the initial state of an element's properties for smooth entry animations. It is particularly useful for animating elements that transition from a display: none state to visible. The rule can be applied either nested within an element's main ruleset or as a separate standalone block. Its primary function is to provide a defined starting point from which standard CSS transitions can occur.

0
ProgrammingDEV Community ·

OpenAI, Anthropic, NVIDIA advance AI models and security in latest updates

OpenAI released GPT-6.1 Sol on September 29, enhancing its agent capabilities while maintaining existing pricing. Anthropic launched Claude Sonnet 5.5 on September 28, offering improved speed and potential cost savings. NVIDIA focused on enhancing agent security at lower system layers. The industry shift emphasizes operational concerns like agent longevity, access, and security. These developments mark a move from mere model launches to integrated AI systems.

0
ProgrammingDEV Community ·

Solo developer builds encrypted chat app with rooms, calls, and in-room games

A developer has created and maintains a chat application called PTT Chat single-handedly. The app features group rooms, voice and video calls, and in-room games, with direct messages secured by end-to-end encryption. It is currently built on a single Node.js process using SQLite for data storage, prioritizing simplicity for solo development and maintenance. The application's user interface is currently available only in Russian, with an English version planned for the future.

0
ProgrammingDEV Community ·

Low-Code Platforms Promise Speed but Raise Vendor Lock-In and Scalability Concerns

Low-code development platforms allow users to build software using visual interfaces and drag-and-drop components, promising faster delivery times. Proponents argue they enable rapid prototyping and allow non-technical staff to create basic applications. Traditional manual coding offers greater control, flexibility, and portability, but requires more technical expertise. Real-world examples show low-code can accelerate initial projects but may lead to scalability issues or vendor dependency, while a hybrid approach is sometimes adopted.

Over 430,000 Drupal Sites Exposed; High-Risk Security Advisory Issued · ShortSingh