Drupal teams now have a shorter interval between major Chrome milestones to catch interface and JavaScript regressions before the supported browser window advances.
...more
Updating alone is not enough for every affected site. One module introduces a new permission requirement, while another has no fixed release and should be uninstalled.
...more
Internet-facing sites routinely receive probes for software they do not run. The useful signal is how each layer of the stack handles and records that unsolicited traffic.
...more
Resource-constrained maintainers can now seek subsidised cyber access, but OpenAI has not published criteria showing how independent open-source projects will qualify.
...more
Critical ratings are only part of the triage. Project reach varies sharply, and one advisory requires administrators to clean stored data after updating.
...more
Drupal AI integrations can depend on services whose runtimes, build pipelines and credentials sit outside the site's Composer-managed code. The LiteLLM incident shows how that external trust boundary can become part of the security picture.
...more
Unsupported CMS branches can turn a security patch into a major-version project. The 18 August releases show how support status changes the remediation burden across mixed CMS estates.
...more
The latest three projects have limited reported use, but the pattern extends beyond their reach. For affected site teams, the recurring security response is to uninstall the project rather than install an update.
...more