The Drupal AI Security Initiative Made Finding Bugs Cheap, and the Advisory Count Shows It
Sixteen contributed module advisories landed on September 2, 2026, five of them rated Critical. Fifteen landed the week before. It is tempting…
Information security is the practice of protecting systems, data, and users from compromise and loss. Articles in this category cover threat models, social engineering, authentication, compliance considerations, and the operational habits that keep an organization defensible at scale.
Sixteen contributed module advisories landed on September 2, 2026, five of them rated Critical. Fifteen landed the week before. It is tempting…
A self-replicating worm has been moving through the npm registry since September 2025, and the variant researchers were writing about last month…
Ten Drupal security advisories for contributed modules published on August 26, 2026, running from SA-CONTRIB-2026-108 to SA-CONTRIB-2026-117, every one rated moderately critical.…
Anthropic has told affected Claude users that a bad actor is using commodity infostealer malware to lift active login sessions off their…
The interesting security question about AI agents in 2026 has stopped being what the model will say and started being what the…
Wordfence disclosed an unauthenticated arbitrary file upload flaw in Gravity Forms, tracked as CVE-2026-19513 and rated CVSS 8.1, affecting versions up to…
We have written about the OpenAI and Hugging Face incident twice, and both times on the framing that a set of evaluation…
Package registry security is not a thing most teams have a plan for. The registry is plumbing. It caches dependencies, it sits…
Local ai agent security has a founding assumption that almost nobody states out loud, and CVE-2026-65105 is what happens when it fails.…
The cra reporting obligations under the EU Cyber Resilience Act take effect on September 11, 2026. From that date, manufacturers of products…