Grilled Cheese

ExploreLog inSign up
Terms of UsePrivacy PolicyCommunity StandardsHelpGet the app

Grilled Cheese is a product of Village Compute

Version devBuilt at: 2026-10-10 20:13:24 EDT

Explore

PostsPeople
LatestRanked
@thedroptimes.bsky.socialOct 9, 2026, 1:48 PM

The Drupal Security Team published 26 contrib advisories across 25 projects, including a highly critical Block AJAX flaw and seven critical notices. Several fixes also require follow-up steps beyond updating packages.

www.thedroptimes.com/72734/drupal...

#Drupal #DrupalSecurity #OpenSource

Social media card for a The DropTimes report on 26 Drupal contributed-project security advisories. The headline asks, “The Update Is Installed. Is the Fix Complete?” Supporting text explains that some fixes require configuration changes, database updates or manual follow-up after the package is updated. An illustration shows a website interface with an open panel and warning symbol.
@thedroptimes.bsky.socialOct 8, 2026, 10:00 AM

Two new guides tackle different operational risks around modern Drupal: DrupalFit focuses on site security, while Pantheon examines reliability and governance in decoupled CMS deployments.

www.thedroptimes.com/72676/drupal...

#Drupal #DrupalSecurity #DecoupledDrupal

Editorial graphic for The Drop Times about two new eBooks examining Drupal security and decoupled CMS operations. The headline asks, “What Gets Harder After Drupal Goes Live?” Supporting text says the guides explore security gaps and operational complexity that can emerge once a site reaches production. The design features the covers of DrupalFit’s “Top Security Risks in Drupal Websites” and Pantheon’s “Decoupled, Governed, and Stable,” alongside an eBook illustration.
@thedroptimes.bsky.socialSep 17, 2026, 7:16 PM

Drupal core security updates fix a CKEditor 5 XSS vulnerability. A user who can create or edit content may target someone who later opens it through CKEditor, including privileged administrators.

Update to 10.6.17, 11.3.17, or 11.4.7.

https://bit.ly/4hxDe0j

#DrupalSecurity #CKEditor #WebSecurity

@thedroptimes.bsky.socialSep 17, 2026, 6:36 PM

Researcher Matan Kotick says Claude found and validated a Critical SQL injection in the amazee[.]ai Private AI Provider in about ten minutes. Drupal’s advisory confirms CVE-2026-87936 and the affected code path.

https://bit.ly/4haV1cf

#Drupal #DrupalSecurity #Claude #DrupalAI

TDT security card asks “How Far Did Claude Get In Ten Minutes?” and says it did not stop at finding vulnerable code, in an analysis of Drupal advisory SA-CONTRIB-2026-134 and its fixes.
@thedroptimes.bsky.socialSep 17, 2026, 12:49 PM

Larger Drupal security-advisory batches may reflect cheaper AI-assisted vulnerability discovery, not suddenly worse contrib code. The initiative reported 30+ issues and contributions to 10+ advisories and CVEs in six weeks.

https://bit.ly/4yM9JOo

#Drupal #DrupalSecurity #DrupalAI #OpenSource

@thedroptimes.bsky.socialSep 7, 2026, 7:14 PM

Drupal’s September 2 security batch includes 16 advisories across 14 contrib projects. Five are Critical, covering issues including account takeover, access bypass, and XSS. Corrective releases are available.

https://bit.ly/46awHCs

#Drupal #DrupalSecurity #SecurityAdvisory

TDT security card on 16 Drupal contributed-project advisories, including five Critical flaws and 12 access-bypass disclosures.