Hotline: 0274 383 347
Sunday, 24-8-25 06:24:22

World

Hotline: 0274 383 347

Millions of websites hit by Drupal hack attack

Up to 12 million websites may have been compromised by attackers who took advantage of a bug in the widely used Drupal software.


Millions of sites are managed and updated using Drupal


The sites use Drupal to manage web content and images, text and video.

Drupal has issued a security warning saying users who did not apply a patch for a recently discovered bug should "assume" they have been hacked.

It said automated attacks took advantage of the bug and can let attackers take control of a site.

'Shocking' statement

In its "highly critical" announcement, Drupal's security team said anyone who did not take action within seven hours of the bug being discovered on 15 October should "should proceed under the assumption" that their site was compromised.

Anyone who had not yet updated should do so immediately, it warned.

However, the team added, simply applying this update might not remove any back doors that attackers have managed to insert after they got access. Sites should begin investigations to see if attackers had got away with data, said the warning.

"Attackers may have copied all data out of your site and could use it maliciously," said the notice. "There may be no trace of the attack." It also provided a link to advice that would help sites recover from being compromised.

Mark Stockley, an analyst at security firm Sophos, said the warning was "shocking".

The bug in version 7 of the Drupal software put attackers in a privileged position, he wrote. Their access could be used to take control of a server or seed a site with malware to trap visitors, he said.

He estimated that up to 5.1% of the billion or so sites on the web use Drupal 7 to manage their content, meaning the number of sites needing patching could be as high as 12 million.

Drupal should no longer rely on users to apply patches, said Mr Stockley.

"Many site owners will never have received the announcement and many that did will have been asleep," he said. "What Drupal badly needs but doesn't have is an automatic updater that rolls out security updates by default."

BBC

Malaysia launches ASEAN startup platform

Malaysia’s Ministry of Science, Technology and Innovation on June 25 officially launched “Startup ASEAN”,

ASEAN steps up terrorism fight in digital age

The Southeast Asia Regional Centre for Counter‑Terrorism (SEARCCT) under Malaysia's Ministry of Foreign Affairs held an international conference in Kuala Lumpur on June 24

Singapore's core inflation falls in May

Singapore’s core inflation and overall inflation are projected to average between 0.5% and 1.5% this year.

Indonesia concludes FTA talks with Eurasian Economic Union

Indonesia and the Eurasian Economic Union (EAEU) have officially concluded negotiations on a free trade agreement (FTA), aiming to sign the deal later this year,

ASEAN education ministers agree on joint statement on student dropout

The key content of the document titled "Accelerating Innovative Strategies: Addressing the OOSCY Challenges"

ASEAN reaffirms commitment to advancing green energy agenda

The 43rd ASEAN Senior Officials Meeting on Energy (SOME), held from June 16–18, marked a significant milestone as member states reached consensus on key strategic agendas

Indonesia to start operating first ocean power plant in 2028

The project is planned to be developed in two phases with each phase of 20 MW in East Nusa Tenggara and West Nusa Tenggara.

ASEAN identified as strategic partner of Argentina

In 2023, trade turnover between Argentina and ASEAN exceeded 9 billion USD, with Argentina

Leaders extend congratulations on Russia Day

General Secretary of the Communist Party of Vietnam Central Committee To Lam and State President Luong Cuong on June 12 cabled their messages of congratulations to Russian President Vladimir Putin on the occasion of Russia Day (June 12, 1990).

Indonesia aims to stop corn imports in 2026

President Prabowo noted that in 2024, the country imported around 500,000 tonnes of corn.

Enterprise - Brand

Company Social Media Net

Company VIETNAMNAY

Company HANEL MIROLIN

Company Keangnam - vina

Company HP Travel

Company Keloph