POPULARITY
Today we are talking about Security, Vulnerabilities, and how to avoid exposure with guest Dave Welch. We'll also cover Security Scanner as our module of the week. For show notes visit: https://www.talkingDrupal.com/567 Topics What Are CVEs CVE Lifecycle and Disclosure AI Era Security Challenges What CVE Program Excludes Patch Fast Reality Global Security Signals CVE Timing Judgment KEV Flags Explained CVE Updates Link Rot Who Decides CVE Sneaky Patch Dangers ADP Program Fixes Small Team Triage Vulnerability Tsunami AI Autonomous Security Future Legal Pressure Budgets Resources Psalm PHP Static Analysis Tool SARIF format PHP ecosystem Council of roots How AI Broke Open Source Security: End-of-Life Software Is the Most Exposed CVE podcast Vulncon PSIRT Guests David Welch - github: dwelch2344 dwelch2344 Hosts Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi JD Flynn - dorficus MOTW Correspondent Martin Anderson-Clutz - mandclu.com mandclu Brief description: Have you ever wanted a fast way to catch the security mistakes that slip into custom Drupal code — especially the code your AI assistant just wrote — before it ships? There's a module for that. Module name/project name: Security Scanner Brief history How old: created in July 2026 by Mayank Gupta (mayankguptadotcom) of Acquia Versions available: 1.0.0, which works with Drupal 10.3 and 11 Maintainership Actively maintained — created and shipped its first stable this summer, with steady development right through late July Security coverage Test coverage — and it's strong: unit and kernel tests, including a regression corpus built from real Drupal core advisories Documentation? In-depth README with a full check table and CI recipes, plus a CHANGELOG Number of open issues: 1 issue, not a bug Usage stats: 2 sites (it's brand new) Module features and usage Provide a Drush command, has no UI — you point drush security:scan at a module or any path, it reads the code statically, and prints a prioritized, OWASP-mapped list of things to review It's built for the age of AI-written code — the checks target the classes AI assistants keep reintroducing: routes with no access check, #markup and |raw XSS, missing CSRF tokens, unserialize() on untrusted data, hardcoded secrets Then there's an optional deep pass: with the Psalm static analysis scanning engine installed, it'll trace untrusted input across functions and files to catch cross-function issues. And it's honest about state — the report always says whether that deep pass ran, was skipped, or failed, so a failure never gets mistaken for a clean scan One nice detail under the hood: a tokenizer-backed "code map" that knows whether a match is real code, a comment, or a string — so it won't flag the word "unserialize" sitting in a doc comment. That kills the single biggest source of false positives The checks are regression-tested against real Drupal advisories (Drupalgeddon, Drupalgeddon2, the 2019 unserialize bug, etc) so a pattern that caused an actual CVE can't quietly come back in your custom code Output comes in three flavors: a readable table, JSON for CI and AI agents, and SARIF — which means findings show up as annotations right on your GitHub or GitLab merge-request diff instead of buried in a job log For adopting it on an existing codebase there's a baseline file — you fingerprint the findings you've reviewed, with a required reason on each, and they stop failing the build but never go invisible; every run still counts them It exits non-zero on error-level findings, so it drops straight into CI or a pre-commit hook And it's extensible — checks are Drupal plugins with a #[SecurityCheck] attribute, so any module can add its own or alter the ones that ship Big caveat, and the module says this itself: a finding means "review this," not "this is broken." Static analysis has false positives, and a clean scan doesn't prove the code is secure — access-control logic especially still needs human review I first heard about this module over beverages at Drupalcamp Asheville, so I know that this module was largely vibe-coded, after having an AI agent ingest every single Drupal security team CVE. So I like to think of this module as security pattern recognition tool, but of course it does even more
Hackers use Drupalgeddon 2 and Dirty COW exploits to take over web servers, second WordPress hacking campaign underway, USPS took a year to fix a vulnerability that exposed all 60 million users' data, this JavaScript can snoop on other Browser Tabs to work out what you're visiting, and more! Full Show Notes: https://wiki.securityweekly.com/ASW_Episode41 Follow us on Twitter: https://www.twitter.com/securityweekly
Hackers use Drupalgeddon 2 and Dirty COW exploits to take over web servers, second WordPress hacking campaign underway, USPS took a year to fix a vulnerability that exposed all 60 million users' data, this JavaScript can snoop on other Browser Tabs to work out what you're visiting, and more! Full Show Notes: https://wiki.securityweekly.com/ASW_Episode41 Follow us on Twitter: https://www.twitter.com/securityweekly
This week, Keith and Paul interview Brent Dukes! Brent is a hacker, and Director of Information Security for an established manufacturing company. He joins Keith and Paul this week to talk about WAF’s, Pentesting, Burp Suite, and more! In the Application Security News, Hackers use Drupalgeddon 2 and Dirty COW exploits to take over web servers, second WordPress hacking campaign underway, USPS took a year to fix a vulnerability that exposed all 60 million users' data, this JavaScript can snoop on other Browser Tabs to work out what you're visiting, and more! Full Show Notes: https://wiki.securityweekly.com/ASW_Episode41 Visit https://www.securityweekly.com/asw for all the latest episodes! Visit https://www.activecountermeasures/asw to sign up for a demo or buy our AI Hunter! Follow us on Twitter: https://www.twitter.com/securityweekly Like us on Facebook: https://www.facebook.com/secweekly Follow us on Twitter: https://www.twitter.com/securityweekly
This week, Keith and Paul interview Brent Dukes! Brent is a hacker, and Director of Information Security for an established manufacturing company. He joins Keith and Paul this week to talk about WAF’s, Pentesting, Burp Suite, and more! In the Application Security News, Hackers use Drupalgeddon 2 and Dirty COW exploits to take over web servers, second WordPress hacking campaign underway, USPS took a year to fix a vulnerability that exposed all 60 million users' data, this JavaScript can snoop on other Browser Tabs to work out what you're visiting, and more! Full Show Notes: https://wiki.securityweekly.com/ASW_Episode41 Visit https://www.securityweekly.com/asw for all the latest episodes! Visit https://www.activecountermeasures/asw to sign up for a demo or buy our AI Hunter! Follow us on Twitter: https://www.twitter.com/securityweekly Like us on Facebook: https://www.facebook.com/secweekly
This week, iOS updates, hacker charged with murder, a steaming vulnerability, to pay or not to pay the ransom, Drupal still vulnerable, freaking out over GitHub, and this day in something forever. Jason Wood of Paladin Security joins us for the expert commentary this week, and more on this episode of Hack Naked News! Full Show Notes: https://wiki.securityweekly.com/HNNEpisode176 Visit http://hacknaked.tv to get all the latest episodes!
Firms running Cisco WebEx are told to update their software, Medical devices vulnerable to KRACK Wi-Fi attacks, Kitty Cryptomining Malware Cashes in on Drupalgeddon 2.0, Facebook fires engineer accused of stalking women, and more on this episode of Paul’s Security Weekly! Full Show Notes: https://wiki.securityweekly.com/Episode558 Subscribe to our YouTube channel: https://www.youtube.com/securityweekly Visit our website: http://securityweekly.com Follow us on Twitter: https://www.twitter.comsecurityweekly
Firms running Cisco WebEx are told to update their software, Medical devices vulnerable to KRACK Wi-Fi attacks, Kitty Cryptomining Malware Cashes in on Drupalgeddon 2.0, Facebook fires engineer accused of stalking women, and more on this episode of Paul’s Security Weekly! Full Show Notes: https://wiki.securityweekly.com/Episode558 Subscribe to our YouTube channel: https://www.youtube.com/securityweekly Visit our website: http://securityweekly.com Follow us on Twitter: https://www.twitter.comsecurityweekly
This week, we interview Leonard Rose, Principal Security Archtiect of Limelight Networks! In the news, we have updates from Cisco, Drupalgeddon, Facebook, Twitter, and more on this episode of Paul's Security Weekly! Full Show Notes: https://wiki.securityweekly.com/Episode558 Visit https://www.securityweekly.com/psw for all the latest episodes! →Visit https://www.activecountermeasures/psw to sign up for a demo or buy our AI Hunter!!
This week, we interview Leonard Rose, Principal Security Archtiect of Limelight Networks! In the news, we have updates from Cisco, Drupalgeddon, Facebook, Twitter, and more on this episode of Paul's Security Weekly! Full Show Notes: https://wiki.securityweekly.com/Episode558 Visit https://www.securityweekly.com/psw for all the latest episodes! Visit https://www.activecountermeasures/psw to sign up for a demo or buy our AI Hunter!!
Drupalgeddon part 3 - the sequel, teenage SAP vulnerabilities, PHP is vulnerable, hacking Apple MFi, Oracle, Mass pays the ransom, and hacking into a prison will land you in prison. Jason Wood from Paladin Security joins us for expert commentary on Staying Cool in a Crisi so stay tuned to this episode of Hack Naked News! Full Show Notes: https://wiki.securityweekly.com/HNNEpisode171 Visit http://hacknaked.tv to get all the latest episodes!
Drupalgeddon part 3 - the sequel, teenage SAP vulnerabilities, PHP is vulnerable, hacking Apple MFi, Oracle, Mass pays the ransom, and hacking into a prison will land you in prison. Jason Wood from Paladin Security joins us for expert commentary on Staying Cool in a Crisi so stay tuned to this episode of Hack Naked News! Full Show Notes: https://wiki.securityweekly.com/HNNEpisode171 Visit https://www.securityweekly.com/hnn for all the latest episodes! Visit https://www.activecountermeasures/hnn to sign up for a demo or buy our AI Hunter!!
Drupalgeddon is back, as discussed by security analysts Jessica Ortega and Ram Gall.
While speaking with Melissa Anderson about behavior driven development (BDD) at BADCamp 2014, she suggested I get John Bickar from Stanford Web Services in front of my cameras to talk about his experience during last year's "Drupalgeddon" security vulnerability. The result is this podcast and some great insight into how this kind of testing can significantly improve initial, ongoing, and emergency delivery of software. As John puts it, using BDD means: "delivering better software, delivering it faster, and knowing that it is delivering the value that we have promised to our partners." I would have named this episode of the Acquia Podcast more in the spirit of Dr. Strangelove: "Behat tests mean death to Linky-Clicky or how BDD helped Stanford Web Services recover fast during Drupalgeddon," but reason won out. Read the full post and see the conversation video at the Acquia Developer Center: https://dev.acquia.com/podcast/179-deploying-better-software-confidence-behat-bdd-meet-john-bickar
In der neusten Folge des c't-Podcasts diskutieren wir die Mobile-Events der Woche: Wer hat die besseren neuen Gadgets -- Google oder Apple? Und was ist wirklich neu an Nexus 6, Nexus 9, iPad Air 2 und iPad Mini 3? Außerdem kommt es zum Duell der Sicherheitslücken: Sandworm gegen Poodle gegen Drupalgeddon. Welche Lücke bedroht mehr Nutzer und - vor allem - welche hat das bessere Logo? Peter König stellt Dienstleister vor, bei denen man den eigenen Körper scannen und dann in 3D drucken lassen kann. Dazu hat er natürlich auch sein 15-cm-Ich mitgebracht und zeigt, wie lebensecht das "Mini Me" ist. Der Preis der Technik dürfte allerdings viele noch davon abhalten, sich eine Armee aus kleinen Ichs zusammenzustellen. Diesmal mit dabei: Alexander Spier (asp, @MutantHappy), Fabian Scherschel (fab, @fabsh), Hannes Czerulla (hcz, @Hannibal4885) und Peter König (pek). Das Video zur Folge findet ihr im YouTube-Channel von heise online.
In der neusten Folge des c't-Podcasts diskutieren wir die Mobile-Events der Woche: Wer hat die besseren neuen Gadgets -- Google oder Apple? Und was ist wirklich neu an Nexus 6, Nexus 9, iPad Air 2 und iPad Mini 3? Außerdem kommt es zum Duell der Sicherheitslücken: Sandworm gegen Poodle gegen Drupalgeddon. Welche Lücke bedroht mehr Nutzer und - vor allem - welche hat das bessere Logo? Peter König stellt Dienstleister vor, bei denen man den eigenen Körper scannen und dann in 3D drucken lassen kann. Dazu hat er natürlich auch sein 15-cm-Ich mitgebracht und zeigt, wie lebensecht das "Mini Me" ist. Der Preis der Technik dürfte allerdings viele noch davon abhalten, sich eine Armee aus kleinen Ichs zusammenzustellen. Diesmal mit dabei: Alexander Spier (asp, @MutantHappy), Fabian Scherschel (fab, @fabsh), Hannes Czerulla (hcz, @Hannibal4885) und Peter König (pek). Das Video zur Folge findet ihr im YouTube-Channel von heise online.
In der neusten Folge des c't-Podcasts diskutieren wir die Mobile-Events der Woche: Wer hat die besseren neuen Gadgets -- Google oder Apple? Und was ist wirklich neu an Nexus 6, Nexus 9, iPad Air 2 und iPad Mini 3? Außerdem kommt es zum Duell der Sicherheitslücken: Sandworm gegen Poodle gegen Drupalgeddon. Welche Lücke bedroht mehr Nutzer und - vor allem - welche hat das bessere Logo? Peter König stellt Dienstleister vor, bei denen man den eigenen Körper scannen und dann in 3D drucken lassen kann. Dazu hat er natürlich auch sein 15-cm-Ich mitgebracht und zeigt, wie lebensecht das "Mini Me" ist. Der Preis der Technik dürfte allerdings viele noch davon abhalten, sich eine Armee aus kleinen Ichs zusammenzustellen. Diesmal mit dabei: Alexander Spier (asp, @MutantHappy), Fabian Scherschel (fab, @fabsh), Hannes Czerulla (hcz, @Hannibal4885) und Peter König (pek). Das Video zur Folge findet ihr im YouTube-Channel von heise online.