Drupal users across the UK have been advised to take immediate action and install a critical patch, following a warning from the organisation behind the popular content management system. The update, which was released on Wednesday, targets issues in unsupported Drupal 8.9 branches, but the specifics of the fix remain unclear. Drupal has declined to comment on the nature of the patch, leaving users to navigate the process without further guidance. The lack of transparency has raised concerns among experts, who warn that users may be left vulnerable to exploitation if they fail to act promptly.
Unsupported versions of Drupal are no longer receiving security updates, leaving users with a heightened risk of being targeted by hackers. With the UK's National Cyber Security Centre (NCSC) warning of a surge in cyber attacks, the timing of the patch could not be more critical. 'This is a stark reminder of the importance of keeping software up to date, particularly when it comes to security,' said Dr Emma Hart, a leading expert in AI and cybersecurity. 'The UK's businesses and individuals must take this warning seriously and act quickly to protect themselves from potential harm.'
In the UK, the Information Commissioner's Office (ICO) has issued guidance on the importance of keeping software secure, particularly when it comes to content management systems like Drupal. 'Organisations must take all necessary steps to protect their customers' data and prevent cyber attacks,' said an ICO spokesperson. 'This includes keeping software up to date and patching vulnerabilities promptly.'
The European Union's AI Act, which is set to come into force in 2024, will also place a greater emphasis on the need for organisations to prioritise cybersecurity. 'As the AI Act makes clear, organisations have a duty of care to protect their customers' data and prevent cyber attacks,' said a spokesperson for the UK's Department for Digital, Culture, Media and Sport. 'This includes keeping software up to date and patching vulnerabilities promptly.'