The U.S. Cybersecurity and Infrastructure Security Agency has issued a mandate requiring federal agencies to patch an actively exploited SQL injection vulnerability in Drupal by Wednesday evening.
CISA's directive targets a critical security flaw in Drupal, a widely used open-source content management system deployed across government and private sector infrastructure. The SQL injection vulnerability allows attackers to access or manipulate databases on affected servers.
The agency classified the vulnerability as actively exploited, meaning threat actors are already leveraging it in real-world attacks. This designation elevates the urgency for all federal civilian agencies to apply patches immediately.
Government agencies have until the end of business Wednesday to deploy the necessary security updates. CISA typically enforces such deadlines through its Binding Operational Directive (BOD) authority, which compels compliance across federal information systems.
SQLi vulnerabilities remain among the most dangerous attack vectors. Successful exploitation grants attackers direct access to backend databases, potentially exposing sensitive information including personal data, authentication credentials, and classified government information.
Drupal is maintained by a community-driven project and released its patches for the vulnerability before CISA's announcement. Organizations running Drupal installations are advised to update to patched versions immediately, regardless of whether they receive federal directives.
The vulnerability is not limited to U.S. government systems. Private sector organizations, educational institutions, and international entities using vulnerable Drupal versions face similar risks. Security researchers recommend treating this as a priority patch.
CISA regularly flags actively exploited vulnerabilities to accelerate patching timelines. The agency maintains a catalog of known exploited vulnerabilities and publishes regular advisories to help organizations prioritize remediation efforts.
Administrators unable to patch immediately should implement compensating controls such as web application firewalls, network segmentation, and enhanced monitoring for suspicious database activity.
Authorities have arrested two alleged members of TeamPCP, a hacking group responsible for infecting over 1,000 organizations through supply-chain attacks.
A Georgia police officer used Flock surveillance technology to track the movements of his ex-partner and another officer after their affair ended, according to internal investigation records.
McKesson, a major healthcare and pharmaceutical distributor, confirmed a cybersecurity incident involving unauthorized access to third-party applications. Extortion group ShinyHunters claims responsibility for stealing 284 million patient data records.
Fraudsters are exploiting Microsoft Teams and similar enterprise chat apps to deceive Chinese users into sending large sums of money. The trend has sparked a wave of complaints across the region.