This article aims to give a short overview of the most important things to do after your website has been compromised.
Since some people contacted us with questions regarding the latest release, this post will elaborate on the changes in that release and why they have been done that way.
The TYPO3 Security Team introduced a new structure and a new naming scheme for security bulletins.
Recently a security issue in TYPO3 has been fixed, where it was possible to circumvent checks, which should ensure file names to match specific patterns (e.g. denying .php file extensions to be uploaded or renamed to). As...
The TYPO3 Security Team has decided to partly handle TYPO3 Core Incidents publicly by the standard Core Review Process.
The upcoming version 4.5 will include a form protection for improved security.
Check your own code for correct usage of TYPO3 database API in LIKE comparisons!