All Posts

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Security

Apr 17, 2026

CVE-2026-35554: Apache Kafka Producer Message Corruption and Silent Misrouting (Buffer Pool Race Condition)

How a Kafka Producer Race Condition Leads to Undetected Data Corruption and Unauthorized Topic Exposure

Mark Szymanski

Mark Szymanski

Share this post via:

herodevs.com/blog-posts/
cve-2026-35554-apache-kafka-producer-message-corruption-and-silent-misrouting-buffer-pool-race-condition

Security

Apr 17, 2026

CVE-2025-9551: Brute Force Vulnerability in Drupal's Protected Pages Module

How a Missing Rate Limit in Drupal 7 Creates Real Security and Compliance Risk

Javier Perez

Javier Perez

Share this post via:

herodevs.com/blog-posts/
cve-2025-9551-brute-force-vulnerability-in-drupals-protected-pages-module

Security

Apr 10, 2026

Spring AI 2.0 Is Coming May 28. Here Is Why That Makes the June 30 Deadline More Urgent, Not Less.

The Spring AI 2.0 launch is not a reason to wait on your EOL decision. It is a reason to act now.

Taylor Corbett

Taylor Corbett

Share this post via:

herodevs.com/blog-posts/
spring-ai-2-0-is-coming-may-28-here-is-why-that-makes-the-june-30-deadline-more-urgent-not-less

Security

Apr 9, 2026

Node.js v20 Goes EOL April 30 — and Your Cloud Provider Is Pulling the Plug the Next Day

Two deadlines, one week apart. Most teams running Node.js v20 in production only know about one of them.

Javier Perez

Javier Perez

Share this post via:

herodevs.com/blog-posts/
node-js-v20-goes-eol-april-30----and-your-cloud-provider-is-pulling-the-plug-the-next-day