"This Public Service Announcement is a follow up to SA-CORE-2014-005 - Drupal core - SQL injection. This is not an announcement of a new vulnerability in Drupal." If you read my newsletter every week you already knew about this and should have already taken action.
url:
https://www.drupal.org/PSA-2014-003
163