This is the news from Thursday 8 October. Read the latest news
Daily news
Ninja Forms attacks, WordPress 7.1.3 and Mistral Large 4
Today in 30 seconds
- Ninja Forms flaw CVE-2026-94504 is used to hack WordPress sites
- WordPress 7.1.3 fixes seven security flaws
- Atlassian CVE-2026-21589 is now under attack
- Chrome 155 is out with 247 security fixes
- Mistral Large 4 is a 1 trillion parameter model with open weights soon
- Google’s Nano Banana 2.1 makes 4K images at half the price
- OpenAI’s Decisions API gives fast yes or no answers
- The internet’s DNS root key changes on 11 October
- Google now documents Retry-After for slowing its crawlers
- Google Merchant Center adds a hub for AI Mode checkout
- GitHub stacked pull requests are now for everyone
Good morning. Today is a patch day for WordPress people. Two plugins are under attack, WordPress itself has a security release, and Chrome 155 fixes 247 flaws. The AI news is fun too, with a giant French model and cheaper Google images.
Ninja Forms flaw CVE-2026-94504 is used to hack WordPress sites
Attackers are using flaws in two WordPress plugins to take over sites. Ninja Forms 3.15.3 and older (CVE-2026-94504) and WPC Product Bundles for WooCommerce 8.6.6 and older (CVE-2026-93836) are affected. Ninja Forms runs on more than 500,000 sites.
Both are stored cross-site scripting flaws. The attacker hides JavaScript in a form entry or order. When an admin opens it, the code creates a visible admin, a hidden admin, a secret login URL and a file manager. It also installs a fake plugin called “WP Smart Thumbnails”.
Why it matters Updating stops new attacks, but it does not clean a hacked site. Update to Ninja Forms 3.15.4 and WPC Product Bundles 8.6.7 now. Then check your user list, your plugin list and any unknown admin accounts.
My tip: look for “WP Smart Thumbnails” in your plugins folder, not only in the dashboard. Hidden admins love hiding.
WordPress 7.1.3 fixes seven security flaws
WordPress 7.1.3 came out on 6 October as a security release. It fixes seven flaws. They include a stored XSS on the Comments screen, a second-order SQL injection in the WXR export and a leak of comments on private posts.
Researchers from Trail of Bits, Anthropic and Patchstack reported several of them. The fixes are being backported to older branches back to WordPress 4.7.
Why it matters WordPress says to update your sites immediately. Most sites get minor updates on their own, but check that yours did. Go to Dashboard, then Updates.
Atlassian CVE-2026-21589 is now under attack
Yesterday Atlassian patched CVE-2026-21589, a critical path traversal flaw rated CVSS 9.3. Now attackers are using it. The Hacker News reports exploit attempts within two hours of public details.
The flaw lets an attacker with no login read files like those in WEB-INF. That can lead to admin access. It hits the Data Center versions of Jira, Jira Service Management, Confluence, Bitbucket, Bamboo and Crowd, plus Crucible and Fisheye.
Why it matters If you run any of these yourself, patch today. Fixed versions include Confluence 9.2.26 and 10.2.19, and Jira 9.12.40, 10.3.26 and 11.3.12. If you can’t patch yet, take the server off the public internet.
Chrome 155 is out with 247 security fixes
Google released Chrome 155 to the stable channel on 6 October. The version is 155.0.8059.39 or .40 on Windows and Mac, and 155.0.8059.39 on Linux. It fixes 247 security flaws, and four of them are critical.
The four critical bugs are use-after-free flaws in Chromecast, Browser, Navigation and Track. Several bugs were found by an Anthropic researcher with help from Claude. Google does not say that any of them are being exploited.
Why it matters 247 fixes is a big batch. Open the Chrome menu, go to Help, then About Google Chrome, and restart when it asks.
I restart my browser once a week anyway. It is the cheapest security tool you have.
Mistral Large 4 is a 1 trillion parameter model with open weights soon
Mistral released Mistral Large 4 on 6 October. Its nickname is “le Chonk”. It has 1 trillion parameters, with 49 billion active at a time. The API preview costs US$1.36 per million input tokens and US$4.18 per million output tokens.
Mistral says it is strong at coding, agents and cybersecurity, and works in more than 160 languages. The open weights are due by the end of October. It was the top story on Hacker News yesterday.
Why it matters A frontier-level model you can run on your own servers is good news for privacy. It is also more choice and lower prices for anyone building AI into a site.
My take: I like having a strong European option. Wait for real tests before you switch, though.
Google’s Nano Banana 2.1 makes 4K images at half the price
Google launched Nano Banana 2.1, its new image model, on 6 October. It can make 4K images and keep up to four characters looking the same across images. It is rolling out in the Gemini app, AI Mode in Search, Google Ads and AI Studio.
The API price is about half of what it was. Android Headlines reports US$0.0336 for a 1K image and US$0.0756 for a 4K image. Vercel’s AI Gateway added it on day one.
Why it matters Product photos in new scenes just got cheaper. Shops can test lifestyle shots for a few cents each. Keep the real product photo too, so buyers know what they get.
I wrote about product photos for online shops if you want the basics first.
OpenAI’s Decisions API gives fast yes or no answers
OpenAI opened its Decisions API as a public beta. It reads text or images and gives a typed answer. It can check if something is true, pick from a list, or give a score. OpenAI says it is about 10 times faster than the Responses API.
It uses the gpt-6-luna model. You pay US$0.10 per million input tokens, and output is free. OpenAI expects it to be generally available in the coming weeks.
Why it matters This is cheap for small jobs on a website. Think sorting support emails, flagging spam comments or scoring bug reports.
I’d try it on contact form spam first. At that price, it should cost very little for most small sites.
The internet’s DNS root key changes on 11 October
On 11 October the DNS root moves from its old key, KSK-2017, to a new one, KSK-2024. This is only the second time this has ever happened. Cloudflare explained the change on 6 October.
Most website owners don’t need to do anything. People who run their own DNSSEC-validating resolvers must make sure the resolver trusts KSK-2024. If it doesn’t, domains can stop resolving.
Why it matters If you or your IT person run a DNS server, test it this week at dnstest.dev. Cloudflare DNS and 1.1.1.1 users are already covered.
New to Cloudflare? My Cloudflare 101 guide walks you through the free plan.
Google now documents Retry-After for slowing its crawlers
Google updated its guide on reducing its crawl rate on 6 October. It now says you can send a Retry-After HTTP header with a 503 or 429 response. The header tells Google’s crawlers when to come back.
You can give a delay in seconds or an exact date and time. Google already slowed down on 500, 503 and 429 errors. Now the extra hint is in the official docs.
Why it matters If your server is overloaded or down for maintenance, a 503 with Retry-After is the polite way to say “later”. Don’t block Google with robots.txt for a short outage.
For more on how crawlers see your site, read my post on how AI search finds your website.
Google Merchant Center adds a hub for AI Mode checkout
Google is rolling out a UCP integration hub in Merchant Center in the United States. UCP is the Universal Commerce Protocol, an open standard that lets AI tools handle checkout. The hub lets shops sign up from their Merchant Center account.
Shops that join can show checkout buttons on products in AI Mode and Gemini. Google plans to bring it to Australia and Canada in 2027.
Why it matters Buying inside AI answers is coming. Australian shops have time, but clean product data in Merchant Center is the first step.
GitHub stacked pull requests are now for everyone
GitHub made stacked pull requests generally available on 6 October. You can split a big change into small pull requests that depend on each other. Reviewers check each one, and the stack merges together.
Approvals stay when a rebase doesn’t change the code. You can jump between pull requests in a stack with Shift+J and Shift+K. The gh stack CLI extension now works with Git worktrees.
Why it matters Small pull requests get reviewed faster. GitHub says repos using stacks merged 9% more code.
Quick hits
- SonicWall SMA1000 has a max severity SSRF flaw, CVE-2026-102255. Hotfixes are out and it is not exploited yet. BleepingComputer
- LMCache has an unpatched CVSS 9.8 flaw. Keep its multiprocess server on localhost for now. The Hacker News
- Fake ChatGPT, Gemini and Claude ad portals steal Google logins and MFA codes from ad managers. BleepingComputer
- Google Search no longer shows review stars for healthcare pages, outside local results. Search Engine Roundtable
- Search Console is emailing sites how many people chose them as a preferred source. Search Engine Roundtable
- Google Business Profiles now show a WhatsApp button in local results. Search Engine Roundtable
- EmbeddingGemma 2 is a free 740M model for search across text, images, audio and video. Google
- Anthropic opened three tiers of Claude access for vetted security teams. Anthropic
- Shopify Balance users in the US can now pay suppliers overseas from the app. Shopify
- Apple and LG will reportedly launch a smart lock, doorbell and thermostat next week. TechCrunch
You're all caught up
That's today's web, tech and SEO news. The next edition lands tomorrow morning, around 3 am Melbourne time.That was the news from Thursday 8 October. A newer edition is waiting for you.
Read the latest news → ← Wednesday's news Every edition
Get Riksi News by email
One short email each morning with every headline. Free, and you can leave any time.
That’s you caught up. Two plugin attacks in one morning is a lot to watch. If you’d rather not check updates every day, my site updates service keeps WordPress patched for you. Have a great Thursday.
Opens in a new tab
Comments
No comments yet. Questions, fixes and better ways are all welcome.