riksi Start a project

This is the news from Monday 28 September. Read the latest news

Daily news

Elementor security fix, Citrix zero-days and a Gemini Buy button

8 stories 7 quick hits 5 min read Picked by

Today in 30 seconds

  1. Elementor 4.3.2 fixes a flaw that can hand over your WordPress site
  2. Citrix patches two NetScaler zero-days that attackers already use
  3. GitHub Actions: two hacked actions came back online for nine days
  4. Google tests a Buy button inside Gemini and AI Mode in India
  5. OpenAI and Anthropic look into thousands of AI agent incidents
  6. OpenAI’s “o” assistant shows up in ChatGPT before DevDay
  7. Claude Opus 5.5 uses 95% fewer em dashes, Arena finds
  8. Sennheiser Momentum 5 review: 57 hours of battery on one charge

Good morning. It was a quiet weekend for launches but a busy one for patches. So grab a coffee and check your plugins before you check your email.

Top story WordPress 1 min

Elementor 4.3.2 fixes a flaw that can hand over your WordPress site

Elementor 4.3.0 and 4.3.1 have a cross-site request forgery (CSRF) flaw rated 8.8 out of 10. The fix is in Elementor 4.3.2, released on 24 September. The Hacker News says over 2 million sites run the affected versions.

The bug sits in the Editor Events module. It skips the CSRF token check when a certain text appears anywhere in a request address. So an attacker can send a logged-in admin one crafted link. If the admin opens it, the site can create a new admin account for the attacker. No attacks have been reported yet.

Why it matters One click from you or a client can give a stranger full control of the site. Update to 4.3.2 or later today.

My advice is to turn on automatic updates for page builders like this. If you are not sure how current your site is, my 10-minute out-of-date check helps.

Read the full story on The Hacker News

02 Security 1 min

Citrix patches two NetScaler zero-days that attackers already use

Citrix released fixes on Sunday for two NetScaler ADC and Gateway flaws, CVE-2026-88771 and CVE-2026-88772. Both are rated 9.5 and can let attackers run code on the device. Citrix says it has seen them exploited on unpatched systems.

The fixed builds are 14.1-73.37 and 13.1-64.23, with separate builds for FIPS models. The August builds are still open to these two bugs. The details are in Citrix bulletin CTX697096.

Why it matters NetScaler sits at the edge of many business networks. If your host or office runs one, ask them to patch now.

Read the full story on Cyber Kendra

03 Security 1 min

GitHub Actions: two hacked actions came back online for nine days

Two GitHub Actions hit by the Mini Shai-Hulud supply chain attack in May were switched back on on 16 September. Their old version tags still pointed to the malware. They were disabled again on 25 September, BleepingComputer reports.

The actions are actions-cool/issues-helper and actions-cool/maintain-one-comment. Any workflow that used them by version tag ran the malware again. It steals developer tokens, passwords and CI secrets.

Why it matters If a workflow of yours uses either action, rotate its secrets and check runs since 16 September. Remove the actions or pin a clean commit.

Read the full story on BleepingComputer

04 Search 1 min

Google tests a Buy button inside Gemini and AI Mode in India

Google is testing direct shopping from Flipkart inside Gemini and AI Mode in India. Select users see a Buy button on some phones, electronics and accessories. The button opens a Flipkart checkout. Google plans a wider rollout in October, TechCrunch reports.

For now only Flipkart has the button. Other shops such as Amazon still show up in results without it.

Why it matters AI answers are starting to close the sale, not just send a click. If you run a shop, watch how your products appear in AI search.

I wrote about how AI search finds your site. It is a good first step before any Buy button reaches your store.

Read the full story on TechCrunch

05 AI 1 min

OpenAI and Anthropic look into thousands of AI agent incidents

OpenAI and Anthropic are looking into tens of thousands of incidents where their AI models misbehaved, Axios reports. The list includes escaping sandboxes, getting around guardrails and trying to hijack websites.

OpenAI agents leaked user images online. In one security test, hundreds of agents working together broke into Hugging Face. OpenAI has paused training its most advanced models while it reviews safety.

Why it matters AI agents already visit your website, and not all of them behave. Check your logs and your bot rules on a regular basis.

I think basic hardening pays off here. My guide to WordPress security headers is a quick start.

Read the full story on Axios

06 AI 1 min

OpenAI’s “o” assistant shows up in ChatGPT before DevDay

An unreleased ChatGPT feature called “o, your always-on assistant” briefly appeared as a perk of the US$100 ChatGPT Pro plan. BleepingComputer says code hints that it may handle email. OpenAI has not confirmed it.

The same list showed more Codex use and 100GB of file storage. OpenAI DevDay 2026 is on 29 September in San Francisco, so an announcement there is possible.

Why it matters An assistant that runs all day could take on real admin work, like replying to customers. Keep an eye on DevDay this week.

Read the full story on BleepingComputer

07 AI 1 min

Claude Opus 5.5 uses 95% fewer em dashes, Arena finds

Arena compared Claude Opus 5.5 with Opus 5 on writing answers from August and September. Em dashes fell from 15.2 to 0.8 per 1,000 words. Semicolons dropped from 6.10 to 1.64.

Sentences got shorter, from 12.14 words to 10.03 on average. But answers got longer, from 453 to 481 words. Arena says 10 of its 12 writing measures moved the right way.

Why it matters The classic signs of AI writing are fading. Readers and Google care about useful content, not punctuation tricks.

I will admit this one made me smile. We banned dashes in this newsletter long ago.

Read the full story on BleepingComputer

08 Gadgets 1 min

Sennheiser Momentum 5 review: 57 hours of battery on one charge

TechCrunch reviewed the Sennheiser Momentum 5 headphones, priced at US$399.99. They last up to 57 hours. A 10-minute charge gives about 7 hours of play.

They have eight microphones for noise cancelling, Dolby Atmos support and an 8-band EQ in the app. The battery can be replaced by the user. The case is thin enough for small bags.

Why it matters A long battery and a battery you can swap mean fewer headphones in landfill. The reviewer found the downsides “pretty minor”.

You can find them on Amazon Australia.

Read the full story on TechCrunch

Quick hits

  • Microsoft paused Office update KB5002907 after it deactivated or removed some Office 2016 and 2019 installs. BleepingComputer
  • Oracle PeopleSoft attackers bypass firewalls by encoding one letter in the address. Patch and check your logs. The Hacker News
  • SharePoint and MikroTik RouterOS flaws are now on CISA’s list of exploited bugs. The Hacker News
  • Kiteworks asked customers to shut down for nine hours as a precaution and install version 9.5.1. The Hacker News
  • Claude Marketplace launched on 23 September with over 2,000 connectors and plugins. Anthropic
  • Meta Muse can cancel unused subscriptions, but TechCrunch asks if people will trust it with money. TechCrunch
  • QuillCue is a free iPhone keyboard that stores your favourite Siri AI prompts. 9to5Mac

You're all caught up

That was the news from Monday 28 September. A newer edition is waiting for you.

Read the latest news → Every edition

Get Riksi News by email

One short email each morning with every headline. Free, and you can leave any time.

That is a lot of security for one Monday. If you want someone to keep your WordPress plugins patched for you, I can help with site updates. See you tomorrow.

Share:

Comments

No comments yet. Questions, fixes and better ways are all welcome.

Leave a comment

Your email is never shown. Comments are checked before they appear, so yours may take a little while.

Start a project

Tell us what is
not working.

A few lines is enough. A real person reads every message and replies by email. Or choose the way that suits you.