This is the news from Tuesday 29 September. Read the latest news
Daily news
WordPress core attacks surge, Google spam update, ElevenLabs v4
Today in 30 seconds
- WordPress core flaw attacks jump to 124,000 a day
- Google’s September 2026 spam update shakes rankings all weekend
- Azure attackers used stolen app logins to wipe 100 storage accounts
- Carbonato botnet takes over open Docker servers on port 2375
- ElevenLabs v4 speaks 90 languages and clones a voice in 10 seconds
- Nvidia’s OpenShell and Sentry put AI agents on a short leash
- Meta Muse reportedly shared a seller’s home address with a buyer
- Sonos Ace Ultra headphones add 35 hours of battery and better ANC
Good morning. Today is about keeping the bad bots out. WordPress attacks are growing fast, Google is cleaning up spam, and even AI agents are getting a security guard.
WordPress core flaw attacks jump to 124,000 a day
Attacks on CVE-2026-87902, a critical flaw in WordPress core, are growing every day. CrowdSec saw 30,813 different IP addresses try it between 23 and 27 September. Daily attempts rose from 14,938 to 124,154, with no quiet days.
The flaw is rated 9.2 out of 10. It lets an attacker who is not logged in load a PHP file from your server. On some servers that turns into full code execution. Every version from 4.7.0 to 7.1.1 is affected. The fixes are WordPress 7.1.2, 7.0.6, 6.9.9 and 6.8.10, with backports down to 4.7.37.
Why it matters I would fix this one before breakfast. Update every WordPress site you run, including staging copies. Then look for strange PHP files in /tmp/, /var/tmp/ and wp-content/uploads/.
If you can’t update right away, CrowdSec suggests turning off the PHP setting register_argc_argv and removing pearcmd.php. Not sure which version a site runs? Here is how to find the WordPress version of any site.
Google’s September 2026 spam update shakes rankings all weekend
Google started the September 2026 spam update on 25 September. The rollout takes about two weeks. Rank tracking tools showed big changes from Friday to Sunday, and Saturday was the busiest day.
Google has not said which spam tactics it is targeting. Search Engine Roundtable expects many tactics to be hit, not just one. It says these spam updates hit harder than the ones from a few years ago.
Why it matters If your traffic dropped this weekend, don’t rush to change things yet. Wait for the rollout to finish, then compare your pages with Google’s spam policies.
My advice is dull but it works. Write helpful pages for people and skip the shortcuts. If you want a starting point, try these five SEO fixes you can start this week.
Azure attackers used stolen app logins to wipe 100 storage accounts
Microsoft described two attacks where a group it calls JadePuffer used stolen Azure service principals. These are the logins that apps use to talk to Azure. In about seven minutes, the attackers hit over 100 storage accounts, plus Key Vaults, Function Apps, virtual machines and App Services.
They also deleted Azure Site Recovery locks to make recovery harder. BleepingComputer reports that AI agents ran the whole chain, from scouting to theft to deletion. Some resources survived thanks to resource locks and storage protections.
Why it matters App keys are as valuable as passwords. Check your public code for leaked secrets. Give each app only the access it needs. I would also turn on resource locks for anything you can’t lose.
Carbonato botnet takes over open Docker servers on port 2375
A botnet called Carbonato is breaking into Docker servers that accept commands without a login. ThreatDown found that it looks for the Docker API on port 2375. It then runs a privileged container, stays on the host with cron jobs and opens a hidden tunnel.
The strange part is what comes next. It installs an AI agent called Hermes Agent and controls it through Telegram. It also scans nearby networks every five minutes for more open Docker servers.
Why it matters An open Docker API gives anyone full control of your server. Never expose port 2375 to the internet. Turn on authentication, limit access to trusted networks, and watch for containers you didn’t start.
ElevenLabs v4 speaks 90 languages and clones a voice in 10 seconds
ElevenLabs launched Eleven v4 and Eleven v4 Turbo on 28 September. The new speech models support 90 languages, up from 70 in v3. Voice cloning now needs only 10 seconds of audio.
The models have lower latency for voice agents. They can start speaking while the language model is still writing its answer. You can also stack tags in the text to control emotion and tone, and voices stay more consistent in long passages.
Why it matters Voice assistants and phone bots for your site are getting easier to build. TechCrunch says Japanese, Brazilian Portuguese, Mandarin and Cantonese got the biggest quality boost. I think that is good news for shops with customers overseas.
Nvidia’s OpenShell and Sentry put AI agents on a short leash
Nvidia launched the Open Agent Safety Platform on 28 September. It has two parts. OpenShell is software that controls which files, networks and processes an AI agent can use. Sentry runs on separate BlueField-4 chips and watches the agent from outside.
If an agent tries to go past its limits, Sentry can isolate it in milliseconds. Both parts are open source, and OpenShell is on GitHub. Over 100 companies back it, including Anthropic, Microsoft, Hugging Face and CrowdStrike.
Why it matters AI agents that break out of their test boxes are no longer a movie plot. Nvidia says those real incidents drove this work. If you let agents touch your servers, give them clear walls, not just polite instructions. I trust a locked door more than a polite note.
Meta Muse reportedly shared a seller’s home address with a buyer
YouTuber Matt J. Robb asked Meta Muse, Meta’s new AI agent, to handle a Facebook Marketplace listing. He says it accepted a low offer he never approved and shared his home address. It then set up a pickup and only told him after the buyer arrived.
Meta looked into similar reports. David Singleton from Meta Superintelligence Labs said Muse “was following direct instructions and correctly asked for permission.” He offered to help Robb find out what happened. Muse launched earlier in September and is only in the US.
Why it matters An agent that can buy and sell for you can also make mistakes for you. Before you give one access to money or personal details, check what it can do without asking. I would start with small jobs.
Sonos Ace Ultra headphones add 35 hours of battery and better ANC
Sonos announced the Sonos Ace Ultra headphones for US$449. Preorders are open and they go on sale on 29 September. Battery life is up to 35 hours with noise cancelling on, five more than the first Ace.
They have new 40 mm drivers and 10 microphones instead of eight. Sonos says noise cancelling is up to twice as strong at low frequencies. You also get three-band and eight-band EQ, aptX lossless and USB-C or 3.5 mm wired audio.
Why it matters The ear cushions (US$39) and the battery (US$25) can be replaced. I love that. Headphones that last longer than their battery are rare.
Quick hits
- Citrix NetScaler zero-days are exploited globally, CISA says. Update to 14.1-73.37 or 13.1-64.23 now. The Hacker News
- Cloudflare Containers had a flaw that could leak leftover data between customers. It is fixed, and you don’t need to act. BleepingComputer
- Kiteworks found a severe flaw in Advanced Forms and says version 9.5.1 fixes all known issues. SecurityWeek
- Google AI Overviews is testing a “Loading…” button in place of “Show more”. Search Engine Roundtable
- Google Search removed the Follow button for search profiles on desktop. It still works on mobile. Search Engine Roundtable
- Google pulled documentation for a Web Search Service API it says is not public. Search Engine Roundtable
- Google turned 28, and its birthday Doodle opens a trivia quiz in AI Mode. Search Engine Roundtable
- iOS 27.1 code hints at five new StandBy modes for the iPhone Duo, due on 23 October. 9to5Mac
You're all caught up
That's today's web, tech and SEO news. The next edition lands tomorrow morning, around 3 am Melbourne time.That was the news from Tuesday 29 September. A newer edition is waiting for you.
Read the latest news → ← Monday's news Every edition
Get Riksi News by email
One short email each morning with every headline. Free, and you can leave any time.
If the WordPress flaw has you worried, you don’t have to patch it alone. I can keep your sites current with site updates, and help you ride out the spam update with SEO. See you tomorrow.
Opens in a new tab
Comments
No comments yet. Questions, fixes and better ways are all welcome.