This is the news from Friday 2 October. Read the latest news
Daily news
Gemini 4 Argon, a self-healing WordPress backdoor and more
Today in 30 seconds
- Google’s Gemini 4 Argon is out, but only for security teams first
- WordPress backdoor “SC” rebuilds itself every time you delete it
- Zammad helpdesk zero-days were used to break into DIVD
- MikroTik RouterOS has a critical flaw that needs no login
- Over 543,000 working passwords and keys sit in public GitHub code
- Google’s spam update hits again with a second wave on 30 September
- Google AI Overviews now show up for most big brand searches
- Cloudflare Pay Per Use wants AI companies to pay when they use your work
- Shopify Canvas shows your whole store on one page you can edit
- GitHub brings HydraFusion to VS Code to mix AI models
- Amazon’s new Kindle loses the bezel and gets lighter
Good morning. Google has a new top AI model, and you can’t use it yet. There is also a WordPress backdoor that grows back like a weed, so today is a good day to check your sites.
Google’s Gemini 4 Argon is out, but only for security teams first
Google announced Gemini 4 Argon on 30 September. It is the first Gemini 4 model and Google’s new frontier model. It is built for long tasks in coding, legal and finance work, and cyber defence.
Google says Argon scores 77.9% on the DeepSWE v1.1 coding test. It can also write up to 1 million tokens of output, up from 64,000. For now it only goes to trusted cyber defenders in Google’s Fairwind Program. Paid API customers and Google AI Ultra subscribers come next. Google has not given a date. The launch price is US$2 per million input tokens and US$10 per million output tokens. It rises to US$4 and US$20 later.
Why it matters The best models now go to defenders before everyone else. That is a sign of how good they have become at finding bugs. For your site, the lesson is plain. Old, unpatched software will get found faster than ever.
WordPress backdoor “SC” rebuilds itself every time you delete it
Sucuri found WordPress malware that came back within seconds of every removal. It hides in eight places at once. When you delete one part, another part writes it back.
The hiding places include a .user.ini file, a db.php drop-in and a must-use plugin. Others are a plugin called hyper-engine-kit.php, theme files and loaders like c1b12371.php. It can hide itself from the admin screens, make hidden admin users and add bad JavaScript for your visitors. It even takes orders through the Ethereum blockchain.
Why it matters Deleting one bad file is not enough here. You must clean all eight places at the same time, including the database. Then change every password and update every plugin, because the way in is usually an old plugin or a weak login. If this sounds like a lot, it is a job for a pro. My guide to WordPress security headers is a good next step after the clean-up.
Zammad helpdesk zero-days were used to break into DIVD
Two critical flaws in Zammad, the open-source helpdesk app, were used in a real attack. Both are rated CVSS 9.4. The Dutch security group DIVD was hacked through them on 21 September by an automated, AI-driven attack.
The flaws are CVE-2026-102489 and CVE-2026-102490. Chained together, they let an attacker take over sessions, run code and get root access in seconds. Zammad 6.3.0 to 6.5.4 can be attacked. Versions 7.0.0 to 7.1.3 have the bug, but it can’t be used there.
Why it matters Many small teams run their own helpdesk and forget it. If you host Zammad, upgrade to version 7 today or take it offline. DIVD has also shared a script to check for signs of a break-in.
MikroTik RouterOS has a critical flaw that needs no login
CISA warned on 30 September about a critical flaw in MikroTik RouterOS. It is CVE-2026-84411. One crafted request to the router’s web management page can run code as root, with no password.
All RouterOS versions below 7.23 are affected. The fixed releases are 7.24.4 stable and 7.23.7 long-term, out since 16 September. No attacks have been reported yet. MikroTik routers are still a favourite target for botnets.
Why it matters Lots of offices and shops run on a MikroTik router. Update RouterOS now. Then make sure the management page can’t be reached from the internet.
Over 543,000 working passwords and keys sit in public GitHub code
Truffle Security scanned 224 million public GitHub repositories. It found 543,699 credentials that still worked. The top ones were Google Cloud service accounts, MongoDB connection strings and Google API keys.
The median key stayed exposed for 784 days. Nearly 200,000 were pushed after GitHub turned on push protection by default. So the block helps, but it misses a lot.
Why it matters A leaked key is only safe once you revoke it. Deleting the file is not enough, because git keeps the history. Rotate any key that has ever been in a repository, and give new keys an expiry date.
Google’s spam update hits again with a second wave on 30 September
The Google September 2026 spam update had a second wave on 30 September. Some site owners saw big drops on that day. Discover and News traffic swung a lot too.
Google said on 24 September that this update would take about two weeks. The first wave hit from 25 to 27 September. More waves may still come before it ends.
Why it matters Don’t make big changes to your site in the middle of an update. Note the dates of any drop and wait until Google says it is done. Then compare. My post on why SEO matters has five safe fixes you can start any time.
Google AI Overviews now show up for most big brand searches
Google is showing AI Overviews for brand name searches far more often. Chris Long tested about 100 big brands and found AI Overviews for 93% of them. DemandSphere says AI Overviews on brand searches tripled in September.
Most of these sit lower on the page, below the brand’s own listing. Adobe is an exception, with the overview at the top. Searches for Google itself and for news sites don’t get them.
Why it matters When people search your business name, Google may now describe you in its own words. Search your brand today and read what it says. If it’s wrong, fix the facts on your own site first. Google’s answer often draws from there.
Cloudflare Pay Per Use wants AI companies to pay when they use your work
Cloudflare launched Pay Per Use in beta on 30 September. AI companies set a price for each use of a page, like showing it in an answer. Publishers accept the offers they like in the Cloudflare dashboard, and Cloudflare pays them monthly.
Cloudflare also says more than half of the traffic on its network is now automated. AI agent requests grew over 1,700% in a year. Some busy categories, like retail, lost up to 40% of their human traffic in under a year.
Why it matters Fewer people click, and more bots read. Payment for AI use may become a real income line for content sites. If your site is on Cloudflare, it is worth a look. My guide on how AI search finds your site explains the crawlers.
Shopify Canvas shows your whole store on one page you can edit
Shopify started rolling out Canvas to existing stores on 1 October. It is a new design space that lays out every page of your store side by side. You can zoom around, click to edit, or ask Sidekick, Shopify’s AI helper, to make changes.
Find it under Online Store, then Themes. You can make a new Canvas theme or convert a Shopify or custom theme. Your original theme stays as it is. Canvas does not yet work with Theme Store themes, Markets, translations, app blocks or automatic theme updates.
Why it matters Seeing every page at once makes it easier to keep a store consistent. But check the limits first. If you sell in more than one language or rely on app blocks, wait for now.
GitHub brings HydraFusion to VS Code to mix AI models
GitHub added HydraFusion to VS Code and the GitHub Copilot app on 30 September. It picks how several AI models work on a task. One model can do it alone, a cheap model can try first and pass it up, or one model can check another’s work.
It needs VS Code 1.140 or later. It works on Copilot Pro, Pro+, Business and Enterprise. On Business and Enterprise, an admin must turn on preview features. GitHub calls it a research preview.
Why it matters You no longer have to guess which model fits a task. I like the “one model checks the other” mode for risky changes. Try it on a small job first.
Amazon’s new Kindle loses the bezel and gets lighter
Amazon showed a new Kindle lineup on 1 October. The basic 6-inch Kindle has a flat, bezel-free front. It is 6.8 mm thick, weighs 140 g and turns pages 30% faster. It starts at US$149.99.
The Paperwhite and Colorsoft get the same flat design. Amazon says the screen can tell when your thumb rests on the edge, so it won’t turn the page by mistake. Australia is on the list: the basic Kindle is on sale now, and the others are up for preorder.
Why it matters It’s not a work tool, but a light e-reader is a great way to get away from screens full of tabs. That is my excuse, anyway.
Quick hits
- Cisco Catalyst SD-WAN Manager has an exploited CVSS 9.8 login bypass, CVE-2026-76504, so update now. BleepingComputer
- Apple CoreGraphics now has a public proof of concept, so install Apple’s 28 September update. The Hacker News
- Zimbra servers below 10.1.20 are being hacked through an SNMP flaw, so patch or remove zimbra-snmp. The Hacker News
- Chrome 155 is rolling out to a small share of Windows and Mac users as an early stable release. Chrome Releases
- Vercel no longer caches responses with Vary: Cookie, so add Cache-Control: private if they are personal. Vercel
- npm trusted publishing can now manage dist-tags with short-lived OIDC logins instead of long-lived tokens. GitHub Changelog
- Shopify Analytics now lets you add your own notes to reports, like “sale started”. Shopify Changelog
- Google Search is testing the removal of the “I’m Feeling Lucky” button, sometimes for AI buttons. Search Engine Roundtable
- MacBook Pro with a touchscreen and OLED could reportedly arrive as early as October. 9to5Mac
You're all caught up
That's today's web, tech and SEO news. The next edition lands tomorrow morning, around 3 am Melbourne time.That was the news from Friday 2 October. A newer edition is waiting for you.
Read the latest news → ← Thursday's news Every edition
Get Riksi News by email
One short email each morning with every headline. Free, and you can leave any time.
A backdoor that rebuilds itself is a good reason to stop putting off updates. If you’d like someone else to keep your plugins patched and watch for trouble, my site updates service does that. And if the spam update or AI Overviews moved your traffic, I can help with SEO. See you tomorrow.
Opens in a new tab
Comments
No comments yet. Questions, fixes and better ways are all welcome.