riksi Start a project

This is the news from Saturday 3 October. Read the latest news

Daily news

FortiMail zero-day, a WordPress key thief and Google’s AI rule

10 stories 9 quick hits 6 min read Picked by

Today in 30 seconds

  1. Fortinet FortiMail zero-day is under attack and has no patch yet
  2. TIKTOUK toolkit steals keys from 37,000 WordPress sites
  3. Google says it is “critical” to fact-check all AI content
  4. ChatGPT can now show you wearing clothes before you buy
  5. Microsoft launches MAI voice models for live speech agents
  6. Cloudflare AI Search is now ready for your site search
  7. SvelteKit 3 is out with a new config and a migration tool
  8. Shopify API 2026-10 is stable, with new Events for apps
  9. GitHub Copilot can now click around your desktop apps
  10. Apple’s iPhone Duo has a folding screen layer you can replace

Some links in this post are affiliate links. If you buy through one, I may earn a small commission, at no extra cost to you. As an Amazon Associate I earn from qualifying purchases.

Good morning. Today has a mail server zero-day with no patch and a kit that robs WordPress sites. Google also wants you to check your AI writing. There’s also a phone screen you can peel. Grab a coffee.

Top story Security 1 min

Fortinet FortiMail zero-day is under attack and has no patch yet

Fortinet warns that attackers are using a critical flaw in FortiMail, its email security appliance. The bug is CVE-2026-104286, rated CVSS 9.8. It lets an attacker with no login write any file on the device through crafted web requests. That can lead to full code execution.

Affected versions are 7.2.0 to 7.2.9, 7.4.0 to 7.4.8, 7.6.0 to 7.6.6 and 8.0.0 to 8.0.1. Fixes will come in 7.4.9, 7.6.7 and 8.0.2, but Fortinet has not released them yet. CISA added the flaw to its Known Exploited Vulnerabilities list on 2 October.

Why it matters If you or a client run FortiMail, you need to act today. Turn off IBE feature support, and block the management interface from the web so only trusted addresses can reach it. Install the fixed version the day it lands.

Read the full story on SecurityWeek

02 WordPress 1 min

TIKTOUK toolkit steals keys from 37,000 WordPress sites

Researchers at LevelBlue SpiderLabs found a toolkit called TIKTOUK that targets WordPress sites. It grabs files that should never be public, like wp-config.php.bak, .env, .git/config, backup.sql and wp-content/debug.log. It also decrypts email passwords saved by WP Mail SMTP, Easy WP SMTP and FluentSMTP.

A leaked control panel showed about 50,000 credentials across 37,000 domains. The kit uses two WordPress core flaws, CVE-2026-60137 and CVE-2026-63030. They are fixed in 6.8.6, 6.9.5 and 7.0.2.

Why it matters One old backup file in your web root can give away your database and your email account. Update WordPress, delete backup and debug files from public folders, and change any keys that may have leaked.

A few security headers and a tidy server go a long way. My guide on WordPress security headers without a plugin is a good start.

Read the full story on Cyber Press

03 Search 1 min

Google says it is “critical” to fact-check all AI content

Google updated its guidance on AI-generated content on 1 October. Its new line is short. “It is critical to manually factcheck and review all AI-generated content for accuracy and trustworthiness before publishing.” The check covers titles, meta descriptions, structured data and image alt text too.

Google also updated its helpful content page. It adds a section on main content, meaning any part of the page that helps it do its job. It lists the four things quality raters look for: Effort, Originality, Talent or Skill, and Accuracy.

Why it matters Google rarely uses the word “critical”. If you publish AI drafts, a human must read and check every one. Your meta descriptions and alt text count as well.

I like this change. AI is a fine first draft and a poor final editor.

Read the full story on Search Engine Roundtable

04 AI 1 min

ChatGPT can now show you wearing clothes before you buy

ChatGPT has a new Try on button on clothing products in chats. You upload a selfie and a full-body photo, and it makes images of you wearing the item. It uses the new ChatGPT Images 2.5 model.

It also works with screenshots of clothes from anywhere. A new Library lets you save products you like. Engadget notes that personal account images can be used for training unless you opt out.

Why it matters Shoppers can now try your products inside ChatGPT, without visiting your store. Clear product photos and clean product data will matter even more for fashion shops.

Read the full story on Engadget

05 AI 1 min

Microsoft launches MAI voice models for live speech agents

Microsoft released three new voice models in Microsoft Foundry. MAI-Transcribe-2-Streaming turns live speech into text as the person talks. It costs $0.54 per audio hour and works in more than 60 languages.

MAI-Voice-2.1 turns text into expressive speech in 23 languages for $22 per million characters. MAI-Voice-2.1-Flash is faster and cheaper at $15 per million characters.

Why it matters A voice assistant for a booking or support line is now cheaper to build. You get listening, thinking and talking from one company.

Read the full story on SiliconANGLE

06 Cloud 1 min

Cloudflare AI Search is now ready for your site search

Cloudflare AI Search is now generally available. It is a managed index that can power search for your docs or your website. New features include image search, text reading from scanned PDFs, and files up to 10 MiB.

Billing starts on 1 November 2026, with a free tier on all Workers plans. Ingestion costs $0.75 per million tokens with 5 million free. Storage is $2 per GB each month with 10 GB free. There are no monthly minimums.

Why it matters A smart search box that answers questions used to need a big budget. Now a small site can try it for free.

Read the full story on the Cloudflare blog

07 Web 1 min

SvelteKit 3 is out with a new config and a migration tool

The Svelte team released SvelteKit 3 on 1 October. Config moves from svelte.config.js to vite.config.ts. The $lib alias becomes #lib, which uses standard subpath imports.

You also get simpler service workers, better error handling and stronger type safety. To upgrade, run npx sv migrate sveltekit-3 --tasks all --confirm. It changes what it can and gives you a to-do list for the rest.

Why it matters This is a breaking release. Upgrade on a branch first, run the tool, and test before you ship.

Read the full story on the Svelte blog

08 Shopify 1 min

Shopify API 2026-10 is stable, with new Events for apps

Shopify API version 2026-10 becomes stable on 2 October. It brings breaking changes. ProductVariant.barcode is deprecated in favour of a new barcodes list. The Customer Account API drops lastIncompleteCheckout with no replacement.

Shopify also made Next Gen Events generally available across 18 topics, including products, orders and customers. You choose which changes matter, what data to send, and filters for delivery. Classic webhooks keep working next to Events, so you can move over slowly.

Why it matters If you build or maintain a Shopify app, check the release notes now. Events can also cut the extra API calls your app makes after each webhook.

Read the full release notes on Shopify.dev

09 AI 1 min

GitHub Copilot can now click around your desktop apps

GitHub Copilot can now use desktop apps on macOS and Windows. It is in public preview in the Copilot CLI and the Copilot app. It can read the screen, click, type, scroll and move between apps.

It asks before it touches each app, and you can reset its permissions. In the CLI you control it with /computer on and /computer off. Organisations can turn it off.

Why it matters Old tools with no API can now be part of an AI workflow. Give it only the apps it needs, and watch what it does.

Read the full story on the GitHub changelog

10 Gadgets 1 min

Apple’s iPhone Duo has a folding screen layer you can replace

Apple says the protective layer on the iPhone Duo folding screen can be peeled off and replaced. This helps keep the crease from showing over time. A matte coating also helps hide it.

The phone costs over US$2,000. With AppleCare, a new layer costs $19. Apple has not said the price without AppleCare.

Why it matters The crease is the big worry with folding phones. A $19 fix makes the Duo easier to live with for years. It is on Amazon Australia if you want a closer look.

Read the full story on 9to5Mac

Quick hits

  • Citrix NetScaler attackers plant web shells via CVE-2026-88771, so patch and check for unknown accounts. The Hacker News
  • Poper Blocker, a Chrome ad blocker with 2 million users, collects browsing history and AI chats. Uninstall it. SecurityWeek
  • Chrome 154.0.8037.97 is rolling out to desktop, with security details still to come. Chrome Releases
  • Cloudflare Workers KV Instant enters private beta with reads under 2 ms for config data. Cloudflare
  • Cloudflare Clef brings two open-source models for fast yes-or-no choices in AI agents. Cloudflare
  • GitHub Actions retention settings now also clean up old checks, runs and statuses. GitHub
  • Bing is testing a “Recommended by” label that credits review sites in product results. Search Engine Roundtable
  • Google Local Service Ads now hide phone numbers behind a “Get phone number” button. Search Engine Roundtable
  • Samsung Galaxy S26 phones now cost US$100 more on every storage size. 9to5Google

You're all caught up

That was the news from Saturday 3 October. A newer edition is waiting for you.

Read the latest news → ← Friday's news Every edition

Get Riksi News by email

One short email each morning with every headline. Free, and you can leave any time.

That’s you caught up. If TIKTOUK made you nervous about your WordPress site, I can check it and lock it down for you. See my WordPress services. Have a great weekend.

Share:

Comments

No comments yet. Questions, fixes and better ways are all welcome.

Leave a comment

Your email is never shown. Comments are checked before they appear, so yours may take a little while.

Start a project

Tell us what is
not working.

A few lines is enough. We read every message and reply personally by email. Or choose the way that suits you.