This is the news from Saturday 3 October. Read the latest news
Daily news
FortiMail zero-day, a WordPress key thief and Google’s AI rule
Today in 30 seconds
- Fortinet FortiMail zero-day is under attack and has no patch yet
- TIKTOUK toolkit steals keys from 37,000 WordPress sites
- Google says it is “critical” to fact-check all AI content
- ChatGPT can now show you wearing clothes before you buy
- Microsoft launches MAI voice models for live speech agents
- Cloudflare AI Search is now ready for your site search
- SvelteKit 3 is out with a new config and a migration tool
- Shopify API 2026-10 is stable, with new Events for apps
- GitHub Copilot can now click around your desktop apps
- Apple’s iPhone Duo has a folding screen layer you can replace
Some links in this post are affiliate links. If you buy through one, I may earn a small commission, at no extra cost to you. As an Amazon Associate I earn from qualifying purchases.
Good morning. Today has a mail server zero-day with no patch and a kit that robs WordPress sites. Google also wants you to check your AI writing. There’s also a phone screen you can peel. Grab a coffee.
Fortinet FortiMail zero-day is under attack and has no patch yet
Fortinet warns that attackers are using a critical flaw in FortiMail, its email security appliance. The bug is CVE-2026-104286, rated CVSS 9.8. It lets an attacker with no login write any file on the device through crafted web requests. That can lead to full code execution.
Affected versions are 7.2.0 to 7.2.9, 7.4.0 to 7.4.8, 7.6.0 to 7.6.6 and 8.0.0 to 8.0.1. Fixes will come in 7.4.9, 7.6.7 and 8.0.2, but Fortinet has not released them yet. CISA added the flaw to its Known Exploited Vulnerabilities list on 2 October.
Why it matters If you or a client run FortiMail, you need to act today. Turn off IBE feature support, and block the management interface from the web so only trusted addresses can reach it. Install the fixed version the day it lands.
TIKTOUK toolkit steals keys from 37,000 WordPress sites
Researchers at LevelBlue SpiderLabs found a toolkit called TIKTOUK that targets WordPress sites. It grabs files that should never be public, like wp-config.php.bak, .env, .git/config, backup.sql and wp-content/debug.log. It also decrypts email passwords saved by WP Mail SMTP, Easy WP SMTP and FluentSMTP.
A leaked control panel showed about 50,000 credentials across 37,000 domains. The kit uses two WordPress core flaws, CVE-2026-60137 and CVE-2026-63030. They are fixed in 6.8.6, 6.9.5 and 7.0.2.
Why it matters One old backup file in your web root can give away your database and your email account. Update WordPress, delete backup and debug files from public folders, and change any keys that may have leaked.
A few security headers and a tidy server go a long way. My guide on WordPress security headers without a plugin is a good start.
Google says it is “critical” to fact-check all AI content
Google updated its guidance on AI-generated content on 1 October. Its new line is short. “It is critical to manually factcheck and review all AI-generated content for accuracy and trustworthiness before publishing.” The check covers titles, meta descriptions, structured data and image alt text too.
Google also updated its helpful content page. It adds a section on main content, meaning any part of the page that helps it do its job. It lists the four things quality raters look for: Effort, Originality, Talent or Skill, and Accuracy.
Why it matters Google rarely uses the word “critical”. If you publish AI drafts, a human must read and check every one. Your meta descriptions and alt text count as well.
I like this change. AI is a fine first draft and a poor final editor.
ChatGPT can now show you wearing clothes before you buy
ChatGPT has a new Try on button on clothing products in chats. You upload a selfie and a full-body photo, and it makes images of you wearing the item. It uses the new ChatGPT Images 2.5 model.
It also works with screenshots of clothes from anywhere. A new Library lets you save products you like. Engadget notes that personal account images can be used for training unless you opt out.
Why it matters Shoppers can now try your products inside ChatGPT, without visiting your store. Clear product photos and clean product data will matter even more for fashion shops.
Microsoft launches MAI voice models for live speech agents
Microsoft released three new voice models in Microsoft Foundry. MAI-Transcribe-2-Streaming turns live speech into text as the person talks. It costs $0.54 per audio hour and works in more than 60 languages.
MAI-Voice-2.1 turns text into expressive speech in 23 languages for $22 per million characters. MAI-Voice-2.1-Flash is faster and cheaper at $15 per million characters.
Why it matters A voice assistant for a booking or support line is now cheaper to build. You get listening, thinking and talking from one company.
Cloudflare AI Search is now ready for your site search
Cloudflare AI Search is now generally available. It is a managed index that can power search for your docs or your website. New features include image search, text reading from scanned PDFs, and files up to 10 MiB.
Billing starts on 1 November 2026, with a free tier on all Workers plans. Ingestion costs $0.75 per million tokens with 5 million free. Storage is $2 per GB each month with 10 GB free. There are no monthly minimums.
Why it matters A smart search box that answers questions used to need a big budget. Now a small site can try it for free.
SvelteKit 3 is out with a new config and a migration tool
The Svelte team released SvelteKit 3 on 1 October. Config moves from svelte.config.js to vite.config.ts. The $lib alias becomes #lib, which uses standard subpath imports.
You also get simpler service workers, better error handling and stronger type safety. To upgrade, run npx sv migrate sveltekit-3 --tasks all --confirm. It changes what it can and gives you a to-do list for the rest.
Why it matters This is a breaking release. Upgrade on a branch first, run the tool, and test before you ship.
Shopify API 2026-10 is stable, with new Events for apps
Shopify API version 2026-10 becomes stable on 2 October. It brings breaking changes. ProductVariant.barcode is deprecated in favour of a new barcodes list. The Customer Account API drops lastIncompleteCheckout with no replacement.
Shopify also made Next Gen Events generally available across 18 topics, including products, orders and customers. You choose which changes matter, what data to send, and filters for delivery. Classic webhooks keep working next to Events, so you can move over slowly.
Why it matters If you build or maintain a Shopify app, check the release notes now. Events can also cut the extra API calls your app makes after each webhook.
GitHub Copilot can now click around your desktop apps
GitHub Copilot can now use desktop apps on macOS and Windows. It is in public preview in the Copilot CLI and the Copilot app. It can read the screen, click, type, scroll and move between apps.
It asks before it touches each app, and you can reset its permissions. In the CLI you control it with /computer on and /computer off. Organisations can turn it off.
Why it matters Old tools with no API can now be part of an AI workflow. Give it only the apps it needs, and watch what it does.
Apple’s iPhone Duo has a folding screen layer you can replace
Apple says the protective layer on the iPhone Duo folding screen can be peeled off and replaced. This helps keep the crease from showing over time. A matte coating also helps hide it.
The phone costs over US$2,000. With AppleCare, a new layer costs $19. Apple has not said the price without AppleCare.
Why it matters The crease is the big worry with folding phones. A $19 fix makes the Duo easier to live with for years. It is on Amazon Australia if you want a closer look.
Quick hits
- Citrix NetScaler attackers plant web shells via CVE-2026-88771, so patch and check for unknown accounts. The Hacker News
- Poper Blocker, a Chrome ad blocker with 2 million users, collects browsing history and AI chats. Uninstall it. SecurityWeek
- Chrome 154.0.8037.97 is rolling out to desktop, with security details still to come. Chrome Releases
- Cloudflare Workers KV Instant enters private beta with reads under 2 ms for config data. Cloudflare
- Cloudflare Clef brings two open-source models for fast yes-or-no choices in AI agents. Cloudflare
- GitHub Actions retention settings now also clean up old checks, runs and statuses. GitHub
- Bing is testing a “Recommended by” label that credits review sites in product results. Search Engine Roundtable
- Google Local Service Ads now hide phone numbers behind a “Get phone number” button. Search Engine Roundtable
- Samsung Galaxy S26 phones now cost US$100 more on every storage size. 9to5Google
You're all caught up
That's today's web, tech and SEO news. The next edition lands tomorrow morning, around 3 am Melbourne time.That was the news from Saturday 3 October. A newer edition is waiting for you.
Read the latest news → ← Friday's news Every edition
Get Riksi News by email
One short email each morning with every headline. Free, and you can leave any time.
That’s you caught up. If TIKTOUK made you nervous about your WordPress site, I can check it and lock it down for you. See my WordPress services. Have a great weekend.
Opens in a new tab
Comments
No comments yet. Questions, fixes and better ways are all welcome.