This is the news from Wednesday 7 October. Read the latest news
Daily news
Google’s fake author warning, Atlassian fix, ChatGPT watermarks
Today in 30 seconds
- Google warns against fake authors and AI headshots
- Atlassian fixes critical CVE-2026-21589 in Jira and Confluence
- LibreOffice flaw lets a spreadsheet run code with no macro warning
- OpenAI adds hidden watermarks to ChatGPT text in the EU
- OpenAI makes GPT-6 Astra and GPT-6.1 Sol about 50% faster
- Wikimedia says OpenAI agents made edits and hammered its APIs
- Reflection AI shows Beam, a 501B open model for coding
- Google Docs now opens and edits Markdown files
- Shopify’s Shop now syncs carts across devices
- Ghost Core is a US$3,499 box that runs your AI at home
Good morning. Google has a clear message today: no more fake experts with AI faces. Atlassian and LibreOffice have fixes to install, and OpenAI is busy as always. Coffee first, then patches.
Google warns against fake authors and AI headshots
Google added a new line to its helpful content guide on 6 October. It says you should avoid deceptive authorship information. Fake creator profiles with AI-generated headshots, made-up names or false credentials count as deception.
Google says this kind of trick makes a page less trustworthy, for readers and for its systems. Search Engine Roundtable notes that Google used to say little about made-up author details.
Why it matters Some sites invent “expert” writers to look more credible. Use real names and real bios, or no byline at all. A fake doctor with a perfect AI smile is now a clear risk.
My take: trust is built by showing who you are. My post on why SEO matters has five fixes that work without tricks.
Atlassian fixes critical CVE-2026-21589 in Jira and Confluence
Atlassian has patched CVE-2026-21589, a path traversal flaw rated CVSS 9.3. An attacker with no login can read files from the web app folder, if they know the exact file path. It hits eight self-hosted Data Center products.
The fixed versions include Jira Software 9.12.40, 10.3.26 and 11.3.12, Confluence 9.2.26 and 10.2.19, and Bitbucket 9.4.26, 10.2.8 and 10.5.1. Bamboo, Crowd, Crucible, Fisheye and Jira Service Management also have fixes. Atlassian has found no sign of attacks on its cloud. It cannot say whether your own servers were hit.
Why it matters If you host Jira or Confluence yourself, update now. If you can’t, take it off the public internet. Then search your logs for “..” next to slashes. Atlassian Cloud customers don’t need to do anything.
LibreOffice flaw lets a spreadsheet run code with no macro warning
A flaw in LibreOffice and Apache OpenOffice lets a booby-trapped spreadsheet run code when you open it. No macro warning appears. LibreOffice fixed CVE-2026-63277 in versions 26.2.5 and 26.8.0.
The trick joins two normal features. A database range pulls in outside data, and a Java database driver downloads and runs code. It only works when Java support is on. OpenOffice is affected up to 4.1.16, and the fix in 4.1.17 is still in testing. So far it is a proof of concept, with no reports of real attacks.
Why it matters Spreadsheets arrive by email every day. Update LibreOffice to 26.2.5 or newer. On OpenOffice, turn Java off in the settings and don’t open spreadsheets you don’t trust.
OpenAI adds hidden watermarks to ChatGPT text in the EU
OpenAI will add an invisible watermark to ChatGPT and Codex text for users in the European Union. It rolls out over the coming weeks to meet EU rules. API customers anywhere can turn it on now, and it is off by default.
The tech is called textGrain. It changes word choices a little to leave a statistical pattern. OpenAI’s own tests show the limits. Swapping 10% of the words cut detection from 92% to 66%, and swapping 25% cut it to 17%. Only approved researchers can use the detector for now.
Why it matters If you publish AI text in Europe, it may now carry a hidden mark. OpenAI says plainly that “the absence of a detected watermark does not prove human authorship.” So treat any “AI detector” result with care.
OpenAI makes GPT-6 Astra and GPT-6.1 Sol about 50% faster
OpenAI has started “28 days of quality of life improvements”. Each day it will ship one clear fix for Codex and work users. Day 1 on 5 October made GPT-6 Astra and GPT-6.1 Sol about 50% faster by default.
The speed boost comes from inference tuning, so you don’t need to change anything. It covers ChatGPT subscriptions and partner tools that use Sign in with ChatGPT, such as OpenCode, Amp and Devin.
Why it matters Faster answers make AI coding tools nicer for long tasks. I’ll keep an eye on the next 27 days. Some of these small fixes may help your daily work more than a new model.
Wikimedia says OpenAI agents made edits and hammered its APIs
The Wikimedia Foundation says AI agents run by OpenAI made edits to its wikis without approval. Most edits were in sandbox areas readers don’t see. The agents also tried to misuse its public Etherpad tool and sent millions of API requests.
The agents crawled millions of Wikidata and Commons pages and ran hundreds of thousands of queries. Wikimedia thinks this may have helped cause an outage in May. It found no sign its data was compromised. OpenAI said the agents behaved “unpredictably” and will review the activity with Wikimedia.
Why it matters AI agents now visit sites like busy humans, but faster. Rate limits and bot rules matter on any open form, API or tool you run. My guide on how AI search finds your site covers the robots.txt side.
Reflection AI shows Beam, a 501B open model for coding
Reflection AI has announced Beam, an open-weight model with 501 billion parameters. Only 23 billion are active at a time. It has a 1 million token context and an Apache 2.0 licence.
Reflection says Beam matches GLM 5.2 on coding and agent tasks, and uses three to four times less compute. The weights and technical report arrive later in October. You can sign up for early access now.
Why it matters A strong open model with a friendly licence gives you more choice. You could run it on your own servers, with no API bill and no data leaving your network.
Google Docs now opens and edits Markdown files
Google Docs can now open, edit and share .md and .markdown files without converting them. Google Drive also shows a rendered preview, with links and tables. The rollout started on 5 October and can take up to 15 days.
The file stays a Markdown file after you edit it. It works for all Google Workspace customers and personal Google accounts. No admin setting is needed.
Why it matters README files, docs and AI notes are often Markdown. Now a client or teammate can comment on them in Docs, with no Git and no raw syntax. I’ll use this a lot.
Shopify’s Shop now syncs carts across devices
Shopify says the Shop app can now recognise shoppers while they browse your store. Checkout loads faster, carts sync between phone and laptop, and sign-in takes one tap. It now works in all web browsers.
The Shop Pay button can also show the card the shopper used before. Shop sends cart recovery reminders too. Merchants don’t need to set anything up.
Why it matters People often add to cart on a phone and buy later on a laptop. A cart that follows them means fewer lost sales. My post on abandoned cart emails covers the rest.
Ghost Core is a US$3,499 box that runs your AI at home
Startup Ghost has opened preorders for Core, a personal AI computer for US$3,499. It has no screen. You talk to it through a phone app or by voice. It ships in the last week of October.
Inside is an Nvidia RTX Pro 4000 SFF Blackwell GPU. It comes with Qwen and Gemma models, and you can add others from Hugging Face. Everything runs locally, and Ghost says it keeps working even if the company stops its service.
Why it matters Private, local AI is moving from hobby builds into ready-made boxes. It is pricey, but it is a sign of where home AI is going.
Quick hits
- No new critical flaws came out for WordPress core, popular plugins or browsers in the last 36 hours. Chrome Releases
- Zammad help desks on 6.5 or older have two exploited flaws, so update to 7.2.0. Cyber Security News
- MALFEX npm malware hides in function-flag, function-color and cdn-img-fetch. Remove them if installed. SecurityWeek
- Google Search Console now lets you pick several countries at once in the Performance report. Search Engine Roundtable
- Google’s September spam update seems to be in its third and likely last phase, from 4 to 6 October. Search Engine Roundtable
- Search Console AI controls now alert domain owners when a child property overrides their setting. Search Engine Roundtable
- ChatGPT is testing product labels like “best all-rounder” and “best for beginners” in shopping results. Search Engine Roundtable
- TikTok adds an AI shopping assistant and one-click checkout, built with partners including Shopify. TechCrunch
- GitHub secret scanning now spots leaked keys for Lovable, Supabase and more. GitHub
- Example.com had its biggest redesign in decades, and now cycles through six languages. DebugBear
You're all caught up
That's today's web, tech and SEO news. The next edition lands tomorrow morning, around 3 am Melbourne time.That was the news from Wednesday 7 October. A newer edition is waiting for you.
Read the latest news → ← Tuesday's news Every edition
Get Riksi News by email
One short email each morning with every headline. Free, and you can leave any time.
That’s you caught up. If Google’s fake author warning made you look twice at your About page, my SEO service can help you show real expertise. Have a great Wednesday.
Opens in a new tab
Comments
No comments yet. Questions, fixes and better ways are all welcome.