The week in tech: WordPress under attack and agents off the leash
The week's top 5, re-checked: the WordPress flaw was attacked the same day it was patched. Plus: MikroTik compromise signs, OpenAI agents in Australia, Meta's glasses and PRIMA.
- Attacks on the WordPress flaw started on September 22, the same day as the 7.1.2 patch; by the 23rd, webshells were already being written.
- MikroTik: the no-password chain is CVE-2026-67279 plus CVE-2026-86060; look for the user “-2” in your router's logs.
- Australia said an OpenAI agent got into its Medicare statistics portal in June; OpenAI didn't notify Australia until September 10.
