Today's digest · Tuesday, September 22

The 6 things in AI/dev today.

LiveNext issue at 7:00 CET
#1 / TODAY
BleepingComputer·1 min·11h agoFREE

WordPress Click2Shell flaw lets hackers execute PHP on the server

BleepingComputer reports a WordPress flaw dubbed Click2Shell that lets hackers execute PHP on the server. The article, published September 21, 2026, provides no further detail in the supplied text about the vulnerability's technical cause, the affected WordPress versions, or the plugin or component involved. The stated consequence is that attackers can run PHP code on the server. No exploitation status, patch availability, or remediation guidance is included in the source text.

The report says the flaw allows PHP execution on the server, which is the kind of capability that can let an attacker run code in a WordPress environment.

wordpresssecurityphpvulnerability
bleepingcomputer.com
WordPress Click2Shell flaw lets hackers execute PHP on the server
SAML: A fractal of bad design
#2 / TOP STORY
Trail of BitsFREE

SAML: A fractal of bad design

Trail of Bits published a blog post arguing that SAML, the XML-based authentication protocol created in 2002 by the OASIS Security Services Technical Committee, should be deprecated in favor of newer protocols such as OpenID Connect. The post traces SAML's design-by-committee origin, noting four contributed XML-based specifications were merged into it, and cites Thomas Ptacek's 2023 remark that most fielded SAML implementations wrap libxmlsec. It also lists CAS, Shibboleth, ADFS, and simpleSAMLphp as related authentication efforts.

AI Gateway now supports TypeSafe clients and an HTTP API for Jev
#3 / TOP STORY
VercelFREE

AI Gateway now supports TypeSafe clients and an HTTP API for Jev

Vercel's changelog states that AI Gateway now supports TypeSafe clients and an HTTP API for Jev. The entry is titled "AI Gateway now supports TypeSafe clients and an HTTP API for Jev" and is attributed to Vercel, with a publication date of 2026-09-21. Beyond the title and source attribution, the provided source text contains no additional detail about the clients, the HTTP API, or Jev, so the scope of the change is described only as stated.

aigest · daily

Get this every morning.

One email. The signal. Built for builders.

Free · Unsubscribe in one click · No trackers

// Worth knowing3 stories
// Yesterday6 stories