Today's digest · Thursday, September 24

The 8 things in AI/dev today.

LiveNext issue at 7:00 CET
#1 / TODAY
BleepingComputer·1 min·10d agoFREE

Hackers start exploiting critical WordPress flaw for code execution

BleepingComputer reports that hackers have started exploiting a critical WordPress flaw to achieve code execution. The source, published September 23, 2026, states that exploitation of the vulnerability is underway and that the flaw enables code execution. No further details about the vulnerability, the attackers, the affected versions, or the number of impacted sites are provided in the available source text.

The source says a critical WordPress flaw enabling code execution is being actively exploited, which is relevant to developers running WordPress.

wordpresssecurityexploitcode-execution
bleepingcomputer.com
Hackers start exploiting critical WordPress flaw for code execution
Node 20 is no longer available in GitHub Actions
#2 / TOP STORY
GitHub ChangelogFREE

Node 20 is no longer available in GitHub Actions

GitHub announced in a changelog post dated September 23, 2026, that Node 20 is no longer available in GitHub Actions. The post is titled "Node 20 is no longer available in GitHub Actions" and appears on the GitHub Changelog. The available source text consists of the title and page styling markup, with no additional detail on migration paths, replacement versions, or affected workflows. The stated consequence is that Node 20 can no longer be used in GitHub Actions.

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
#3 / TOP STORY
The Hacker NewsFREE

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

The Hacker News reports that compromised MemTensor packages distributed a credential stealer called sckit through both npm and PyPI. The report, published September 23, 2026, describes the incident as supply-chain compromise affecting the MemTensor package ecosystem across the two registries. The stealer's stated purpose is credential theft, according to the source. The source does not name specific package versions, affected version ranges, download counts, or a remediation status.

aigest · daily

Get this every morning.

One email. The signal. Built for builders.

Free · Unsubscribe in one click · No trackers

// Worth acting on2 stories
// Worth knowing3 stories
// Yesterday8 stories