Security researchers say hackers are exploiting two chained vulnerabilities, CVE-2026-61979 and CVE-2026-15981, in the miniOrange SAML 2.0 Single Sign On plugin to forge SAML responses and log into WordPress sites as administrators. The plugin, made by Xecurify, lets sites authenticate through identity providers like Microsoft Entra ID, Okta, Google Workspace or OneLogin, and comes in a free version plus six paid editions used by roughly 30,000 customers.
bleepingcomputer.com
· 2026-08-24
Code inside Google Play Store version 52.8.55-34 reveals that the Ask Play conversational search feature will soon accept image attachments from a phone's camera or gallery. Users could upload a screenshot of a home screen widget or app feature and ask Ask Play's AI to identify it or find similar apps. Google also appears ready to drop the separate 'Ask Play about this app' section, replacing it with scrollable suggested-question chips.
androidauthority.com
· 2026-08-24
A user posted an 'Ask HN' thread inviting developers to share side projects generating at least $500 monthly income in 2026, continuing a tradition of similar posts from prior years. The poster noted a recent attempt at this question failed to gain traction, and admitted their own side projects currently earn nothing.
news.ycombinator.com
· 2026-08-24
CISA has ordered federal civilian agencies to fix CVE-2026-73570, a Zimbra Collaboration Suite flaw allowing unauthenticated attackers to run arbitrary commands via crafted SMTP requests when SNMP notifications are enabled. Zimbra released a fix in version 10.1.20 on July 20, but CERT Polska flagged active exploitation last week, and Shadowserver has already identified over 270 compromised Zimbra servers among more than 12,000 exposed online.
bleepingcomputer.com
· 2026-08-24