AI news you can use — August 20, 2026
A critical flaw in Elementor Pro lets strangers take over WordPress sites
Elementor Pro, one of the most widely used page builders for WordPress, has a flaw in its contact-form module that lets an unauthenticated visitor upload a file the site was supposed to reject and then run it — effectively handing over the site. It is rated 9.0 out of 10 for severity, affects every version up to and including 4.2.1, and is fixed in version 4.2.2, released August 19. A site is exposed if it has even one published page with a form that includes a file-upload field — no unusual setup required. There are no reports of attacks yet, but details of how the flaw works are now public.
Why it matters: If your business website runs WordPress with Elementor Pro, log in today, open Plugins, and update to 4.2.2 or later. If you are not sure whether you have Elementor Pro or who maintains your site, ask whoever built it to confirm the version this week. While you are in there, delete plugins you no longer use — the fewer add-ons running, the fewer flaws like this one apply to you.
Forty Firefox add-ons posing as crypto wallets were stealing recovery phrases
Researchers identified 40 malicious Firefox extensions inside a set of 77 add-ons that shared code and servers. Some impersonated well-known cryptocurrency wallet products; others posed as harmless football, basketball and hockey score trackers. Once installed, they harvested wallet recovery phrases, private keys, saved credentials and clipboard contents, sometimes through convincing fake wallet screens. The campaign has been running since March 2026, and the operators kept publishing replacements as older ones were removed — the add-ons have since been pulled from the Firefox store.
Why it matters: Browser extensions run inside every page you open, including your bank and your email, and a fake one looks identical to the real thing in a store listing. Open your browser's extensions page, remove anything you do not actively use or do not remember installing, and only install a wallet add-on from a link on the wallet company's own website. If you installed a wallet extension recently and hold cryptocurrency, move it to a new wallet with a fresh recovery phrase — an exposed phrase cannot be changed after the fact.
Researchers made expired Visa cards pay for things again
A university team demonstrated an attack they call Zombie Card at a security research conference this month: using two ordinary phones, they relayed the signal from an expired contactless Visa card to a checkout terminal while rewriting the expiry date in transit. It works because, in the Visa contactless setup they tested, the expiry date is not covered by the card's own digital signature, so changing it does not break the security check the terminal performs. Results varied across five US banks — one approved the revived payments, one declined them all. Equivalent Mastercard, American Express and Discover setups resisted the attack. This is laboratory research, not something being used against people today, and the researchers reported it to Visa and the banks before publishing.
Why it matters: The practical lesson is about the dead cards in your drawer. When a card expires, cut through the chip and the magnetic stripe before throwing it out rather than tossing it in whole, and keep an eye on statements for accounts you have closed or replaced — a closed account is not one most people check.
A web page can trick Grok into handing over your chat history
Security researchers showed that a booby-trapped web page can make Grok leak the user's conversation to an outside server. The trick is to hide the instructions on the page in encrypted form: the safety filter that scans incoming text cannot read them, but the chatbot itself can decrypt and then follow them. If you ask Grok to summarise such a page, it can send your name, rough location, subscription tier and everything you typed in that conversation to the attacker, with no warning and nothing to click. It worked in roughly 40 percent of attempts in testing. There is no fix available at the time of writing.
Why it matters: This is a general weakness in AI assistants that can read web pages, not a one-off bug — anything an assistant reads can contain instructions aimed at the assistant. Treat an AI chat window like a semi-public place: do not paste account numbers, passwords, client details or anything confidential into one, and be wary of asking any assistant to summarise a page you landed on from an unsolicited email or message.
Google put free study tools into Search and Gemini
Google added a set of learning features across Search and its Gemini assistant, all free. Search can now generate practice quizzes on a topic, including for standardised tests, and build interactive visuals and simulations to explain a concept rather than just describing it. Pointing your phone camera at a problem through Google Lens will walk through it step by step and flag where the mistake was, rolling out globally in English over the coming weeks. There is also a notebook in AI Mode that gathers your own documents and notes so you can ask questions about them, rolling out in more than 180 countries, and it syncs with the Gemini app.
Why it matters: If you have kids heading back to school, these replace a lot of what families currently pay for in tutoring apps and test-prep subscriptions — worth trying before renewing one. The same notebook feature works for non-students too: dropping in your own manuals, contracts or policy documents and asking questions about them is the practical version of this for a small business. Check the answers on anything that matters, though; these tools still get things wrong with total confidence.