EVREN opening with 11 open-weight language models, unbacked generic green claims landing on the EU blacklist, and an Elementor flaw that turns one link into an attacker admin account
Today’s 3 verified stories: EVREN, the AI platform developed within Türkiye’s Presidency of Defence Industries, has opened with an inference layer serving 11 open-weight large language models through an API, and API calls until November 1, 2026 are not deducted from credit balances. According to the European Commission, Directive (EU) 2024/825 has applied since September 27, 2026, putting unbacked generic environmental claims, sustainability labels based neither on a certification scheme nor on a public authority, and offset-based product climate claims on the EU blacklist. Patchstack disclosed a CSRF flaw in versions 4.3.0 and 4.3.1 of the Elementor plugin that lets a logged-in administrator opening one link create an admin account for an attacker, fixed in 4.3.2. The detailed look at each story, its sources and what it means for your business lives on its own page.
Türkiye’s defence industry AI platform EVREN opens with 11 open-weight language models
Anadolu Agency reported on September 27, 2026 that EVREN, the AI platform developed within Türkiye’s Presidency of Defence Industries, has opened for use. An inference layer covering 11 open-weight large language models is now live, existing applications can connect through an API, and API calls made until November 1, 2026 are not deducted from credit balances. A DefenceTurk screenshot shows the models are called through a single OpenAI-compatible API. Instead of selling access, EVREN runs on credits that users earn by uploading datasets, labelling data or sharing models they have trained. Sign-in is through e-Devlet, and prompts and responses are processed on GPU infrastructure in Türkiye. Anadolu Agency puts active users at 7,500, TRT Haber at more than 8,000.
Generic green claims and eco-labels without proper backing are now on the EU blacklist
According to the European Commission, Directive (EU) 2024/825 has applied since September 27, 2026. The Unfair Commercial Practices Directive’s blacklist of practices banned in all circumstances now covers generic claims such as eco-friendly or green that the trader cannot back with recognised excellent environmental performance, sustainability labels based neither on a certification scheme nor on a public authority, and offset-based claims that a product has a neutral, reduced or positive emissions impact. The Commission’s Q&A gives labels no transition period beyond that date, requires old stock to comply too and applies the rules to traders from third countries. Labels from non-EU public authorities must also rest on a certification scheme. National authorities and courts enforce the rules.
The CSRF flaw in Elementor 4.3.0 and 4.3.1 lets a single link hand an attacker an admin account
On September 25, 2026 the security company Patchstack disclosed a CSRF flaw in the Elementor Website Builder plugin that affects only versions 4.3.0 and 4.3.1, scoring it 8.8 on CVSS. Whenever the string elementor/v1/events/ appears anywhere in the request URI, the Editor Events module tells WordPress authentication has already succeeded, so the core nonce check for cookie-authenticated REST requests never runs. On a default installation, a logged-in administrator opening one link creates a second administrator account for the attacker, and the bypass reaches the REST endpoints of core and every other installed plugin. Elementor fixed it in 4.3.2 on September 24, and Patchstack recommends updating. Reports citing WordPress.org statistics put the affected versions at roughly 2 million sites.
The agenda moves fast, the system stays calm.
Let us talk about what these shifts mean for your business and work out together which step fits you.