News
Tech and automobile headlines, newest first, refreshed automatically every few hours. Each story links to a summary here, then out to the original source for the full article.
Tech

Apple’s new Upgrade program makes getting a Mac easier, but it may not save you money
Image via Apple Apple has expanded its upgrade program beyond the iPhone, giving customers a new way to get Macs, iPads, Apple Watches, and iPhones without paying the full price upfront. The catch

US' first sixth-gen fighter jet could fly with less powerful engine
Regardless of the engine used initially, the F-47 is expected to be significantly more capable than previous generations of fighters in terms of survivability, networking, sensor fusion, and long-range operations.
RevAPK: Reverse engineer Android apps
submitted by /u/cronocr [link] [comments]
CVE-2026-56672 ComfyUI: Stored XSS via /userdata/{file} due to Missing Content-Type Sanitization
ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/file served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and access to browser-stored API tokens, settings, workflows, ...
CVE-2026-56672 ComfyUI: Stored XSS via /userdata/{file} due to Missing Content-Type Sanitization
ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/file served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and access to browser-stored API tokens, settings, workflows, ...

CVE-2026-62323 Cloudreve WOPI ViewerSessionValidation improper authentication
A security vulnerability has been detected in Cloudreve up to 4.16.x. This vulnerability is listed as CVE-2026-62323. Upgrading the affected component is recommended.
CVE-2026-63220 | CodeIgniter up to 4.7.3 isSecure information disclosure
A vulnerability marked as problematic has been reported in CodeIgniter up to 4.7.3. This affects the function IncomingRequest::isSecure. This manipulation causes information disclosure. This vulnerability is tracked as CVE-2026-63220. The attack is possible to be carried out remotely. No exploit ex...

Nothing Phone (4a) Buyers May Have to Pay Rs. 3,000 More From August 1
All three variants of the Nothing Phone 4a could become more expensive by Rs. 3,000, as per the tipster.
CVE-2026-56671 ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file read
ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, getmodelpreview in app/modelmanager.py joins an unrestricted filename route capture to a selected model directory without a containment check, allowing an unauthenticated remote attacker to use t...
CVE-2026-56671 ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file read
ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, getmodelpreview in app/modelmanager.py joins an unrestricted filename route capture to a selected model directory without a containment check, allowing an unauthenticated remote attacker to use t...
CVE-2026-56670 ComfyUI: Stored XSS via SVG file upload on the /view endpoint
ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline because image/svg+xml and related XML content types were absent from the dangerous-content-type handling, allowing stored cross-site scripting ...
CVE-2026-56670 ComfyUI: Stored XSS via SVG file upload on the /view endpoint
ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline because image/svg+xml and related XML content types were absent from the dangerous-content-type handling, allowing stored cross-site scripting ...
CVE-2026-63220
CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an attacker could spoof these headers and cause the application to incorrectly treat an HTTP request as s...
CVE-2026-55497
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed file size but do not limit decoded pixel dimensions, allowing an authenticated user to submit a small PNG, JPEG, or GIF that triggers an unbounded allocat...
CVE-2026-55502
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even though GetOauthRedirectService persists caller-supplied OneDrive secret and appid values, allowing an OAuth token without Admin.Write to modify storage...
CVE-2026-55499
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscription resolves the share root to the owner’s parent folder and subscribes to that folder topic, allowing an authenticated share recipient to receive names, paths, rename targets, e...
CVE-2026-55495
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUTRELATIVE handler passes X-WOPI-SuggestedTarget to URI.JoinRaw as a path rather than a filename, allowing slash and dot-dot segments to escape the source file directory and create or conditionally overwrite fi...
CVE-2026-55496
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActive without adding a StatusActive predicate and serializes matches at RedactLevelUser, allowing any logged-in user to enumerate email addresses and profile metadata for inactive or ...
CVE-2026-43833
Successful exploitation of the vulnerability could allow an authenticated attacker to exploit a stack-based buffer overflow in the upload functionality to conduct code execution...
CVE-2026-43830
Successful exploitation of the command injection vulnerability could allow an attacker to execute arbitrary commands during the firmware upgrade file verification process...
Automobiles

Electric car tax looms for one state unless PM steps in
One state is prepared to charge ahead with a tax on electric vehicle drivers unless the federal government introduces a national scheme.

China Automotive Systems (CAAS) Projected to Announce Quarterly Earnings on Friday
China Automotive Systems (NASDAQ:CAAS) will be releasing its Q1 2026 earnings before the market opens on Friday, August 7. (View Earnings Report at https://www.marketbeat.com/earnings/reports/2026-8-7-china-automotive-systems-inc-stock/)
India, Bhutan review development partnership; sign Rs 4,000-crore LoC agreement
India and Bhutan reviewed development projects during high-level talks. A concessional line of credit worth Rs 4,000 crore was signed. Cooperation in health education and research was also expanded between institutions. Forty-five electric vehicles were handed over to support green mobility initiati...
E-cars: what are they, when might they arrive, and could they be the future of EVs? | Stuff
The groundwork is being laid for an all-new class of EV. Here's what the E-Car could look like

Factbox-Tesla’s China operations, the EV maker’s global production powerhouse By Reuters
Factbox-Tesla’s China operations, the EV maker’s global production powerhouse
Factbox-Tesla’s China operations, the EV maker’s global production powerhouse
SHANGHAI/BEIJING, July 31 (Reuters) - Tesla is considering a separation of its China business to pave the way for a potential merger with SpaceX, the Wall Street Journal reported, citing a person familiar with the talks. Reuters was unable to independ...

Sonic Automotive (SAH) Q2 2026 Earnings Call Transcript
@media (max-width: 768px) { .image-container { width: 100% !important; float: none !important; margin: 0 0 1rem 0 !important; } } Image source: The Mo

Nissan Patrol, X-Trail and Toyota factories hit by Japan earthquake
Several auto factories have halted operations after a major earthquake in southwest Japan; the impact on Australian vehicle supply remains unknown.

Honda Super-One baby EV's leaked price was wrong, says Honda Australia
The Japanese automaker says a previous configurator 'leak' used placeholder pricing for its city-sized Super-One electric vehicle, with official Australian pricing to be announced next week.

Honda Super-One baby EV's leaked price was wrong, says Honda Australia
The Japanese automaker says a previous configurator 'leak' used placeholder pricing for its city-sized Super-One electric vehicle, with official Australian pricing to be announced next week.

2026 Polestar 3 review
Polestar is growing slowly in Australia, and its updated large electric SUV is a good demonstration of its continued efforts to gain popularity here.
Luxury auto giant cuts 5,000 more jobs in major reset
Porsche has long occupied a rare position in the auto industry as a premium sports-car brand capable of delivering some of the industry's strongest profit margins. But weaker demand, slowing sales in China, and the high cost of supporting electric, hybrid, and combustion-engine vehicles ...

Musk dismisses report of Tesla’s potential China business sale By Reuters
Musk dismisses report of Tesla’s potential China business sale

Industry seeks clarity ahead of EV bike launch
Indonesia's plan to launch a national electric motorcycle brand within weeks is prompting industry players to seek clarity over the programme, as the government moves to redirect long-delayed purchase incentives for electric vehicles (EV) to the new initiative.

Data Centers Need Power Fast. The Auto Industry Already Has It.
Hyperscalers are racing to secure electricity for AI data centers. Electric vehicles could be the fastest fix in the quest for speed to power.
Sonic Automotive targets EchoPark $3,100-$3,300 total GPU and 12%-15% used unit growth in 2026 while planning 2-4 new locations in 2027
Sonic Automotive targets EchoPark $3,100-$3,300 total GPU and 12%-15% used unit growth in 2026 while planning 2-4 new locations in 2027

BMW profit down a third as carmaker plans job cuts
Net profit at premium carmaker BMW fell over a third in the second quarter, the firm said Thursday as it prepares to cut almost 10 percent of its German workforce. Net income in the three months to the end of June came in at 1.2 billion euros ($1.4 billion), BMW…

Sonic Automotive, Inc. (SAH) Q2 2026 Earnings Call Transcript
Sonic Automotive, Inc. (SAH) Q2 2026 Earnings Call July 30, 2026 11:00 AM EDTCompany ParticipantsDavid Smith - CEO & ChairmanFrank Dyke - President...

Sonic Automotive, Inc. (NYSE:SAH) to Issue $0.41 Quarterly Dividend
Sonic Automotive, Inc. (NYSE:SAH) declared a quarterly dividend on Thursday, July 30th. Shareholders of record on Tuesday, September 15th will be given a dividend of 0.41 per share on Thursday, October 15th. This represents a c) dividend on an annualized basis and a yield of 1.6%. The ex-dividend da...
Gov’t unveils P60-B incentive to pitch PH as EV makers’ hub
MANILA, Philippines — President Marcos has greenlighted a P60-billion incentives package aimed at luring electric vehicle (EV) manufacturers to produce their units in the Philippines, as the government drives to position the country as a regional automotive manufacturing hub. Executive Order (EO) No...

Rivian Automotive (RIVN) Q2 Earnings: Taking a Look at Key Metrics Versus Estimates
Although the revenue and EPS for Rivian Automotive (RIVN) give a sense of how its business performed in the quarter ended June 2026, it might be worth considering how some key metrics compare with Wall Street estimates and the year-ago numbers.