⏐ Taklimat Pagi
Taklimat Pagi Saya
🔗 baca_penuh: pagi.hejes.my/2026/09/12
> ringkasan_ai
# 🤖 AI & Machine Learning (The Big Stuff)
✅ **OpenAI Lancar GPT-6 Astra & GPT-Live-1** [OpenAI/Amanz] — Model Astra sekarang dah power gila sampai Perplexity guna untuk monitor sistem, manakala GPT-Live-1 bawa voice conversation yang lebih natural ke API. OpenAI siap tutup langganan ChatGPT Pro $200 kejap sebab ramai sangat nak guna Astra.💡 **Kenapa Penting** — Standard AI dah naik level; keupayaan *agentic* dan suara sekarang dah makin *seamless*.
✅ **Perang 'Distillation' AI: China vs US** [CISA/Hacker News/TechCrunch] — Lab AI dari China (Alibaba, DeepSeek, etc.) kantoi buat 'industrial-scale distillation' untuk curi fungsi model Claude (Anthropic) dan model US lain. Garry Tan pula cadang US buat benda sama untuk lawan balik.💡 **Kenapa Penting** — Ni bukan setakat isu tech, tapi dah jadi perang geopolitik pasal siapa pegang "otak" AI paling power.
✅ **Cohere & Sakana AI Lancar Model Baru** [MarkTechPost] — Cohere keluarkan North Small Translate (MoE) untuk 50 bahasa, manakala Sakana AI lancarkan Fugu Max/Ultra v2 untuk orchestration multi-agent yang lebih murah.💡 **Kenapa Penting** — Pilihan model yang lebih spesifik dan murah makin banyak, tak payah bergantung pada satu gergasi je.
✅ **Google Gemini Kini Di Windows** [Amanz] — Google dah release app Gemini khas untuk Windows supaya user boleh akses pantas terus dari desktop.💡 **Kenapa Penting** — Workflow Master akan jadi lebih laju kalau Gemini ada terus kat desktop.
# 🛡️ Cybersecurity (The Scary Stuff)
✅ **Claude Jadi Alat Hacker** [BleepingComputer/Hacker News] — Anthropic dedahkan group hacker Russia & China guna Claude untuk buat malware, extract secret dari 1.8 juta app Android, dan automate serangan siber.💡 **Kenapa Penting** — AI bukan setakat bantu coder, tapi sekarang dah jadi "senjata" automatik untuk penjenayah siber.
✅ **Krisis Vulnerability & Leak** [CISA/SecurityWeek/BleepingComputer] — Banyak CVE kritikal baru (GitLab, OpenStack, OpenMRS) dan kes leak kredensial CISA kat GitHub selama 6 bulan. Ada juga kes database DMV Florida kena breach.💡 **Kenapa Penting** — Peringatan untuk Master check balik semua patch dan jangan biar API key terlepas kat public repo.
✅ **Scam Passkey & Proxy TV** [BleepingComputer/Krebs] — Hacker guna tema 'passkey' untuk curi data Microsoft 365, dan LG nak ban app Smart TV yang tukar TV jadi residential proxy tanpa user tahu.💡 **Kenapa Penting** — Teknik phishing makin licik, sekarang dia target benda yang kita rasa "selamat" macam passkey.
# 🇲🇾 Lokal & Tech Lain-lain
✅ **BYD Batal Kilang CKD Tanjong Malim** [Amanz] — BYD decide tak jadi buat kilang kat Perak sebab nak cari lokasi dan pelaburan yang lebih strategik.💡 **Kenapa Penting** — Impak besar pada landskap automotif elektrik (EV) kat Malaysia.
✅ **Insta360 Luna Pro Masuk Malaysia** [Amanz] — Kamera kompak sensor 1" hasil collab dengan Leica kini boleh dibeli bermula RM2099.💡 **Kenapa Penting** — Kalau Master nak upgrade gear content creation, ni option yang mantap.
🔥 Top Picks
**GPT-6 Astra & GPT-Live-1** (Game changer untuk AI agents & voice).
**China's Distillation Campaign** (Drama geopolitik AI yang sangat serius).
**Claude's Abuse by State-Sponsored Hackers** (Bukti AI dah jadi tool serangan skala besar).
> ls -la berita/
🧠 AI/ML
37AI for Food Allergies
China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies
Executive summary China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form
Sentence Transformers is joining Hugging Face!
Google Research Releases ToolGrad: Answer-First Framework Hits 99.8% Pass Rate for Tool-Use Data Generation
Google Research has released ToolGrad, an ACL 2026 Findings framework that inverts tool-use dataset generation: it builds a verified API chain first, then writes the matching user query. Guided by textual "gradients" from a 4-module propose-execute-s
Cohere Releases North Small Translate: A 218B MoE Translation Model That Scores 83.6 on WMT26 Across 50 Languages
Cohere has released North Small Translate, an open-weight Mixture-of-Experts model built for machine translation across 50 languages. It uses 25B of its 218B parameters per token and scores 83.6 on Cohere's WMT26 evaluation. Weights are free for non-
Supercharge your OCR Pipelines with Open Models
Google Perkenal Aplikasi Gemini Untuk Windows
Google hari ini melancarkan aplikasi Gemini untuk Windows, sekaligus membolehkan para pengguna komputer Windows untuk mengakses pantas Gemini dengan mudah di desktop. Dengan memasang aplikasi ini juga, pengguna boleh melakukan akses pantas dengan men
Cognition helps Devin test its own work with GPT‑6 Astra
GPT‑6 Astra improves Devin’s ability to test software and show that it works, with the goal of helping engineers review less code and ship more.
What Byzantine Fault Tolerance Can Teach Us About Trust in Multi-Agent AI Systems
Multi-agent AI failures look like broken identities, but recent research shows they behave like Byzantine faults in distributed systems.
Khosla Ventures is opening a New York office this fall — its first outpost outside Sand Hill Road
"It's actually allegedly being built out now," said Rabois, who has clearly dealt with a missed construction timeline or two.
OpenAI Menutup Sementara Langganan Baru Untuk ChatGPT Pro $200 Disebabkan Permintaan Tinggi Untuk Astra
OpenAI kini menghentikan sementara langganan baru untuk pelan ChatGPT Pro $200, disebabkan oleh permintaan tinggi sejak pelancaran model terbaru mereka, Astra. Disebabkan permintaan tinggi, ia sekaligus membawa kepada penggunaan perkomputeran tinggi,
Roundtables: AI’s apocalypse crisis
Employees at the world’s leading AI labs are saying there’s a real possibility that advanced AI could destroy humanity. Are they right? Or is this more scaremongering and hype? Join MIT Technology Review executive editor Niall Firth for a conversatio
Build more natural voice experiences with GPT‑Live‑1 in the API
GPT‑Live‑1 brings natural, full-duplex voice conversations to the API, with stronger instruction following, custom voices, and telephony support.
Hackers abused Claude to extract secrets from 1.8M Android apps
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. [...]
Sakana AI Launches Fugu Max and Fugu Ultra v2 for Cheaper, Stronger Multi-Agent Orchestration
Sakana AI has released Fugu Max and Fugu Ultra v2, 2 models built on the same learned orchestration architecture. Fugu Max routes tasks to lean open and specialized models, including NVIDIA Nemotron, at $2/$6 per 1M tokens. Fugu Ultra v2 targets peak
Mecka AI nears $500M valuation in Sequoia-led deal amid rush for robot training data
The round for the two-year-old startup is coming together months after Mecka announced its Series A.
Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain
From creating lab environments for staging and testing agentic attacks to reconnaissance to lateral movement and exfiltration, the most innovative attackers are widely incorporating AI.
Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
Cybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI.
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax. Knowledge distillation by itself
BYD Batalkan Kilang CKD Di Tanjong Malim
BYD Malaysia mengesahkan projek kilang pemasangan CKD di Tanjung Malim, Perak tidak akan diteruskan. Keputusan ini bukan kerana halangan tetapi langkah tegas syarikat menilai semula lokasi dan pelaburan yang lebih strategik. Perubahan ini jelas menun
Hugging Face and VirusTotal collaborate to strengthen AI security
Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a grou
Unlock the power of images with AI Sheets
Anthropic Adds Plugin Evals to Claude Code: 6 Grader Types, a No-Plugin Baseline, and a CI Gate for Skills
Anthropic has published a new plugin evals workflow for Claude Code. The claude plugin eval command runs a plugin against realistic prompts, grades what Claude produced, and compares the result with a run where the plugin is not loaded. It answers 3
Can LLMs Engineer Their Own Agent Harness? ByteDance Seed’s HarnessDev Says Only 34 of 64 Changes Generalize
ByteDance Seed, SUTD, Georgia Tech, M-A-P, and TokenWave.AI introduce HarnessDev, a benchmark that scores the runnable harness a model builds rather than the answer it returns. Starting from a seed that scores 0, 6 creator LLMs construct harnesses ac
How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI conversations, spo
Y Combinator’s Garry Tan wants US open-weight AI labs to ‘distill’ frontier models, too
Tan wants smaller, American open-weight AI labs to use the same kind of training techniques on American frontier AI labs, giving the U.S. a more robust set of open-weight options that aren’t Chinese.
Perplexity trusts GPT-6 Astra with end-to-end systems
Perplexity uses Astra to write communications, change software, and monitor production systems, and checks in much less frequently than with earlier models.
Rapidly scaling online storage to serve over 1 billion ChatGPT users
Learn how OpenAI evolved Habitat from a Python library into a globally distributed storage platform serving 1 billion ChatGPT users and 22M requests per second.
OpenAI’s feud with mathematicians is only escalating
Twenty-five leading mathematicians signed an open letter arguing that AI labs are threatening their intellectual work.
AI Governance Can't Wait
Adversaries can manipulate AI defensive reasoning to silently compromise target networks.
Just Dance: Decades of Hits Akan Dilancarkan Pada 10 November – Membawa Lagu Hits Pelbagai Dekad
Ubisoft bakal melancarkan judul terbaharu siri tarian popularnya, Just Dance: Decades of Hits, yang menghimpunkan pilihan 35 lagu ikonik merentasi era 1970-an sehingga 2020-an. Permainan ini akan dilancarkan pada 13... The post Just Dance: Decades of
Why AI Is So Good at Scamming Humans
Fred Heiding of Menlo Park Intelligence talks with the Dark Reading News Desk about his research on frontier models, and their ability to influence human behavior and create emotional dependency.
Ulasan Gangstar: Mirage City
Gangstar oleh Gameloft merupakan satu siri permainan dunia terbuka yang bertapak sejak tahun 2006 lagi melalui permainan pertama mereka Gangstar: Crime City. Sepanjang 20 tahun ini, terdapat pelbagai permainan-permainan lain... The post Ulasan Gangst
Credible Captain Launches Independent Consumer Review Platform Focused on Transparency, AI and Trust
Created with transparency, fairness, and innovation at its core, Credible Captain was founded by a group of successful business owners who have chosen to remain
Election information and safeguards in 2026
Learn how OpenAI is supporting elections in 2026 through reliable information, cyber defense, AI transparency, misuse safeguards, and bias monitoring.
Kementerian Digital Umum Pelantikan Ahli Lembaga Pengarah Untuk AI Malaysia Berhad
Kerajaan sebelum ini telah melancarkan AI Malaysia Berhad, iaitu sebuah agensi dibawah Kementerian Digital yang memfokuskan kepada penyelerasan agenda AI kebangsaan, mempromosikan penerapan AI yang selamat dan bertanggungjawab, serta memacu Pelan Tin
🛡️ Cybersecurity
27Phishing Research Challenges Conventional Security Awareness Testing
Analysis of 2.47 million simulated attacks shows why organizations should measure credential leaks and reporting, not just clicks. The post Phishing Research Challenges Conventional Security Awareness Testing appeared first on SecurityWeek.
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-85706 GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability This type of vulnerabilit
CVE-2026-90444 - Product Name OS Command Injection via Filename Validation Bypass
CVE ID :CVE-2026-90444 Published : Sept. 11, 2026, 10:16 p.m. | 1 hour, 29 minutes ago Description :A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated
CVE-2026-90451 - Packet-Analysis Component Authentication Cookie Forgery via Hardcoded Secret
CVE ID :CVE-2026-90451 Published : Sept. 11, 2026, 10:16 p.m. | 1 hour, 29 minutes ago Description :An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-ana
Artifactory flaws chained in attacks deploying backdoor malware
Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. [...]
CVE-2026-49464 - NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak
CVE ID :CVE-2026-49464 Published : Sept. 11, 2026, 9:17 p.m. | 2 hours, 28 minutes ago Description :NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner or
CareCam Pro IP Cameras
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take full control of the device. The following versions of CareCam Pro IP Cameras are affected: ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threat actors, which the artificial
CVE-2026-90461 - OpenStack Ironic Credential Exposure Vulnerability
CVE ID :CVE-2026-90461 Published : Sept. 11, 2026, 10:16 p.m. | 1 hour, 34 minutes ago Description :OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authe
Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. The operation has been attributed to a cyber espio
GitLab Vulnerability Exploited One Day After Disclosure
The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server. The post GitLab Vulnerability Exploited One Day After Disclosure appeared first on SecurityWeek.
CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols.
CVE-2026-90460 - OpenStack Keystone Improper Access Control Vulnerability
CVE ID :CVE-2026-90460 Published : Sept. 11, 2026, 10:16 p.m. | 1 hour, 34 minutes ago Description :An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application creden
4 Ways to Win a Hackathon (None of Them Is Writing Code)
Learn how to win a hackathon with four practical lessons on product vision, AI coding tools, tech choices and pitching, from a hackathon winner.
CVE-2026-90456 - Inventory Management Component Default Administrative Credential Vulnerability
CVE ID :CVE-2026-90456 Published : Sept. 11, 2026, 10:16 p.m. | 1 hour, 34 minutes ago Description :An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A d
Florida confirms DMV database breached via stolen police account
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. [...]
Canadian Man Pleads Guilty in Snowflake Extortions
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider S
Your Critical Vulnerabilities Might Not Be Your Biggest Risk
Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise. A critical vulnerability
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability CVE-2026-19490 Citrix NetScaler
CVE-2026-54174 - melange: Incomplete package integrity verification allows data section substitution
CVE ID :CVE-2026-54174 Published : Sept. 11, 2026, 9:17 p.m. | 2 hours, 28 minutes ago Description :melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4,
CVE-2026-44715 - OpenMRS has Broken Access Control in HL7 Configuration
CVE ID :CVE-2026-44715 Published : Sept. 11, 2026, 10:16 p.m. | 1 hour, 29 minutes ago Description :OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticated user can trigger administra
Lessons Learned from CISA’s Recent GitHub Leak
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six mont
CVE-2026-90457 - Product Credential Store Insecure Password Hash Storage and Improper Access Control
CVE ID :CVE-2026-90457 Published : Sept. 11, 2026, 10:16 p.m. | 1 hour, 34 minutes ago Description :The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and the fil
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a
CVE-2026-89266 - stb_vorbis through 1.22 heap buffer overflow via codebook multiplicands
CVE ID :CVE-2026-89266 Published : Sept. 11, 2026, 11:23 p.m. | 27 minutes ago Description :stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. A
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability CVE-2026-42018 JFrog Artifactory Improper
Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack
Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking. The post Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack appeared first on SecurityWeek.
⚡ Tech/Dev
8LG to Ban Residential Proxies from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more th
Passkey-themed phishing attacks lead to Microsoft 365 data theft
Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. [...]
Carrie Menerima Treler – Tiba Di Prime Video Oktober Ini
Prime Video telah melancarkan treler rasmi bagi siri televisyen terbaharu, Carrie, yang dijadualkan menemui penonton pada 7 Oktober 2026. Siri lapan episod terbitan Amazon MGM Studios ini diadaptasi daripada novel... The post Carrie Menerima Treler –
One week left to book your exhibit table at TechCrunch Disrupt 2026
Only one week left to secure your exhibit table. Tables are limited and can sell out before the September 18 deadline.
In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review
Noteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber official, military ties of Chinese hacking group QTFY. The post In Other News: InjectEave Attack, S
Pratonton Made in Korea (Musim 2) – Drama Siasatan Dan Perebutan Kuasa
Selepas kejayaannya menepis ancaman Jang Geon-young (Jung Woo-sung) di musim pertama, Baek Ki-tae (Hyun Bin) kini lebih berkuasa dan turut memasang cita-cita yang lebih tinggi termasuk juga menjadi pengarah untuk... The post Pratonton Made in Korea (
Microsoft Patches a Record 570 Security Flaws
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release
Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison
Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023. The post Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison appeared first on SecurityWeek.
🇲🇾 Malaysia/Lokal
3Insta360 Luna Pro Dilancarkan Di Malaysia – Harga Bermula RM2099
Insta360 Luna Pro dilancarkan ke pasaran global dua minggu selepas dilancarkan di China. Kamera kompak dengan gimbal ia versi dengan satu sahaja kamera dilengkapi sensor 1″ yang dibangunkan menerusi kerjasama dengan Leica yang membezakannya dengan Lu
GoMining Launches GoMining Gifts, a Bitcoin Miner You Can Send as a Present in One Link
GoMining Gifts lets anyone send a digital Bitcoin miner as a present in one link. Eight tiers from under $20, one-tap activation, no crypto experience needed.
Asus Lancar Desktop ROG G100 – AMD Ryzen 9, RTX5080, Bermula RM29,999
ASUS Republic of Gamers (ROG) secara rasmi melancarkan desktop gaming mercu terbaharunya, ROG G1000, untuk pasaran Malaysia. Hadir dalam reka bentuk casis bersaiz 104 liter (ATX Ultra Tower) dengan berat... The post Asus Lancar Desktop ROG G100 – AMD