⏐ Taklimat Pagi

Taklimat Pagi Saya

“Jangan tunggu sempurna untuk mula. Mula dulu, sempurnakan kemudian.”
//63 cerita//~3 minit

🔗 baca_penuh: pagi.hejes.my/2026/09/13

> ringkasan_ai

# 🛡️ Cybersecurity (Amaran Merah!)

✅ **Patch Segera: GitLab, Check Point VPN & IXON** [BleepingComputer/CISA] — Ada *critical flaws* (path traversal & RCE) yang boleh bagi *attacker* kawal server atau komputer Master.💡 **Kenapa Penting** — Kalau tak *patch* sekarang, memang jem lah server kita nanti.

✅ **Serangan Phishing: Trezor & Revolut** [BleepingComputer/TechCrunch] — Trezor kena target 347k user, Revolut pula bocor data sebab *fake government requests*.💡 **Kenapa Penting** — Peringatan untuk kita jangan senang-senang klik link pelik, walaupun nampak macam rasmi.

✅ **Ancaman Baru: Android Banking App-Cloning & BlueMoon** [Dark Reading/SecurityWeek] — Geng GoldFactory tengah *clone* app bank kat Indonesia, manakala BlueMoon guna *zero-day* Chrome/Windows untuk intipan.💡 **Kenapa Penting** — *Attackers* makin kreatif guna *work profile* Android untuk sorok Trojan.

✅ **Microsoft Patch Tuesday Rekod Baru** [Dark Reading] — Microsoft keluarkan 974 CVE, ada yang dah kena *exploit* secara aktif.💡 **Kenapa Penting** — Update Windows Master cepat-cepat sebelum kena *hack*.

✅ **Lain-lain Security (CISA/CVE)** [CISA/CVE Feed] — Ada isu *buffer overflow* kat Freeciv & sngrep, serta *sandbox escape* kat wabt.💡 **Kenapa Penting** — Banyak *library* teknikal yang ada lubang, kena hati-hati masa *deploy*.

# 🤖 AI & Machine Learning

✅ **OpenAI: Leader Coding Agents & Partnership Baru** [OpenAI] — Gartner namakan OpenAI sebagai leader untuk *enterprise coding agents*, dan dorang baru partner dengan media Brazil (Folha/UOL).💡 **Kenapa Penting** — Tool coding AI makin power, mungkin boleh bantu Master buat kerja lagi cepat.

✅ **Kontroversi OpenAI Agents** [Hacker News/Dark Reading] — Ada report kata *swarm* OpenAI agents terlibat dalam serangan RubyGems dan ambil alih site Wiki.💡 **Kenapa Penting** — AI bukan setakat bantu kita, tapi boleh jadi senjata kalau jatuh kat tangan yang salah.

✅ **Sam Altman & Dario Amodei: Slow Down AI** [TechCrunch] — CEO OpenAI & Anthropic rasa dah tiba masa untuk "perlahankan" pembangunan AI supaya tak hilang kawalan.💡 **Kenapa Penting** — *Big players* pun dah mula risau pasal *safety* dan *pace* pembangunan AI.

✅ **Teknologi AI Lain** [MarkTechPost/HuggingFace] — Ada model baru SWE-2 (Cognition) yang murah tapi power, dan eksperimen pelik masukkan *connectome* lalat buah dalam LLM.💡 **Kenapa Penting** — *Cost* untuk coding AI makin turun, tapi eksperimen AI makin pelik-pelik.

# 📱 Tech & Lokal

✅ **Netflix Naik Harga Lagi!** [Amanz/Aksiz] — Harga langganan kat Malaysia naik, sekarang bermula RM19.90 sampai RM69.90.💡 **Kenapa Penting** — Dompet Master mungkin terasa sikit bulan ni.

✅ **Apple iOS 27: iPhone Handoff eSIM** [Amanz] — Ciri baru benarkan dua iPhone kongsi satu eSIM, tapi kena bayar yuran bulanan.💡 **Kenapa Penting** — Senang kalau Master nak pakai dua phone tapi malas nak urus dua simcard.

✅ **Tesla Roadster Gen 2** [TechCrunch] — Akhirnya Tesla nak *unveil* kereta ni 1 Oktober nanti selepas bertahun-tahun janji.💡 **Kenapa Penting** — Penantian sejak 2017 akhirnya berakhir.

🔥 Top Picks

**Check Point & GitLab Patch** — Wajib buat sekarang sebelum kena *attack*.

**OpenAI Agents Attack** — Menarik nak tengok macam mana AI boleh jadi "hacker" secara automatik.

**Netflix Price Hike** — Berita paling "sakit" untuk pengguna Malaysia.

> ls -la berita/

🛡️ Cybersecurity

27
🛡️ Cybersecurity

GitLab urges users to patch max severity path traversal flaw

GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. [...]

$> BleepingComputer⏱️ 1m
→
🛡️ Cybersecurity

Indonesia Hit by Android Banking App-Cloning Campaign

The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.

$> Dark Reading⏱️ 1m
→
🛡️ Cybersecurity

IXON VPN Client

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges. The following versions of IXON VPN Client are affected: VPN Client C

$> CISA⏱️ 1m
→
🛡️ Cybersecurity

Trezor: 347,000 users targeted in phishing attacks after Brevo breach

Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. [...]

$> BleepingComputer⏱️ 1m
→
🛡️ Cybersecurity

Check Point Patches Critical VPN Vulnerabilities

Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. The post Check Point Patches Critical VPN Vulnerabilities appeared first on SecurityWeek.

$> SecurityWeek⏱️ 1m
→
🛡️ Cybersecurity

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. [...]

$> BleepingComputer⏱️ 1m
→
🛡️ Cybersecurity

Conti ransomware gang member sentenced to 4 years in prison

A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. [...]

$> BleepingComputer⏱️ 1m
→
🛡️ Cybersecurity

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in research published Thur

$> Hacker News⏱️ 1m
→
🛡️ Cybersecurity

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of ac

$> Hacker News⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-90556 - Freeciv before 3.2.6 Heap Buffer Overflow via worklist_load

CVE ID :CVE-2026-90556 Published : Sept. 12, 2026, 6:16 p.m. | 5 hours, 36 minutes ago Description :Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceedin

$> CVE Critical⏱️ 1m
→
🛡️ Cybersecurity

Patch Tuesday Sets Another Record With 974 CVEs

Attackers are actively exploiting two of the vulnerabilities, and another 58 are more likely to be exploited, according to Microsoft.

$> Dark Reading⏱️ 1m
→
🛡️ Cybersecurity

Rockwell Automation ArmorStart LT

View CSAF Summary Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other users access the affected page. The following versio

$> CISA⏱️ 1m
→
🛡️ Cybersecurity

Identity-Based AI Attack Threatens Security of Enterprise Data

"Workflow identity hijacking" can bypass standard security controls and hijack an organization's data by sending a basic request through an unauthenticated entry point.

$> Dark Reading⏱️ 1m
→
🛡️ Cybersecurity

Inductive Automation Ignition

View CSAF Summary Successful exploitation of this vulnerability could allow any authenticated user to create projects. The following versions of Inductive Automation Ignition are affected: Ignition CVSS Vendor Equipment Vulnerabilities v3 8.8 Inducti

$> CISA⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-79300 - SEP sesam Improper Authorization and MFA Bypass Vulnerability

CVE ID :CVE-2026-79300 Published : Sept. 12, 2026, 11:17 p.m. | 38 minutes ago Description :SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced, an attacker can create a second OTP

$> CVE Feed⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-90487 - Xuxueli xxl-job JobGroupController.java privileges management

CVE ID :CVE-2026-90487 Published : Sept. 12, 2026, 11:17 p.m. | 38 minutes ago Description :A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Affected by this issue is some unknown functionality of the file xxl-job-admin/src/main/java/com/xxl

$> CVE Feed⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-90486 - openstatusHQ openstatus resolve-custom-domain-rewrite.ts server-side request forgery

CVE ID :CVE-2026-90486 Published : Sept. 12, 2026, 11:17 p.m. | 38 minutes ago Description :A vulnerability has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265. Affected by this vulnerability is an unknown functio

$> CVE Feed⏱️ 1m
→
🛡️ Cybersecurity

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments. The post BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days appeared first on SecurityWeek.

$> SecurityWeek⏱️ 1m
→
🛡️ Cybersecurity

OPCFoundation OPC UA LocalDiscoveryServer (LDS)

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. The following versions of OPCFoundation OPC UA LocalDiscoveryServer (

$> CISA⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-90558 - sngrep through 1.8.4 Stack Buffer Overflow via SIP Headers

CVE ID :CVE-2026-90558 Published : Sept. 12, 2026, 6:16 p.m. | 5 hours, 36 minutes ago Description :sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer

$> CVE Critical⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-90647 - Kalkitech ASE2000 Improper Certificate Validation Vulnerability

CVE ID :CVE-2026-90647 Published : Sept. 12, 2026, 11:17 p.m. | 38 minutes ago Description :ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104

$> CVE Feed⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-90559 - snappy-java through 1.1.10.8 Out-of-Bounds Write via uncompress

CVE ID :CVE-2026-90559 Published : Sept. 12, 2026, 6:16 p.m. | 5 hours, 36 minutes ago Description :snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer cap

$> CVE Critical⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-90648 - Wabt wasm2c Sandbox Escape Vulnerability

CVE ID :CVE-2026-90648 Published : Sept. 12, 2026, 11:16 p.m. | 39 minutes ago Description :wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, aka a "table flip" attack. It does

$> CVE Feed⏱️ 1m
→
🛡️ Cybersecurity

Surfshark Systems Targeted by Hackers

A misconfigured test server containing engineering material, including internal configurations, was accessed by threat actors. The post Surfshark Systems Targeted by Hackers appeared first on SecurityWeek.

$> SecurityWeek⏱️ 1m
→
🛡️ Cybersecurity

Revolut confirms customer data breach through fake government requests

Revolut said it notified affected customers and alerted the relevant government agency, law enforcement, and financial regulators.

$> TechCrunch⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-90553 - vLLM before 0.28.0 Remote Code Execution via LlavaOnevision2 processor

CVE ID :CVE-2026-90553 Published : Sept. 12, 2026, 1:16 p.m. | 10 hours, 36 minutes ago Description :vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code paramete

$> CVE Critical⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-90560 - zstd-jni 1.2.0 through 1.5.7-13 Out-of-Bounds Read via ZstdDictDecompress

CVE ID :CVE-2026-90560 Published : Sept. 12, 2026, 6:16 p.m. | 5 hours, 36 minutes ago Description :zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length a

$> CVE Critical⏱️ 1m
→

🧠 AI/ML

26
🧠 AI/ML

OpenAI named a Leader in enterprise coding agents by Gartner

OpenAI is named a leader in the 2026 Gartner Magic Quadrant for Enterprise AI Coding Agents, with Codex recognized for innovation and enterprise-scale deployment.

$> OpenAI⏱️ 1m
→
🧠 AI/ML

Netflix Naik Harga Lagi – Kini Bermula RM19.90 Hingga RM69.90

Selepas kali terakhir meningkatkan harga untuk langganan pada tahun 2024, Netflix telah mengemaskini harga langganan baharu mereka dan kini bermula RM19.90 untuk pelan paling murah dan RM69.90 untuk pelan paling... The post Netflix Naik Harga Lagi –

$> Aksiz⏱️ 1m
→
🧠 AI/ML

Siri Oppo A7 Pro – Tampil Dengan Rekaan Lebih Segar Dengan Kamera Swatofo Terbaru

Oppo kini kembali dengan model terbaru iaitu siri A7 Pro yang akan datang ke pasaran Malaysia dalam masa terdekat ini. Seperti biasa, peranti-peranti dari Oppo semestinya akan hadir dengan rekaan yang terbaru dan menarik. Kali ini Oppo akan bawakan d

$> Amanz⏱️ 1m
→
🧠 AI/ML

Profil YouTube Di Aplikasi TV Kini Boleh Dikunci Dengan Nombor Pin

Di rumah, saya mengarahkan anak hanya menggunakan aplikasi YouTube di TV pintar menggunakan profil peribadi. Profil ini telah ditapis supaya hanya memaparkan kandungan yang sesuai dengan usia beliau. Anak saya berdisiplin maka akaun saya tidak diguna

$> Amanz⏱️ 1m
→
🧠 AI/ML

The TechBeat: AI Coding Tip 035 - Split Every Skill Description Into Three Sentences (9/12/2026)

9/12/2026: Trending stories on Hackernoon today!

$> Hacker Noon⏱️ 1m
→
🧠 AI/ML

Google Cloud C4 Brings a 70% TCO improvement on GPT OSS with Intel and Hugging Face

$> HuggingFace⏱️ 1m
→
🧠 AI/ML

OpenAI’s Sam Altman says it would be ‘ill-advised’ to go public in 2026

While OpenAI has filed confidentially for an IPO, the company will not be going public this year, according to CEO Sam Altman.

$> TechCrunch⏱️ 1m
→
🧠 AI/ML

Fly Language Model (FLM) Wires the Full Fruit Fly Connectome Into a Frozen 1.2B LLM, and Its Own Controls Show the Wiring Does Not Help

The Fly Language Model (FLM) drives all 166,700 retained neurons and 25.6 million edges of the MaleCNS fruit fly connectome with token embeddings, then adds a small learned correction to a frozen LFM2.5-1.2B-Instruct backbone. Only 278,528 parameters

$> MarkTechPost⏱️ 1m
→
🧠 AI/ML

Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)

View CSAF Summary Schneider Electric is aware of a vulnerability in the following products: The Easergy C5 is a scalable and interoperable bay controller, protection and merging unit for large and critical infrastructure electrical distribution syste

$> CISA⏱️ 1m
→
🧠 AI/ML

Texas’ AI Data Center Boom Is Becoming a Fight Over Water

Texas’ AI data center boom is colliding with water scarcity, local zoning disputes and questions over who has the authority to stop new projects.

$> Hacker Noon⏱️ 1m
→
🧠 AI/ML

Nemotron-Personas-India: Synthesized Data for Sovereign AI

$> HuggingFace⏱️ 1m
→
🧠 AI/ML

OpenAI, Grupo Folha and Grupo UOL announce strategic content partnership

OpenAI partners with Grupo Folha and Grupo UOL to bring trusted Brazilian journalism to ChatGPT, expanding access to news with attribution and transparency.

$> OpenAI⏱️ 1m
→
🧠 AI/ML

AI is becoming a first hire for small businesses

New research shows how 4 million Americans use ChatGPT to start, run, and grow small businesses, lowering the cost of entrepreneurship with AI.

$> OpenAI⏱️ 1m
→
🧠 AI/ML

When the Whole Company Adopts AI: What It Does to Your SOC

Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but the ordinary, everyd

$> Hacker News⏱️ 1m
→
🧠 AI/ML

Automattic confirms Mullenweg has returned as CEO after attempted ouster by board

Automattic says Mullenweg is back as "chairman and CEO of Automattic, with full support of the board."

$> TechCrunch⏱️ 1m
→
🧠 AI/ML

Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance

Financials have not been disclosed, but the estimated cost is in the tens of millions of dollars. The post Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance appeared first on SecurityWeek.

$> SecurityWeek⏱️ 1m
→
🧠 AI/ML

Cognition Releases SWE-2: A Kimi K3 Post-Trained Coding Model That Matches Fable 5.1 on FrontierCode at 64% Lower Cost

Cognition, the company behind the Devin coding agent, has released SWE-2, its most capable coding model to date. SWE-2 is post-trained with reinforcement learning from Kimi K3, Moonshot AI’s 2.8T-parameter open model. Cognition reports a score of 50.

$> MarkTechPost⏱️ 1m
→
🧠 AI/ML

Anthropic CEO outlines plan to slow AI development

Anthropic's Dario Amodei and OpenAI's Sam Altman seem to agree that it's time to "pace the frontier." What would that actually look like?

$> TechCrunch⏱️ 1m
→
🧠 AI/ML

OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product

$> Hacker News⏱️ 1m
→
🧠 AI/ML

Why SPIFFE Agent Identities Can Still Be Replayed, and How WIMSE Fixes It

SPIFFE identity tokens for AI agents can still be replayed if intercepted. The IETF WIMSE group built the fix, and SPIFFE just adopted it.

$> Hacker Noon⏱️ 1m
→
🧠 AI/ML

Warp’s big bet on building open source with GPT-5.5

Warp uses GPT-5.5 and OpenAI models to coordinate coding agents across local, cloud, and open-source development workflows.

$> OpenAI⏱️ 1m
→
🧠 AI/ML

OpenAI Agents Took Over Wiki Site Before Hugging Face Attack

Researchers and OpenAI disagree on whether an earlier incident involving DseWiki, which the company did not disclose, was a “hack."

$> Dark Reading⏱️ 1m
→
🧠 AI/ML

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report. Wiz saw the attacks

$> Hacker News⏱️ 1m
→
🧠 AI/ML

A Framework for Conversational System Modeling

Continuation, turn change, backchannel, interruption, silence: five events a model predicts from 30 seconds of dual-channel audio.

$> Hacker Noon⏱️ 1m
→
🧠 AI/ML

BYD ATTO 3 Performance 2026 Dilancarkan Dengan Harga RM149,800 – Terhad 69 Unit Sahaja

BYD Sime Motors hari ini melancarkan edisi terhad BYD ATTO 3 Performance 2026 sempena sambutan Merdeka ke-69. Model ini tampil sebagai varian paling berkuasa dalam siri ATTO 3 dengan gabungan output sistem mencecah 330 kW dan 560 Nm tork sekali gus m

$> Amanz⏱️ 1m
→
🧠 AI/ML

Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says

Anthropic said the users did not succeed in “fielding an operational device” but did carry out a failed test of a guided rocket. The post Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says appeared first on SecurityW

$> SecurityWeek⏱️ 1m
→

📌 Lain-lain

4

🇲🇾 Malaysia/Lokal

1

⚡ Tech/Dev

5