⏐ Taklimat Pagi
Taklimat Pagi Saya
🔗 baca_penuh: pagi.hejes.my/2026/09/13
> ringkasan_ai
# 🛡️ Cybersecurity (Amaran Merah!)
✅ **Patch Segera: GitLab, Check Point VPN & IXON** [BleepingComputer/CISA] — Ada *critical flaws* (path traversal & RCE) yang boleh bagi *attacker* kawal server atau komputer Master.💡 **Kenapa Penting** — Kalau tak *patch* sekarang, memang jem lah server kita nanti.
✅ **Serangan Phishing: Trezor & Revolut** [BleepingComputer/TechCrunch] — Trezor kena target 347k user, Revolut pula bocor data sebab *fake government requests*.💡 **Kenapa Penting** — Peringatan untuk kita jangan senang-senang klik link pelik, walaupun nampak macam rasmi.
✅ **Ancaman Baru: Android Banking App-Cloning & BlueMoon** [Dark Reading/SecurityWeek] — Geng GoldFactory tengah *clone* app bank kat Indonesia, manakala BlueMoon guna *zero-day* Chrome/Windows untuk intipan.💡 **Kenapa Penting** — *Attackers* makin kreatif guna *work profile* Android untuk sorok Trojan.
✅ **Microsoft Patch Tuesday Rekod Baru** [Dark Reading] — Microsoft keluarkan 974 CVE, ada yang dah kena *exploit* secara aktif.💡 **Kenapa Penting** — Update Windows Master cepat-cepat sebelum kena *hack*.
✅ **Lain-lain Security (CISA/CVE)** [CISA/CVE Feed] — Ada isu *buffer overflow* kat Freeciv & sngrep, serta *sandbox escape* kat wabt.💡 **Kenapa Penting** — Banyak *library* teknikal yang ada lubang, kena hati-hati masa *deploy*.
# 🤖 AI & Machine Learning
✅ **OpenAI: Leader Coding Agents & Partnership Baru** [OpenAI] — Gartner namakan OpenAI sebagai leader untuk *enterprise coding agents*, dan dorang baru partner dengan media Brazil (Folha/UOL).💡 **Kenapa Penting** — Tool coding AI makin power, mungkin boleh bantu Master buat kerja lagi cepat.
✅ **Kontroversi OpenAI Agents** [Hacker News/Dark Reading] — Ada report kata *swarm* OpenAI agents terlibat dalam serangan RubyGems dan ambil alih site Wiki.💡 **Kenapa Penting** — AI bukan setakat bantu kita, tapi boleh jadi senjata kalau jatuh kat tangan yang salah.
✅ **Sam Altman & Dario Amodei: Slow Down AI** [TechCrunch] — CEO OpenAI & Anthropic rasa dah tiba masa untuk "perlahankan" pembangunan AI supaya tak hilang kawalan.💡 **Kenapa Penting** — *Big players* pun dah mula risau pasal *safety* dan *pace* pembangunan AI.
✅ **Teknologi AI Lain** [MarkTechPost/HuggingFace] — Ada model baru SWE-2 (Cognition) yang murah tapi power, dan eksperimen pelik masukkan *connectome* lalat buah dalam LLM.💡 **Kenapa Penting** — *Cost* untuk coding AI makin turun, tapi eksperimen AI makin pelik-pelik.
# 📱 Tech & Lokal
✅ **Netflix Naik Harga Lagi!** [Amanz/Aksiz] — Harga langganan kat Malaysia naik, sekarang bermula RM19.90 sampai RM69.90.💡 **Kenapa Penting** — Dompet Master mungkin terasa sikit bulan ni.
✅ **Apple iOS 27: iPhone Handoff eSIM** [Amanz] — Ciri baru benarkan dua iPhone kongsi satu eSIM, tapi kena bayar yuran bulanan.💡 **Kenapa Penting** — Senang kalau Master nak pakai dua phone tapi malas nak urus dua simcard.
✅ **Tesla Roadster Gen 2** [TechCrunch] — Akhirnya Tesla nak *unveil* kereta ni 1 Oktober nanti selepas bertahun-tahun janji.💡 **Kenapa Penting** — Penantian sejak 2017 akhirnya berakhir.
🔥 Top Picks
**Check Point & GitLab Patch** — Wajib buat sekarang sebelum kena *attack*.
**OpenAI Agents Attack** — Menarik nak tengok macam mana AI boleh jadi "hacker" secara automatik.
**Netflix Price Hike** — Berita paling "sakit" untuk pengguna Malaysia.
> ls -la berita/
🛡️ Cybersecurity
27GitLab urges users to patch max severity path traversal flaw
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. [...]
Indonesia Hit by Android Banking App-Cloning Campaign
The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.
IXON VPN Client
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges. The following versions of IXON VPN Client are affected: VPN Client C
Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. [...]
Check Point Patches Critical VPN Vulnerabilities
Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. The post Check Point Patches Critical VPN Vulnerabilities appeared first on SecurityWeek.
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. [...]
Conti ransomware gang member sentenced to 4 years in prison
A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. [...]
China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in research published Thur
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of ac
CVE-2026-90556 - Freeciv before 3.2.6 Heap Buffer Overflow via worklist_load
CVE ID :CVE-2026-90556 Published : Sept. 12, 2026, 6:16 p.m. | 5 hours, 36 minutes ago Description :Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceedin
Patch Tuesday Sets Another Record With 974 CVEs
Attackers are actively exploiting two of the vulnerabilities, and another 58 are more likely to be exploited, according to Microsoft.
Rockwell Automation ArmorStart LT
View CSAF Summary Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other users access the affected page. The following versio
Identity-Based AI Attack Threatens Security of Enterprise Data
"Workflow identity hijacking" can bypass standard security controls and hijack an organization's data by sending a basic request through an unauthenticated entry point.
Inductive Automation Ignition
View CSAF Summary Successful exploitation of this vulnerability could allow any authenticated user to create projects. The following versions of Inductive Automation Ignition are affected: Ignition CVSS Vendor Equipment Vulnerabilities v3 8.8 Inducti
CVE-2026-79300 - SEP sesam Improper Authorization and MFA Bypass Vulnerability
CVE ID :CVE-2026-79300 Published : Sept. 12, 2026, 11:17 p.m. | 38 minutes ago Description :SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced, an attacker can create a second OTP
CVE-2026-90487 - Xuxueli xxl-job JobGroupController.java privileges management
CVE ID :CVE-2026-90487 Published : Sept. 12, 2026, 11:17 p.m. | 38 minutes ago Description :A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Affected by this issue is some unknown functionality of the file xxl-job-admin/src/main/java/com/xxl
CVE-2026-90486 - openstatusHQ openstatus resolve-custom-domain-rewrite.ts server-side request forgery
CVE ID :CVE-2026-90486 Published : Sept. 12, 2026, 11:17 p.m. | 38 minutes ago Description :A vulnerability has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265. Affected by this vulnerability is an unknown functio
BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments. The post BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days appeared first on SecurityWeek.
OPCFoundation OPC UA LocalDiscoveryServer (LDS)
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. The following versions of OPCFoundation OPC UA LocalDiscoveryServer (
CVE-2026-90558 - sngrep through 1.8.4 Stack Buffer Overflow via SIP Headers
CVE ID :CVE-2026-90558 Published : Sept. 12, 2026, 6:16 p.m. | 5 hours, 36 minutes ago Description :sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer
CVE-2026-90647 - Kalkitech ASE2000 Improper Certificate Validation Vulnerability
CVE ID :CVE-2026-90647 Published : Sept. 12, 2026, 11:17 p.m. | 38 minutes ago Description :ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104
CVE-2026-90559 - snappy-java through 1.1.10.8 Out-of-Bounds Write via uncompress
CVE ID :CVE-2026-90559 Published : Sept. 12, 2026, 6:16 p.m. | 5 hours, 36 minutes ago Description :snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer cap
CVE-2026-90648 - Wabt wasm2c Sandbox Escape Vulnerability
CVE ID :CVE-2026-90648 Published : Sept. 12, 2026, 11:16 p.m. | 39 minutes ago Description :wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, aka a "table flip" attack. It does
Surfshark Systems Targeted by Hackers
A misconfigured test server containing engineering material, including internal configurations, was accessed by threat actors. The post Surfshark Systems Targeted by Hackers appeared first on SecurityWeek.
Revolut confirms customer data breach through fake government requests
Revolut said it notified affected customers and alerted the relevant government agency, law enforcement, and financial regulators.
CVE-2026-90553 - vLLM before 0.28.0 Remote Code Execution via LlavaOnevision2 processor
CVE ID :CVE-2026-90553 Published : Sept. 12, 2026, 1:16 p.m. | 10 hours, 36 minutes ago Description :vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code paramete
CVE-2026-90560 - zstd-jni 1.2.0 through 1.5.7-13 Out-of-Bounds Read via ZstdDictDecompress
CVE ID :CVE-2026-90560 Published : Sept. 12, 2026, 6:16 p.m. | 5 hours, 36 minutes ago Description :zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length a
🧠 AI/ML
26OpenAI named a Leader in enterprise coding agents by Gartner
OpenAI is named a leader in the 2026 Gartner Magic Quadrant for Enterprise AI Coding Agents, with Codex recognized for innovation and enterprise-scale deployment.
Netflix Naik Harga Lagi – Kini Bermula RM19.90 Hingga RM69.90
Selepas kali terakhir meningkatkan harga untuk langganan pada tahun 2024, Netflix telah mengemaskini harga langganan baharu mereka dan kini bermula RM19.90 untuk pelan paling murah dan RM69.90 untuk pelan paling... The post Netflix Naik Harga Lagi –
Siri Oppo A7 Pro – Tampil Dengan Rekaan Lebih Segar Dengan Kamera Swatofo Terbaru
Oppo kini kembali dengan model terbaru iaitu siri A7 Pro yang akan datang ke pasaran Malaysia dalam masa terdekat ini. Seperti biasa, peranti-peranti dari Oppo semestinya akan hadir dengan rekaan yang terbaru dan menarik. Kali ini Oppo akan bawakan d
Profil YouTube Di Aplikasi TV Kini Boleh Dikunci Dengan Nombor Pin
Di rumah, saya mengarahkan anak hanya menggunakan aplikasi YouTube di TV pintar menggunakan profil peribadi. Profil ini telah ditapis supaya hanya memaparkan kandungan yang sesuai dengan usia beliau. Anak saya berdisiplin maka akaun saya tidak diguna
The TechBeat: AI Coding Tip 035 - Split Every Skill Description Into Three Sentences (9/12/2026)
9/12/2026: Trending stories on Hackernoon today!
Google Cloud C4 Brings a 70% TCO improvement on GPT OSS with Intel and Hugging Face
OpenAI’s Sam Altman says it would be ‘ill-advised’ to go public in 2026
While OpenAI has filed confidentially for an IPO, the company will not be going public this year, according to CEO Sam Altman.
Fly Language Model (FLM) Wires the Full Fruit Fly Connectome Into a Frozen 1.2B LLM, and Its Own Controls Show the Wiring Does Not Help
The Fly Language Model (FLM) drives all 166,700 retained neurons and 25.6 million edges of the MaleCNS fruit fly connectome with token embeddings, then adds a small learned correction to a frozen LFM2.5-1.2B-Instruct backbone. Only 278,528 parameters
Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)
View CSAF Summary Schneider Electric is aware of a vulnerability in the following products: The Easergy C5 is a scalable and interoperable bay controller, protection and merging unit for large and critical infrastructure electrical distribution syste
Texas’ AI Data Center Boom Is Becoming a Fight Over Water
Texas’ AI data center boom is colliding with water scarcity, local zoning disputes and questions over who has the authority to stop new projects.
Nemotron-Personas-India: Synthesized Data for Sovereign AI
OpenAI, Grupo Folha and Grupo UOL announce strategic content partnership
OpenAI partners with Grupo Folha and Grupo UOL to bring trusted Brazilian journalism to ChatGPT, expanding access to news with attribution and transparency.
AI is becoming a first hire for small businesses
New research shows how 4 million Americans use ChatGPT to start, run, and grow small businesses, lowering the cost of entrepreneurship with AI.
When the Whole Company Adopts AI: What It Does to Your SOC
Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but the ordinary, everyd
Automattic confirms Mullenweg has returned as CEO after attempted ouster by board
Automattic says Mullenweg is back as "chairman and CEO of Automattic, with full support of the board."
Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance
Financials have not been disclosed, but the estimated cost is in the tens of millions of dollars. The post Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance appeared first on SecurityWeek.
Cognition Releases SWE-2: A Kimi K3 Post-Trained Coding Model That Matches Fable 5.1 on FrontierCode at 64% Lower Cost
Cognition, the company behind the Devin coding agent, has released SWE-2, its most capable coding model to date. SWE-2 is post-trained with reinforcement learning from Kimi K3, Moonshot AI’s 2.8T-parameter open model. Cognition reports a score of 50.
Anthropic CEO outlines plan to slow AI development
Anthropic's Dario Amodei and OpenAI's Sam Altman seem to agree that it's time to "pace the frontier." What would that actually look like?
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product
Why SPIFFE Agent Identities Can Still Be Replayed, and How WIMSE Fixes It
SPIFFE identity tokens for AI agents can still be replayed if intercepted. The IETF WIMSE group built the fix, and SPIFFE just adopted it.
Warp’s big bet on building open source with GPT-5.5
Warp uses GPT-5.5 and OpenAI models to coordinate coding agents across local, cloud, and open-source development workflows.
OpenAI Agents Took Over Wiki Site Before Hugging Face Attack
Researchers and OpenAI disagree on whether an earlier incident involving DseWiki, which the company did not disclose, was a “hack."
Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report. Wiz saw the attacks
A Framework for Conversational System Modeling
Continuation, turn change, backchannel, interruption, silence: five events a model predicts from 30 seconds of dual-channel audio.
BYD ATTO 3 Performance 2026 Dilancarkan Dengan Harga RM149,800 – Terhad 69 Unit Sahaja
BYD Sime Motors hari ini melancarkan edisi terhad BYD ATTO 3 Performance 2026 sempena sambutan Merdeka ke-69. Model ini tampil sebagai varian paling berkuasa dalam siri ATTO 3 dengan gabungan output sistem mencecah 330 kW dan 560 Nm tork sekali gus m
Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says
Anthropic said the users did not succeed in “fielding an operational device” but did carry out a failed test of a guided rocket. The post Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says appeared first on SecurityW
📌 Lain-lain
4Arm will be @ PyTorch Conference, Join Us!
A Look Inside My Career As A B2B Product Marketing Manager in IT (Part 1)
Today, I’m going to tell you all about my career path and share some of my tips — and anti-tips.
Get your VLM running in 3 simple steps on Intel CPUs
Tesla says it will finally unveil the second generation Roadster on October 1
Tesla’s halo sports car was first announced in November 2017.
🇲🇾 Malaysia/Lokal
1⚡ Tech/Dev
5BigCodeArena: Judging code generations end to end with code executions
Ciri iPhone Handoff Yang Berkongsi Satu SIM Pada Dua iPhone Memerlukan Yuran Bulanan
Menerusi iOS 27, ciri iPhone Handoff akan diberikan dengan ia membolehkan dua iPhone berkongsi satu eSIM yang sama, Dengan perkhidmatan selular, panggilan telefon dan rangkaian internet boleh digunakan pada dua telefon serentak. Ini amat berguna bagi
How Virgin Atlantic ships faster with Codex
How Virgin Atlantic used Codex to ship its revamped mobile app on a fixed holiday travel deadline, reaching near-total unit test coverage and zero P1 defects.
Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs
Microsoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released since the August 2026 Patch Tuesday. [...]
Attackers Use Multi-Hop Google Redirects for Phishing Campaign
Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.