⏐ Taklimat Pagi
Taklimat Pagi Saya
🔗 baca_penuh: pagi.hejes.my/2026/09/14
> ringkasan_ai
# 🤖 AI & Machine Learning
✅ **Amaran CEO Anthropic & Obama** [SecurityWeek/Amanz/TechCrunch] — Dario Amodei (Anthropic) dan Obama gesa pembangunan AI diperlahankan sebab risau pasal keselamatan, risiko senjata biologi, dan ejen AI yang boleh "take over" internet dalam masa 6-12 bulan.💡 **Kenapa Penting** — Master kena alert sebab *safety measures* sekarang tak sempat nak kejar kepantasan AI.
✅ **OpenAI Pecah Rekod Matematik & Ekspansi** [OpenAI] — Model OpenAI berjaya selesaikan masalah geometri diskret yang dah 80 tahun tak terjawab, sambil lancarkan kerjasama AI di Singapura dan sektor pendidikan global.💡 **Kenapa Penting** — AI bukan setakat buat puisi, tapi dah mula buat penemuan saintifik tahap tinggi.
✅ **Teknikal AI: RLT, NeRF & Context Engineering** [MarkTechPost] — Ada proposal baru pasal *Recurrent Looped Transformer* (RLT) untuk fix isu memori, tutorial Hierarchical NeRF untuk 3D, dan cara atasi *context overflow* dalam tugasan panjang.💡 **Kenapa Penting** — Ini *update* teknikal kalau Master nak optimize performance model AI Master.
✅ **Gadget AI: Oppo A7 Pro & Samsung S26 FE** [Amanz] — Oppo A7 Pro series nak masuk Malaysia, manakala S26 FE hadir dengan isu harga naik sebab krisis RAM.💡 **Kenapa Penting** — Info kalau Master plan nak upgrade phone baru.
# 🛡️ Cybersecurity (Kritikal!)
✅ **Serangan Malware & Ransomware** [BleepingComputer/Hacker News] — Kumpulan espionage China guna flaw Tencent untuk deploy *GrayRabbit*, dan Cisco FMC kena exploit untuk sebarkan *Qilin Ransomware*.💡 **Kenapa Penting** — Menunjukkan *state-sponsored attacks* makin agresif guna *zero-day*.
✅ **Amaran CISA & Era Post-Quantum** [CISA] — CISA gesa semua organisasi tukar ke *Post-Quantum Cryptography* (PQC) segera sebelum komputer kuantum boleh pecahkan encryption sekarang.💡 **Kenapa Penting** — Ini *long-term survival* untuk data rahsia Master.
✅ **Lambakan CVE Baru (WordPress & Others)** [CVE Feed/Critical] — Banyak vulnerability baru dikesan termasuk SQL Injection (itsourcecode), XSS (YouTube Embed, Hoo Companion), dan Sandbox Bypass (CrewAI).💡 **Kenapa Penting** — Kalau Master ada guna plugin-plugin ni, tolong *update* sekarang sebelum kena hack.
✅ **Phishing Passkey & LiteLLM** [Hacker News] — Ada campaign phishing guna tema "Passkey" untuk hijack akaun Microsoft, dan banyak server LiteLLM masih guna admin key contoh "sk-1234".💡 **Kenapa Penting** — Peringatan supaya jangan malas tukar *default password/key*.
# 💻 Tech & Dev
✅ **AWS Pizza Bot** [MarkTechPost] — AWS perkenalkan *Pizza Bot*, satu open-source inbox untuk urus AI agents guna LangGraph.💡 **Kenapa Penting** — Memudahkan Master monitor apa yang AI agents Master buat kat background.
✅ **WhatsApp "Event Hub"** [Amanz] — WhatsApp tengah test feature baru untuk urus event dalam satu page khas, bukan sekadar dalam group.💡 **Kenapa Penting** — Senang sikit Master nak organize meeting dengan Kazekage lain.
✅ **Disney+ Malaysia Update** [Amanz] — Pengalaman baru bermula 7 Oktober, tapi sejarah tontonan Master akan hilang.💡 **Kenapa Penting** — Jangan terkejut kalau *watchlist* Master kosong nanti.
🔥 Top Picks
**Amaran CEO Anthropic** — Serius weh, 6-12 bulan je lagi sebelum AI mungkin boleh kawal internet.
**Post-Quantum Cryptography (CISA)** — Masa untuk fikir pasal security masa depan.
**OpenAI's Geometry Breakthrough** — AI dah mula "berfikir" macam ahli matematik pro.
> ls -la berita/
🛡️ Cybersecurity
21CVE-2026-90600 - itsourcecode Sales and Inventory System inv_edit1.php sql injection
CVE ID :CVE-2026-90600 Published : Sept. 13, 2026, 11:16 p.m. | 43 minutes ago Description :A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit1.php. The manipula
Preparing for the Post-Quantum Era: A Call to Action
CISA and the Group of Seven (G7) Cyber Security Working Group released Preparing for the Post-Quantum Era: A Call to Action highlighting the urgent need for organizations and governments to begin transitioning to post-quantum cryptography (PQC) to pr
Hackers exploit Tencent app flaw to deploy GrayRabbit malware
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. [...]
The U.S. Space Academy Is More of a Workforce Bet Than an Astronaut School
The proposed U.S. Space Academy is a workforce experiment for scaling launch operations, lunar logistics and a growing commercial space economy.
Tycon Systems TPDIN-Monitor-WEB2 (Update A)
View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. The f
Rockwell Automation 1756-ENBT Module
View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-2025-10478
CVE-2026-81648 - CryptoPayment Gateway 1.2.1 - 1.2.2 - Unauthenticated Arbitrary File Deletion and Settings Update via Unguarded AJAX Router
CVE ID :CVE-2026-81648 Published : Sept. 13, 2026, 9:17 p.m. | 2 hours, 42 minutes ago Description :The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenti
CVE-2026-88793 - YouTube Embed 10.0 - 10.3 - Unauthenticated Stored XSS via youram_server
CVE ID :CVE-2026-88793 Published : Sept. 13, 2026, 9:17 p.m. | 2 hours, 42 minutes ago Description :The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it p
ClickFix Campaigns Abuse Legitimate Services for Persistent Access
Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.
CVE-2026-90602 - Anil-matcha Open-Generative-AI Studio Components ImageStudio.js renderHistory cross site scripting
CVE ID :CVE-2026-90602 Published : Sept. 13, 2026, 11:16 p.m. | 43 minutes ago Description :A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the function renderHistory of the file
CVE-2026-37008 - CrewAI Sandbox Bypass via Python Runtime Manipulation
CVE ID :CVE-2026-37008 Published : Sept. 13, 2026, 9:17 p.m. | 2 hours, 42 minutes ago Description :CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275
CVE-2026-90601 - getzep graphiti REST API main.py improper authentication
CVE ID :CVE-2026-90601 Published : Sept. 13, 2026, 11:16 p.m. | 43 minutes ago Description :A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API.
Rockwell Automation ControlFLASH
View CSAF Summary Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level. The following versions of Rockwell A
CVE-2026-90605 - Totolink A3002MU boa formFilter buffer overflow
CVE ID :CVE-2026-90605 Published : Sept. 13, 2026, 11:30 p.m. | 29 minutes ago Description :A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the
CVE-2026-85129 - Hoo Companion 1.0.2 - Unauthenticated Stored XSS via Theme Settings Import
CVE ID :CVE-2026-85129 Published : Sept. 13, 2026, 9:17 p.m. | 2 hours, 42 minutes ago Description :The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the
CVE-2026-90603 - Anil-matcha Open-Generative-AI S3 Upload upload-binary unrestricted upload
CVE ID :CVE-2026-90603 Published : Sept. 13, 2026, 11:16 p.m. | 43 minutes ago Description :A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upl
Pyramid Solutions NetStaX EtherNet/IP Stack
View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be proce
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agen
Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites
A Chinese-language group is compromising government and education sites to create a reverse-proxy network with gambling-themed sites.
CVE-2026-74933 - GenieWords 1.5.27 - 1.5.34 - Unauthenticated Stored XSS and Configuration Overwrite
CVE ID :CVE-2026-74933 Published : Sept. 13, 2026, 9:17 p.m. | 2 hours, 42 minutes ago Description :The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored
🧠 AI/ML
26Hierarchical NeRF with JAX3D for Volumetric Rendering, Novel-View Synthesis, and 3D Reconstruction
In this tutorial, we build an end-to-end hierarchical Neural Radiance Field (NeRF) using JAX, Flax, Optax, and the volume-rendering primitives provided by jax3d. We first construct a synthetic multi-view dataset from an analytic scene containing volu
Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up
Dario Amodei warned that within six to 12 months AI could be capable of leading a swarm of agents that could take over the entire internet. The post Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up appeared f
CEO Anthropic Gesa Pembangunan AI Diperlahankan – Disokong Altman dan Musk
CEO Antropic, Dario Amodei menggesa pembangunan kecerdasan buatan (AI) diperlahankan dan dipantau kerana isu Ini termasuk risiko kehilangan kawalan sistem AI, penyalahgunaan AI untuk serangan siber dan senjata biologi, dan gangguan ke atas ekonomi ya
How I Use Claude and ChatGPT to Make Better AI Images
A practical workflow for using Claude to plan better image prompts, then generating and refining the final image in ChatGPT.
Oppo A7 Pro Dan Oppo A7 Pro Max Bakal Tiba Di Malaysia Tidak Lama Lagi
Oppo mengesahkan bahawa model terbaharu mereka Oppo A7 Pro dan Oppo A7 Pro Max bakal memasuki pasaran Malaysia dalam masa terdekat. Kehadiran kedua-dua model ini menandakan kemunculan generasi baharu telefon Oppo yang dijangka meneruskan tradisi reka
Introducing OpenAI for Singapore
OpenAI for Singapore launches a multi-year AI partnership to expand deployment, build local talent, and support businesses and public services with AI.
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first c
Accelerating Qwen3-8B Agent on Intel® Core™ Ultra with Depth-Pruned Draft Models
Obama urges Democrats to have a ‘clear plan’ for AI safeguards
Obama recently said that Democrats need to make artificial intelligence one of their “central agendas” and “have a very clear plan” to address concerns around the technology’s economic impact and safety.
An OpenAI model has disproved a central conjecture in discrete geometry
An OpenAI model solved the 80-year-old unit distance problem, disproving a major conjecture in discrete geometry and marking a milestone in AI-driven mathematics.
AdventHealth advances whole-person care with OpenAI
AdventHealth is using ChatGPT for Healthcare to streamline workflows, reduce administrative burden, and return more time to patient care.
PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws
PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said P
AI Can Write a Perfectly Reasonable Scientific Sentence, and That’s the Problem
A small AI-generated scientific sentence shows how fluent academic writing can quietly add unsupported mechanistic claims.
Week 5 of Building Pocketflow for Shipaton 2026: Paywalls, Timeline Audits, and Launch!
Pocketflow’s final Shipaton week covered UI polish, RevenueCat paywalls, AI credit pricing, balance syncing, and its iOS and Android launch.
Insight Partners’ Deven Parekh on why the firm is diversifying while everyone else bets the farm on OpenAI and Anthropic
Insight Partners' Devin Parekh opens up about losing Legora to General Catalyst, why he's fine holding stakes in rival AI labs, and why — even as everyone else piles into OpenAI and Anthropic — his $90 billion firm is deliberately staying diversified
Ulasan Samsung Galaxy S26 FE – Sama Tapi Tak Serupa
Penjimatan dan mampu milik adalah dua terma yang diancam kepupusan disebabkan oleh krisis RAM. Secara purata harga telefon pintar di Malaysia meningkat sekitar RM600 berbanding model tahun lalu dengan konfigurasi storan yang sama. Siri Galaxy FE berm
What’s behind the AI industry’s latest warnings of doom?
On Equity, we discussed the AI industry's latest debate about whether it poses an existential threat to humanity.
Implementation of Machine Learning Workflows with NVIDIA cuML, RAPIDS, GPU Benchmarking, Explainability, Clustering, and Model Inference
This practical tutorial demonstrates how to build and accelerate machine learning workflows using NVIDIA cuML and RAPIDS. It covers GPU environment setup, zero-code scikit-learn acceleration with cuml.accel, performance benchmarking across key ML alg
AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?
A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks.
The next phase of OpenAI’s Education for Countries
OpenAI advances Education for Countries, expanding AI adoption in schools with new partnerships, teacher training, and tools to improve global learning outcomes.
Building Isolyne (Part 5): How the Offline Fallback Parser Handles LLM Outages
How Isolyne falls back from Gemini to a local TypeScript parser when connectivity fails, preserving core decision capture and drift detection.
Nemotron-Personas-Japan: ソブリン AI のための合成データセット
Companies Have 6 Months to Prepare for Automated Attacks
Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, but researchers warn the situation will become more urgent very soon.
Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key
Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway, the software a company puts between its applica
Insurers Search for Answers to Rein in Rogue AI
As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout.
Context Engineering Inside the Harness: 4 Mechanisms That Beat Context Overflow and Goal Loss on Long-Horizon Tasks
A shallow agent is an LLM calling tools in a loop, and on long tasks it fails in 2 ways: context overflow and goal loss. This article opens the harness layer that fixes both, with the actual thresholds shipped by LangChain Deep Agents, Claude Code, M
⚡ Tech/Dev
5AWS Introduces Pizza Bot: An Open Source Inbox for Background AI Agents
Pizza Bot is an open source, self-hosted inbox for AI agents built on DeepAgents and LangGraph. It combines persistent task state, MCP integrations, configurable approvals, and scheduled workflows across multiple model providers. The post AWS Introdu
A Princeton Researcher Proposes Recurrent Looped Transformer (RLT) that Carries Decoder State across Every Token, Fixing 96 Blocks per Token with Unbounded Temporal Depth
Yifan Zhang's Recurrent Looped Transformer (RLT) technical report proposes a causal encoder paired with a recurrent decoder that carries its final hidden state and layerwise sliding-window attention cache across every prompt and response token, with
WhatsApp Menguji Ciri “Event Hub” Bagi Memudahkan Pengurusan Acara
WhatsApp kini sedang menguji ciri baharu bernama Events Hub. Ia muncul sebagai halaman khas dalam aplikasi untuk memudahkan pengguna mencipta, mengurus dan menyemak acara. Sebelum ini, acara hanya boleh dibuat dalam kumpulan atau komuniti, tetapi kin
How Ramp engineers accelerate code review with Codex
How Ramp engineers use Codex with GPT-5.5 to review code and ship improvements, allowing them to get substantive feedback in minutes instead of hours.
The 9 buzziest startups from Y Combinator’s latest Demo Day, according to VCs
From floating reactors to brain chips: VCs picked their favorite YC startups from the summer batch.
📌 Lain-lain
4SOTA OCR with Core ML and dots.ocr
Introducing RTEB: A New Standard for Retrieval Evaluation
VibeGame: Exploring Vibe Coding Games
Larry Ellison cancels $7.5 billion sale of Oracle stock
Oracle had previously disclosed that Ellison planned to sell 50 million shares worth around $7.5 billion.