⏐ Taklimat Pagi

Taklimat Pagi Saya

“Ilmu pagi, rezeki petang. Jangan skip.”
//57 cerita//~3 minit

🔗 baca_penuh: pagi.hejes.my/2026/09/14

> ringkasan_ai

# 🤖 AI & Machine Learning

✅ **Amaran CEO Anthropic & Obama** [SecurityWeek/Amanz/TechCrunch] — Dario Amodei (Anthropic) dan Obama gesa pembangunan AI diperlahankan sebab risau pasal keselamatan, risiko senjata biologi, dan ejen AI yang boleh "take over" internet dalam masa 6-12 bulan.💡 **Kenapa Penting** — Master kena alert sebab *safety measures* sekarang tak sempat nak kejar kepantasan AI.

✅ **OpenAI Pecah Rekod Matematik & Ekspansi** [OpenAI] — Model OpenAI berjaya selesaikan masalah geometri diskret yang dah 80 tahun tak terjawab, sambil lancarkan kerjasama AI di Singapura dan sektor pendidikan global.💡 **Kenapa Penting** — AI bukan setakat buat puisi, tapi dah mula buat penemuan saintifik tahap tinggi.

✅ **Teknikal AI: RLT, NeRF & Context Engineering** [MarkTechPost] — Ada proposal baru pasal *Recurrent Looped Transformer* (RLT) untuk fix isu memori, tutorial Hierarchical NeRF untuk 3D, dan cara atasi *context overflow* dalam tugasan panjang.💡 **Kenapa Penting** — Ini *update* teknikal kalau Master nak optimize performance model AI Master.

✅ **Gadget AI: Oppo A7 Pro & Samsung S26 FE** [Amanz] — Oppo A7 Pro series nak masuk Malaysia, manakala S26 FE hadir dengan isu harga naik sebab krisis RAM.💡 **Kenapa Penting** — Info kalau Master plan nak upgrade phone baru.

# 🛡️ Cybersecurity (Kritikal!)

✅ **Serangan Malware & Ransomware** [BleepingComputer/Hacker News] — Kumpulan espionage China guna flaw Tencent untuk deploy *GrayRabbit*, dan Cisco FMC kena exploit untuk sebarkan *Qilin Ransomware*.💡 **Kenapa Penting** — Menunjukkan *state-sponsored attacks* makin agresif guna *zero-day*.

✅ **Amaran CISA & Era Post-Quantum** [CISA] — CISA gesa semua organisasi tukar ke *Post-Quantum Cryptography* (PQC) segera sebelum komputer kuantum boleh pecahkan encryption sekarang.💡 **Kenapa Penting** — Ini *long-term survival* untuk data rahsia Master.

✅ **Lambakan CVE Baru (WordPress & Others)** [CVE Feed/Critical] — Banyak vulnerability baru dikesan termasuk SQL Injection (itsourcecode), XSS (YouTube Embed, Hoo Companion), dan Sandbox Bypass (CrewAI).💡 **Kenapa Penting** — Kalau Master ada guna plugin-plugin ni, tolong *update* sekarang sebelum kena hack.

✅ **Phishing Passkey & LiteLLM** [Hacker News] — Ada campaign phishing guna tema "Passkey" untuk hijack akaun Microsoft, dan banyak server LiteLLM masih guna admin key contoh "sk-1234".💡 **Kenapa Penting** — Peringatan supaya jangan malas tukar *default password/key*.

# 💻 Tech & Dev

✅ **AWS Pizza Bot** [MarkTechPost] — AWS perkenalkan *Pizza Bot*, satu open-source inbox untuk urus AI agents guna LangGraph.💡 **Kenapa Penting** — Memudahkan Master monitor apa yang AI agents Master buat kat background.

✅ **WhatsApp "Event Hub"** [Amanz] — WhatsApp tengah test feature baru untuk urus event dalam satu page khas, bukan sekadar dalam group.💡 **Kenapa Penting** — Senang sikit Master nak organize meeting dengan Kazekage lain.

✅ **Disney+ Malaysia Update** [Amanz] — Pengalaman baru bermula 7 Oktober, tapi sejarah tontonan Master akan hilang.💡 **Kenapa Penting** — Jangan terkejut kalau *watchlist* Master kosong nanti.

🔥 Top Picks

**Amaran CEO Anthropic** — Serius weh, 6-12 bulan je lagi sebelum AI mungkin boleh kawal internet.

**Post-Quantum Cryptography (CISA)** — Masa untuk fikir pasal security masa depan.

**OpenAI's Geometry Breakthrough** — AI dah mula "berfikir" macam ahli matematik pro.

> ls -la berita/

🛡️ Cybersecurity

21
🛡️ Cybersecurity

CVE-2026-90600 - itsourcecode Sales and Inventory System inv_edit1.php sql injection

CVE ID :CVE-2026-90600 Published : Sept. 13, 2026, 11:16 p.m. | 43 minutes ago Description :A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit1.php. The manipula

$> CVE Feed⏱️ 1m
→
🛡️ Cybersecurity

Preparing for the Post-Quantum Era: A Call to Action

CISA and the Group of Seven (G7) Cyber Security Working Group released Preparing for the Post-Quantum Era: A Call to Action highlighting the urgent need for organizations and governments to begin transitioning to post-quantum cryptography (PQC) to pr

$> CISA⏱️ 1m
→
🛡️ Cybersecurity

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. [...]

$> BleepingComputer⏱️ 1m
→
🛡️ Cybersecurity

The U.S. Space Academy Is More of a Workforce Bet Than an Astronaut School

The proposed U.S. Space Academy is a workforce experiment for scaling launch operations, lunar logistics and a growing commercial space economy.

$> Hacker Noon⏱️ 1m
→
🛡️ Cybersecurity

Tycon Systems TPDIN-Monitor-WEB2 (Update A)

View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. The f

$> CISA⏱️ 1m
→
🛡️ Cybersecurity

Rockwell Automation 1756-ENBT Module

View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-2025-10478

$> CISA⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-81648 - CryptoPayment Gateway 1.2.1 - 1.2.2 - Unauthenticated Arbitrary File Deletion and Settings Update via Unguarded AJAX Router

CVE ID :CVE-2026-81648 Published : Sept. 13, 2026, 9:17 p.m. | 2 hours, 42 minutes ago Description :The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenti

$> CVE Critical⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-88793 - YouTube Embed 10.0 - 10.3 - Unauthenticated Stored XSS via youram_server

CVE ID :CVE-2026-88793 Published : Sept. 13, 2026, 9:17 p.m. | 2 hours, 42 minutes ago Description :The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it p

$> CVE Critical⏱️ 1m
→
🛡️ Cybersecurity

ClickFix Campaigns Abuse Legitimate Services for Persistent Access

Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.

$> Dark Reading⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-90602 - Anil-matcha Open-Generative-AI Studio Components ImageStudio.js renderHistory cross site scripting

CVE ID :CVE-2026-90602 Published : Sept. 13, 2026, 11:16 p.m. | 43 minutes ago Description :A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the function renderHistory of the file

$> CVE Feed⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-37008 - CrewAI Sandbox Bypass via Python Runtime Manipulation

CVE ID :CVE-2026-37008 Published : Sept. 13, 2026, 9:17 p.m. | 2 hours, 42 minutes ago Description :CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275

$> CVE Critical⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-90601 - getzep graphiti REST API main.py improper authentication

CVE ID :CVE-2026-90601 Published : Sept. 13, 2026, 11:16 p.m. | 43 minutes ago Description :A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API.

$> CVE Feed⏱️ 1m
→
🛡️ Cybersecurity

Rockwell Automation ControlFLASH

View CSAF Summary Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level. The following versions of Rockwell A

$> CISA⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-90605 - Totolink A3002MU boa formFilter buffer overflow

CVE ID :CVE-2026-90605 Published : Sept. 13, 2026, 11:30 p.m. | 29 minutes ago Description :A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the

$> CVE Feed⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-85129 - Hoo Companion 1.0.2 - Unauthenticated Stored XSS via Theme Settings Import

CVE ID :CVE-2026-85129 Published : Sept. 13, 2026, 9:17 p.m. | 2 hours, 42 minutes ago Description :The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the

$> CVE Critical⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-90603 - Anil-matcha Open-Generative-AI S3 Upload upload-binary unrestricted upload

CVE ID :CVE-2026-90603 Published : Sept. 13, 2026, 11:16 p.m. | 43 minutes ago Description :A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upl

$> CVE Feed⏱️ 1m
→
🛡️ Cybersecurity

Pyramid Solutions NetStaX EtherNet/IP Stack

View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be proce

$> CISA⏱️ 1m
→
🛡️ Cybersecurity

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score

$> Hacker News⏱️ 1m
→
🛡️ Cybersecurity

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agen

$> Hacker News⏱️ 1m
→
🛡️ Cybersecurity

Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites

A Chinese-language group is compromising government and education sites to create a reverse-proxy network with gambling-themed sites.

$> Dark Reading⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-74933 - GenieWords 1.5.27 - 1.5.34 - Unauthenticated Stored XSS and Configuration Overwrite

CVE ID :CVE-2026-74933 Published : Sept. 13, 2026, 9:17 p.m. | 2 hours, 42 minutes ago Description :The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored

$> CVE Critical⏱️ 1m
→

🧠 AI/ML

26
🧠 AI/ML

Hierarchical NeRF with JAX3D for Volumetric Rendering, Novel-View Synthesis, and 3D Reconstruction

In this tutorial, we build an end-to-end hierarchical Neural Radiance Field (NeRF) using JAX, Flax, Optax, and the volume-rendering primitives provided by jax3d. We first construct a synthetic multi-view dataset from an analytic scene containing volu

$> MarkTechPost⏱️ 1m
→
🧠 AI/ML

Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up

Dario Amodei warned that within six to 12 months AI could be capable of leading a swarm of agents that could take over the entire internet. The post Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up appeared f

$> SecurityWeek⏱️ 1m
→
🧠 AI/ML

CEO Anthropic Gesa Pembangunan AI Diperlahankan – Disokong Altman dan Musk

CEO Antropic, Dario Amodei menggesa pembangunan kecerdasan buatan (AI) diperlahankan dan dipantau kerana isu Ini termasuk risiko kehilangan kawalan sistem AI, penyalahgunaan AI untuk serangan siber dan senjata biologi, dan gangguan ke atas ekonomi ya

$> Amanz⏱️ 1m
→
🧠 AI/ML

How I Use Claude and ChatGPT to Make Better AI Images

A practical workflow for using Claude to plan better image prompts, then generating and refining the final image in ChatGPT.

$> Hacker Noon⏱️ 1m
→
🧠 AI/ML

Oppo A7 Pro Dan Oppo A7 Pro Max Bakal Tiba Di Malaysia Tidak Lama Lagi

Oppo mengesahkan bahawa model terbaharu mereka Oppo A7 Pro dan Oppo A7 Pro Max bakal memasuki pasaran Malaysia dalam masa terdekat. Kehadiran kedua-dua model ini menandakan kemunculan generasi baharu telefon Oppo yang dijangka meneruskan tradisi reka

$> Amanz⏱️ 1m
→
🧠 AI/ML

Introducing OpenAI for Singapore

OpenAI for Singapore launches a multi-year AI partnership to expand deployment, build local talent, and support businesses and public services with AI.

$> OpenAI⏱️ 1m
→
🧠 AI/ML

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first c

$> Hacker News⏱️ 1m
→
🧠 AI/ML

Accelerating Qwen3-8B Agent on Intel® Core™ Ultra with Depth-Pruned Draft Models

$> HuggingFace⏱️ 1m
→
🧠 AI/ML

Obama urges Democrats to have a ‘clear plan’ for AI safeguards

Obama recently said that Democrats need to make artificial intelligence one of their “central agendas” and “have a very clear plan” to address concerns around the technology’s economic impact and safety.

$> TechCrunch⏱️ 1m
→
🧠 AI/ML

An OpenAI model has disproved a central conjecture in discrete geometry

An OpenAI model solved the 80-year-old unit distance problem, disproving a major conjecture in discrete geometry and marking a milestone in AI-driven mathematics.

$> OpenAI⏱️ 1m
→
🧠 AI/ML

AdventHealth advances whole-person care with OpenAI

AdventHealth is using ChatGPT for Healthcare to streamline workflows, reduce administrative burden, and return more time to patient care.

$> OpenAI⏱️ 1m
→
🧠 AI/ML

PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said P

$> Hacker News⏱️ 1m
→
🧠 AI/ML

AI Can Write a Perfectly Reasonable Scientific Sentence, and That’s the Problem

A small AI-generated scientific sentence shows how fluent academic writing can quietly add unsupported mechanistic claims.

$> Hacker Noon⏱️ 1m
→
🧠 AI/ML

Week 5 of Building Pocketflow for Shipaton 2026: Paywalls, Timeline Audits, and Launch!

Pocketflow’s final Shipaton week covered UI polish, RevenueCat paywalls, AI credit pricing, balance syncing, and its iOS and Android launch.

$> Hacker Noon⏱️ 1m
→
🧠 AI/ML

Insight Partners’ Deven Parekh on why the firm is diversifying while everyone else bets the farm on OpenAI and Anthropic

Insight Partners' Devin Parekh opens up about losing Legora to General Catalyst, why he's fine holding stakes in rival AI labs, and why — even as everyone else piles into OpenAI and Anthropic — his $90 billion firm is deliberately staying diversified

$> TechCrunch⏱️ 1m
→
🧠 AI/ML

Ulasan Samsung Galaxy S26 FE – Sama Tapi Tak Serupa

Penjimatan dan mampu milik adalah dua terma yang diancam kepupusan disebabkan oleh krisis RAM. Secara purata harga telefon pintar di Malaysia meningkat sekitar RM600 berbanding model tahun lalu dengan konfigurasi storan yang sama. Siri Galaxy FE berm

$> Amanz⏱️ 1m
→
🧠 AI/ML

What’s behind the AI industry’s latest warnings of doom?

On Equity, we discussed the AI industry's latest debate about whether it poses an existential threat to humanity.

$> TechCrunch⏱️ 1m
→
🧠 AI/ML

Implementation of Machine Learning Workflows with NVIDIA cuML, RAPIDS, GPU Benchmarking, Explainability, Clustering, and Model Inference

This practical tutorial demonstrates how to build and accelerate machine learning workflows using NVIDIA cuML and RAPIDS. It covers GPU environment setup, zero-code scikit-learn acceleration with cuml.accel, performance benchmarking across key ML alg

$> MarkTechPost⏱️ 1m
→
🧠 AI/ML

AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?

A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks.

$> Dark Reading⏱️ 1m
→
🧠 AI/ML

The next phase of OpenAI’s Education for Countries

OpenAI advances Education for Countries, expanding AI adoption in schools with new partnerships, teacher training, and tools to improve global learning outcomes.

$> OpenAI⏱️ 1m
→
🧠 AI/ML

Building Isolyne (Part 5): How the Offline Fallback Parser Handles LLM Outages

How Isolyne falls back from Gemini to a local TypeScript parser when connectivity fails, preserving core decision capture and drift detection.

$> Hacker Noon⏱️ 1m
→
🧠 AI/ML

Nemotron-Personas-Japan: ソブリン AI のための合成データセット

$> HuggingFace⏱️ 1m
→
🧠 AI/ML

Companies Have 6 Months to Prepare for Automated Attacks

Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, but researchers warn the situation will become more urgent very soon.

$> Dark Reading⏱️ 1m
→
🧠 AI/ML

Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key

Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway, the software a company puts between its applica

$> Hacker News⏱️ 1m
→
🧠 AI/ML

Insurers Search for Answers to Rein in Rogue AI

As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout.

$> Dark Reading⏱️ 1m
→
🧠 AI/ML

Context Engineering Inside the Harness: 4 Mechanisms That Beat Context Overflow and Goal Loss on Long-Horizon Tasks

A shallow agent is an LLM calling tools in a loop, and on long tasks it fails in 2 ways: context overflow and goal loss. This article opens the harness layer that fixes both, with the actual thresholds shipped by LangChain Deep Agents, Claude Code, M

$> MarkTechPost⏱️ 1m
→

⚡ Tech/Dev

5
⚡ Tech/Dev

AWS Introduces Pizza Bot: An Open Source Inbox for Background AI Agents

Pizza Bot is an open source, self-hosted inbox for AI agents built on DeepAgents and LangGraph. It combines persistent task state, MCP integrations, configurable approvals, and scheduled workflows across multiple model providers. The post AWS Introdu

$> MarkTechPost⏱️ 1m
→
⚡ Tech/Dev

A Princeton Researcher Proposes Recurrent Looped Transformer (RLT) that Carries Decoder State across Every Token, Fixing 96 Blocks per Token with Unbounded Temporal Depth

Yifan Zhang's Recurrent Looped Transformer (RLT) technical report proposes a causal encoder paired with a recurrent decoder that carries its final hidden state and layerwise sliding-window attention cache across every prompt and response token, with

$> MarkTechPost⏱️ 1m
→
⚡ Tech/Dev

WhatsApp Menguji Ciri “Event Hub” Bagi Memudahkan Pengurusan Acara

WhatsApp kini sedang menguji ciri baharu bernama Events Hub. Ia muncul sebagai halaman khas dalam aplikasi untuk memudahkan pengguna mencipta, mengurus dan menyemak acara. Sebelum ini, acara hanya boleh dibuat dalam kumpulan atau komuniti, tetapi kin

$> Amanz⏱️ 1m
→
⚡ Tech/Dev

How Ramp engineers accelerate code review with Codex

How Ramp engineers use Codex with GPT-5.5 to review code and ship improvements, allowing them to get substantive feedback in minutes instead of hours.

$> OpenAI⏱️ 1m
→
⚡ Tech/Dev

The 9 buzziest startups from Y Combinator’s latest Demo Day, according to VCs

From floating reactors to brain chips: VCs picked their favorite YC startups from the summer batch.

$> TechCrunch⏱️ 1m
→

📌 Lain-lain

4

🇲🇾 Malaysia/Lokal

1