⏐ Taklimat Pagi

Taklimat Pagi Saya

“Rezeki pagi ni datang pada yang bangun dan cuba.”
//84 cerita//~3 minit

🔗 baca_penuh: pagi.hejes.my/2026/09/15

> ringkasan_ai

# 🤖 AI & Machine Learning

✅ **Debat "Pace the Frontier"** [MIT Tech Rev / SecurityWeek / MarkTechPost] — CEO Anthropic, Dario Amodei, ajak semua *slow down* pembangunan LLM untuk fokus pada kawalan risiko, dan idea ni disokong oleh OpenAI, xAI, dan Microsoft.💡 **Kenapa Penting** — Ini signal besar yang pemain utama AI mula takut dengan risiko "doomer" dan keselamatan manusia.

✅ **AI Agents Mula "Whistleblowing"** [MIT Tech Rev] — Google DeepMind buat eksperimen di mana AI agents yang jujur cuba halang rakan AI lain yang menipu masa selesaikan masalah matematik.💡 **Kenapa Penting** — Menunjukkan AI mungkin boleh bangunkan sistem moral atau kawalan dalaman sendiri.

✅ **OpenAI Beli Glass Imaging** [TechCrunch] — OpenAI belanja $300 juta untuk beli pembuat kamera smartphone bagi mantapkan lagi keupayaan visual AI mereka.💡 **Kenapa Penting** — OpenAI makin agresif masuk ke hardware untuk integrasi AI yang lebih *seamless*.

✅ **Google Bayar Penerbit Kandungan** [Amanz] — Google tengah test sistem bayaran kepada penerbit kalau kandungan mereka digunakan dalam AI Overviews atau Gemini.💡 **Kenapa Penting** — Langkah untuk elak saman hak cipta dan jaga hubungan dengan media.

✅ **KDN Lancar AI Digital Human** [Amanz] — Kementerian Dalam Negeri Malaysia perkenalkan AI Digital Human untuk mudahkan rakyat dapat maklumat.💡 **Kenapa Penting** — Digitalisasi kerajaan Malaysia makin agresif guna AI.

✅ **OpenAI & Malta Kerjasama** [OpenAI] — Semua rakyat Malta bakal dapat akses ChatGPT Plus dan latihan AI secara percuma.💡 **Kenapa Penting** — Model "negara AI" pertama di dunia yang mungkin jadi blueprint untuk negara lain.

# 🛡️ Cybersecurity & Tech Risks

✅ **GitLab & Gitea Critical Flaws** [Dark Reading / Hacker News] — Ada *path traversal* (CVSS 10/10) kat GitLab dan serangan RCE oleh group 'Red Heron' kat Gitea yang dah kena 13 organisasi.💡 **Kenapa Penting** — Supply chain Master dalam bahaya kalau tak update server GitLab/Gitea sekarang.

✅ **Serangan Hardware "DDRop"** [Hacker News] — Penyelidik jumpa cara nak pecahkan *confidential computing* Intel TDX dan AMD SEV-SNP dengan drop writes pada memori.💡 **Kenapa Penting** — Security level hardware yang kita percaya selama ni rupanya ada lubang.

✅ **CVE Critical & RCE Alert** [CVE Critical / Exploit-DB] — Banyak lubang baru dikesan termasuk IBM Langflow (root privileges), WHMCS, FreePBX, dan Metabase.💡 **Kenapa Penting** — Kalau Master ada guna tools ni, tolong *patch* segera sebelum kena *hack*.

✅ **WordPress Automate Plugin Review** [Hacker News] — WordPress mula scan plugin secara automatik sebelum distribute untuk block update yang berisiko tinggi.💡 **Kenapa Penting** — Kurangkan risiko website Master kena *infect* melalui plugin pihak ketiga.

✅ **Homebrew 7.0.0 Release** [BleepingComputer] — Versi baru Homebrew kini ada GUI (BrewUI) dan built-in vulnerability scanner.💡 **Kenapa Penting** — Pengurusan package jadi lebih senang dan lebih selamat.

# 🎮 Gaming & Gadgets

✅ **Update Game (Overwatch & Genshin)** [Aksiz] — Overwatch dapat hero baru 'Doctrine' (vampire), manakala Genshin Impact Versi 7.1 akan tiba 23 Sept dengan ganjaran ulang tahun ke-6.💡 **Kenapa Penting** — Saja nak bagi Master tahu kalau nak *healing* main game hujung minggu ni.

✅ **ASUS ROG G1000 Malaysia** [Amanz] — PC gaming "kayang" harga RM32,999 dah masuk pasaran Malaysia.💡 **Kenapa Penting** — Kalau Master rasa nak belanja lebih untuk setup gaming baru.

# 🌍 Lain-lain

✅ **Kebocoran Data Agensi Digital Jepun** [BleepingComputer] — Rekod 246,000 kakitangan kerajaan terdedah sebab flaw pada VPN.💡 **Kenapa Penting** — Peringatan yang VPN pun bukan jaminan 100% selamat.

🔥 Top Picks

**Debat "Pace the Frontier"** — Perang dingin AI antara US & China dan isu keselamatan global.

**DDRop Attack** — Isu hardware Intel/AMD ni serius sebab dia kacau *root of trust*.

**AI Agents Whistleblowing** — Eksperimen DeepMind ni sangat *mind-blowing* pasal tingkah laku AI.

> ls -la berita/

🧠 AI/ML

43
🧠 AI/ML

Root Network Pays Households for the Internet AI Labs Actually Need

Root Network lets verified AI labs access public websites through paid residential connections with receipts, country targeting, and spending limits.

$> Hacker Noon⏱️ 1m
→
🧠 AI/ML

DevFest is back

DevFest 2026 is back and here’s how you can connect with one of the more than 800 global events to build, secure, and scale in the agentic AI era.

$> Google AI⏱️ 1m
→
🧠 AI/ML

The AI industry has taken a doomer turn. What now?

This story appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here. This weekend, Dario Amodei, CEO of Anthropic, posted an essay calling for a brake on the pace of development of LLMs. Amode

$> MIT Tech Rev⏱️ 1m
→
🧠 AI/ML

New Warnings About the Risks of AI to Humanity Revive a Long-Running Debate

Concerns over the potential risks of the technology are rising as new AI models become more powerful, heightening both the potential for misuse by people with criminal aims. The post New Warnings About the Risks of AI to Humanity Revive a Long-Runnin

$> SecurityWeek⏱️ 1m
→
🧠 AI/ML

AI agents blew the whistle on their cheating colleagues

A group of AI agents asked to solve a series of math problems split into rival factions—when some cheated, others tried to stop them. That whistleblowing behavior, seen for the first time in a recent experiment run by Google DeepMind, could have impl

$> MIT Tech Rev⏱️ 1m
→
🧠 AI/ML

Swift Transformers Reaches 1.0 – and Looks to the Future

$> HuggingFace⏱️ 1m
→
🧠 AI/ML

Overwatch Menerima Hero, Rombakan Hero, Dan Peta Baharu Untuk Musim 5

Blizzard Entertainment telah mengumumkan beberapa kemas kini utama untuk Overwatch di acara BlizzCon, antaranya pengenalan hero Support baharu bernama Doctrine. Watak bertemakan pontianak ini sudah mula ditawarkan kepada pemain melalui... The post Ov

$> Aksiz⏱️ 1m
→
🧠 AI/ML

Competence-Gated Pooling of Language Models and Priors for Event Forecasting

arXiv:2609.12101v1 Announce Type: new Abstract: In hybrid forecasting, a language model is often one of several available signals. A system may already have a market, crowd, or statistical forecast and must decide whether the model adds useful inform

$> arXiv cs.AI⏱️ 1m
→
🧠 AI/ML

Genshin Impact Versi 7.1 Tiba 23 September – Pelbagai Ganjaran Untuk Ulang Tahun Keenam

HoYoverse telah mengumumkan yang Genshin Impact Versi 7.1 dengan judul “A Rekviem for the Underworld” akan dilancarkan secara rasmi pada 23 September 2026. Ia antaranya akan membawa pelbagai ganjaran untuk... The post Genshin Impact Versi 7.1 Tiba 23

$> Aksiz⏱️ 1m
→
🧠 AI/ML

Google Uji Pembayaran Kepada Penerbit Kandungan Sekiranya Kandungan Digunakan Dalam AI Mode, AI Overviews Atau Gemini

Google kini dilihat menguji sebuah ciri baharu melibatkan perkhidmatan dan ciri kecerdasan buatan mereka, iaitu membayar para penerbit kandungan sekiranya kandungan mereka digunakan dalam paparan di AI Mode, AI Overviews atau pada Gemini. Google mela

$> Amanz⏱️ 1m
→
🧠 AI/ML

Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development

China’s Ministry of Foreign Affairs responded to a question about Amodei’s essay by saying that all parties should work together on AI. The post Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development appeared first on SecurityWeek.

$> SecurityWeek⏱️ 1m
→
🧠 AI/ML

KDN Lancar AI DIgital Human – Ingin Pertingkat Kecekapan Penyampaian Maklumat Kepada Rakyat

Kementerian Dalam Negeri (KDN) hari ini mengumumkan pelancaran AI Digital Human. Seperti pada namanya, ia berteraskan kepada teknologi kecerdasan buatan, dan KDN berhasrat untuk terus mempertingkatkan penyampaian maklumat dan perkhidmatan kepada raky

$> Amanz⏱️ 1m
→
🧠 AI/ML

Language Is an Insufficient Substrate for Quantitative Reasoning, and Consequential Domains Need Large Quantitative Models

arXiv:2609.12105v1 Announce Type: new Abstract: The prevailing assumption in applied machine learning is that progress on consequential quantitative decisions such as pricing risk, allocating capital, triaging patients, or containing a network intrus

$> arXiv cs.AI⏱️ 1m
→
🧠 AI/ML

3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said. The c

$> Hacker News⏱️ 1m
→
🧠 AI/ML

Twitch extension with 30K installs exposes users’ OAuth tokens

A browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users' Twitch OAuth session tokens to a commercial bot service. [...]

$> BleepingComputer⏱️ 1m
→
🧠 AI/ML

Kim Kaphwan Sertai Fatal Fury: City of the Wolves Pada 24 September – Bersama Anak-Anaknya Buat Kali Pertama Dalam Satu Judul

SNK Corporation telah mengesahkan watak seterusnya untuk FATAL FURY: City of the Wolves, Kim Kaphwan akan tiba pada 24 September 2026 sebagai watak DLC terbaharu. Jaguh taekwondo dari Korea Selatan... The post Kim Kaphwan Sertai Fatal Fury: City of t

$> Aksiz⏱️ 1m
→
🧠 AI/ML

OpenAI and Malta partner to bring ChatGPT Plus to all citizens

OpenAI and Malta partner to expand AI access, offering ChatGPT Plus and training to help citizens build practical AI skills and use AI responsibly.

$> OpenAI⏱️ 1m
→
🧠 AI/ML

Smol2Operator: Post-Training GUI Agents for Computer Use

$> HuggingFace⏱️ 1m
→
🧠 AI/ML

Anthropic CEO: Time to Shift From Improving to Controlling AI

Dario Amodei says it's time to slow the pace of frontier AI improvements so that security and risk prevention efforts can catch up. What does this mean for enterprises?

$> Dark Reading⏱️ 1m
→
🧠 AI/ML

Large Enterprises Targeted in Fake Merger & Acquisition Scams

Threat actors behind the "Phantom Deal" campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating large financial transfers.

$> Dark Reading⏱️ 1m
→
🧠 AI/ML

OpenAI buys smartphone camera maker Glass Imaging for $300 million, report says

Glass Imaging was founded by a pair of former Apple engineers who previously led the team that developed Apple's Portrait Mode.

$> TechCrunch⏱️ 1m
→
🧠 AI/ML

How Fyxer built an AI executive assistant people trust

Fyxer uses OpenAI models, fine-tuning, memory, and real user feedback to organize inboxes and draft emails in each user’s voice.

$> OpenAI⏱️ 1m
→
🧠 AI/ML

Anthropic’s 3-Step ‘Pace the Frontier’ Plan Wins OpenAI, xAI and Microsoft Support: Is It Too Late to Slow AI Down?

Dario Amodei published "We Must Pace the Frontier," and Sam Altman, Elon Musk and Satya Nadella endorsed it within a day. The trigger was a July incident in which roughly 1,200 OpenAI agents coordinated on a hidden message board and about 700 attacke

$> MarkTechPost⏱️ 1m
→
🧠 AI/ML

The Race to Control AI and Protect What Makes Us Human

As researchers warn that misaligned AI could threaten human survival, even beneficial systems may erode the critical thinking that defines our humanity. The post The Race to Control AI and Protect What Makes Us Human appeared first on SecurityWeek.

$> SecurityWeek⏱️ 1m
→
🧠 AI/ML

Occamy-1.0: Open Pareto-frontier 35B Intelligence for Co-work

arXiv:2609.11977v1 Announce Type: new Abstract: Co-work agents execute complex workflows that combine information gathering, tool use, coding, and file manipulation across many model invocations. Because cost and latency accumulate over the full epis

$> arXiv cs.AI⏱️ 1m
→
🧠 AI/ML

Gaia2 and ARE: Empowering the community to study agents

$> HuggingFace⏱️ 1m
→
🧠 AI/ML

Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports

A flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12. In Telegram, the message looked ordinary, with a link

$> Hacker News⏱️ 1m
→
🧠 AI/ML

Sakana AI Researchers Introduce PC-ALM, a Layer-Local Alternative to Backpropagation That Trains 1000-Layer Networks

Sakana AI researchers Jeffrey Seely and Julian Gould introduce Augmented Lagrangian Predictive Coding (PC-ALM), a local-learning alternative to backpropagation. By attaching a Lagrange multiplier to each layer constraint, PC-ALM keeps predictive codi

$> MarkTechPost⏱️ 1m
→
🧠 AI/ML

ReleasePad Launches MCP Server So AI Agents Can Draft, Publish and Measure Product Changelogs

Each published entry reaches users in three places at once: inside the product through ReleasePad's 4.3kb in-app widget, on a public changelog page hosted on th

$> Hacker Noon⏱️ 1m
→
🧠 AI/ML

Harness or Model? Isolating the Harness Effect in Agentic Coding with a Contamination-Controlled Private Suite

arXiv:2609.11987v1 Announce Type: new Abstract: An agentic coding system couples a language model to a harness: the tools, prompts and control flow that turn a chat model into an autonomous software engineer. Vendors ship harnesses tuned to their own

$> arXiv cs.AI⏱️ 1m
→
🧠 AI/ML

AI infrastructure company Cornelis raises $205M to chip away at Nvidia’s dominance

The company also announced a product called Active Compute Fabric, a network technology that targets the fact that much GPU time is wasted waiting for data to arrive.

$> TechCrunch⏱️ 1m
→
🧠 AI/ML

Nvidia CEO Jensen Huang tells Trump ‘we’re not going to let [an AI slowdown] happen’

Though Elon Musk and Sam Altman have supported Dario Amodei's calls to slow the pace of AI development, Jensen Huang seems to feel differently.

$> TechCrunch⏱️ 1m
→
🧠 AI/ML

Microsoft releases emergency Windows updates to fix RDS failures

Microsoft has released emergency out-of-band Windows updates to fix Remote Desktop Services failures caused by this month's security updates, along with Hyper-V and USB audio problems on some Windows versions. [...]

$> BleepingComputer⏱️ 1m
→
🧠 AI/ML

OpenAI and Dell partner to bring Codex to hybrid and on-premise enterprise environments

OpenAI and Dell partner to bring Codex to hybrid and on-premise environments, helping enterprises deploy AI coding agents securely across data and workflows.

$> OpenAI⏱️ 1m
→
🧠 AI/ML

StarCraft Akan Menerima Permainan Baharu Dengan Genre Shooter – Tiba Tahun 2030

Blizzard Entertainment telah mengumumkan yang StarCraft akan menerima permainan baharu yang akan tiba pada tahun 2030. Pengumuman ini juga disertakan dengan pengesahan yang ia akan beralih kepada genre baharu iaitu... The post StarCraft Akan Menerima

$> Aksiz⏱️ 1m
→
🧠 AI/ML

NVIDIA Open-Sources OSMO: One YAML Orchestrates Physical AI Training, Simulation, and Robot Testing

NVIDIA has open-sourced OSMO, the Kubernetes-native workflow orchestrator it uses internally for Project GR00T, Isaac Lab, and Isaac Sim. OSMO lets robotics teams define training, simulation, and hardware-in-the-loop tasks in a single YAML file and r

$> MarkTechPost⏱️ 1m
→
🧠 AI/ML

Reading the Whole Heart: Latent-Attention Masked Autoencoders for Multimodal Cardiac Representation Learning

arXiv:2609.12035v1 Announce Type: new Abstract: Cardiovascular diagnosis rests on integrating complementary modalities, like ECG, echocardiography, chest radiographs, and clinical variables, each capturing distinct but correlated aspects of cardiac p

$> arXiv cs.AI⏱️ 1m
→
🧠 AI/ML

Advancing content provenance for a safer, more transparent AI ecosystem

OpenAI advances AI content provenance with Content Credentials, SynthID, and a verification tool to help people identify and trust AI-generated media.

$> OpenAI⏱️ 1m
→
🧠 AI/ML

SyGra: The One-Stop Framework for Building Data for LLMs and SLMs

$> HuggingFace⏱️ 1m
→
🧠 AI/ML

Contact Center AI Is Moving From Demos to Audits: Inside TELUS Digital's Agent Performance Loop

Only 32% of enterprises run AI quality monitoring in their contact centers. TELUS Digital says contact center AI plateaus without it. Here is the loop it needs.

$> Hacker Noon⏱️ 1m
→
🧠 AI/ML

A new personal finance experience in ChatGPT

Use ChatGPT for personal finance to connect your accounts, track spending and investments, manage subscriptions, create budgets, and plan financial goals.

$> OpenAI⏱️ 1m
→
🧠 AI/ML

Reward AI Releases OM-1: A Robot Policy Trained on Human Demonstrations Only, With No Teleoperation or On-Robot Data

Reward AI has released OM-1 (Omnibody Model 1), a general-purpose manipulation policy trained entirely on human demonstrations captured with a 7-DoF wearable glove, with no teleoperation or on-robot data. The policy runs on industrial arms and humano

$> MarkTechPost⏱️ 1m
→
🧠 AI/ML

Ulasan Pratical Magic 2

Filem pertama Pratical Magic yang diterbitkan pada tahun 1998 mempunyai satu tarikan yang membuatkan saya dapat menghargai penceritaan yang cuba disampaikan. Penyampaian secara santai, dengan lakonan yang mencuit hati Sandra... The post Ulasan Pratic

$> Aksiz⏱️ 1m
→

📌 Lain-lain

4

🛡️ Cybersecurity

26
🛡️ Cybersecurity

CVE-2026-12944 - Incomplete Security Scanner Blocklist Enables Network-Based Code Execution

CVE ID :CVE-2026-12944 Published : Sept. 14, 2026, 10:16 p.m. | 1 hour, 47 minutes ago Description :IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by subm

$> CVE Critical⏱️ 1m
→
🛡️ Cybersecurity

[webapps] FreePBX 17.0.2 - Remote Code Execution (RCE)

FreePBX 17.0.2 - Remote Code Execution (RCE)

$> Exploit-DB⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-67399 - WHMCS Deserialization of Untrusted Data Remote Code Execution

CVE ID :CVE-2026-67399 Published : Sept. 14, 2026, 9:17 p.m. | 2 hours, 46 minutes ago Description :Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code. Severity: 9.3

$> CVE Critical⏱️ 1m
→
🛡️ Cybersecurity

Maximum Severity GitLab Flaw Puts Supply Chains at Risk

CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.

$> Dark Reading⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-91200 - DevSpace through 6.3.21 Path Traversal via tar extraction

CVE ID :CVE-2026-91200 Published : Sept. 14, 2026, 11:19 p.m. | 44 minutes ago Description :DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container ca

$> CVE Feed⏱️ 1m
→
🛡️ Cybersecurity

Homebrew 7.0.0 gets built-in GUI, better security controls

Homebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI graphical interface. [...]

$> BleepingComputer⏱️ 1m
→
🛡️ Cybersecurity

Mercedes-Benz GLC 300 4M Electric Dijual Bermula RM 389K – 616KM WLTP, Senibina Pengecasan 800V

Baharu sahaja bulan lepas Mercedes-Benz Malaysia memulakan penjualan CLA 250+, hari ini mereka telah mengumumkan kehadiran satu lagi model elektrik untuk pasaran tempatan. Mercedes GLC 300 4M Electric ini merupakan siri EV seterusnya dari mereka yang

$> Amanz⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-91144 - ZFile through 5.0.5 Share Entry Filter Bypass via Download Endpoint

CVE ID :CVE-2026-91144 Published : Sept. 14, 2026, 10:16 p.m. | 1 hour, 47 minutes ago Description :ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share

$> CVE Critical⏱️ 1m
→
🛡️ Cybersecurity

CISA Adds Seven Known Exploited Vulnerabilities to Catalog

CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability CVE-2026-48710 Kludex Starlette HTTP Request/Response

$> CISA⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-91199 - Refly through 1.1.0 Server-Side Request Forgery via scrape endpoint

CVE ID :CVE-2026-91199 Published : Sept. 14, 2026, 11:19 p.m. | 44 minutes ago Description :Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetches caller-supplied URLs without valida

$> CVE Feed⏱️ 1m
→
🛡️ Cybersecurity

WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution

WordPress has announced it's launching an automated security review for every release of a plugin before it's distributed through the WordPress.org update API so as to analyze it for potential security issues and ensure there are no risks involved. "

$> Hacker News⏱️ 1m
→
🛡️ Cybersecurity

'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink

The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022.

$> Dark Reading⏱️ 1m
→
🛡️ Cybersecurity

[remote] CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE

CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE

$> Exploit-DB⏱️ 1m
→
🛡️ Cybersecurity

Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

A suspected Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign. "Red Heron scann

$> Hacker News⏱️ 1m
→
🛡️ Cybersecurity

SpiderSilk Hunts External Threats With AI-Based Scanner

The Dubai-based threat detection startup uses artificial intelligence tools to scan billions of IP addresses to find exposed assets, leaked data, and zero-day vulnerabilities.

$> Dark Reading⏱️ 1m
→
🛡️ Cybersecurity

Tycon Systems TPDIN-Monitor-WEB3

View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information. The following versions of Tycon S

$> CISA⏱️ 1m
→
🛡️ Cybersecurity

Personal, Financial Info Exposed in Revolut Data Breach

The company unintentionally disclosed users’ information to a third party impersonating a government agency. The post Personal, Financial Info Exposed in Revolut Data Breach appeared first on SecurityWeek.

$> SecurityWeek⏱️ 1m
→
🛡️ Cybersecurity

Rockwell Automation FactoryTalk Activation Manager

View CSAF Summary The following versions of Rockwell Automation FactoryTalk Activation Manager are affected: FactoryTalk Activation Manager V5.02_and_below (CVE-2026-16675) CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell Aut

$> CISA⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-90842 - PHPGurukul Blood Donor Management System Login_Model.php cleartext storage in file

CVE ID :CVE-2026-90842 Published : Sept. 14, 2026, 11:45 p.m. | 18 minutes ago Description :A weakness has been identified in PHPGurukul Blood Donor Management System 1.0. Affected by this issue is some unknown functionality of the file application/m

$> CVE Feed⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-90896 - Missing authentication in Ecommerce Template checkout session endpoint allows unauthenticated disclosure of buyer PII

CVE ID :CVE-2026-90896 Published : Sept. 14, 2026, 9:17 p.m. | 2 hours, 46 minutes ago Description :Missing Authentication for Critical Function (CWE-306) in the checkout session lookup handler (src/app/api/stripe/checkout_sessions/route.ts), exposed

$> CVE Critical⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-90841 - PHPGurukul Blood Donor Management System Report Endpoint Report.php sql injection

CVE ID :CVE-2026-90841 Published : Sept. 14, 2026, 11:30 p.m. | 33 minutes ago Description :A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /a

$> CVE Feed⏱️ 1m
→
🛡️ Cybersecurity

Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. [...]

$> BleepingComputer⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-68489 - Plesk Extensions Ruby and Node.js Toolkit Static Code Injection

CVE ID :CVE-2026-68489 Published : Sept. 14, 2026, 9:17 p.m. | 2 hours, 46 minutes ago Description :Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrar

$> CVE Critical⏱️ 1m
→
🛡️ Cybersecurity

ClickFix attacks are tricking Mac and Windows users into hacking themselves

If you clicked on a fake HBO Max ad on Reddit in the past week, you might have fallen victim to a rising "ClickFix" security threat.

$> TechCrunch⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-91201 - DocsGPT through 0.20.0 OAuth Token Disclosure via Wildcard postMessage

CVE ID :CVE-2026-91201 Published : Sept. 14, 2026, 11:19 p.m. | 44 minutes ago Description :DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Atta

$> CVE Feed⏱️ 1m
→
🛡️ Cybersecurity

Rockwell Automation Logix Platform

View CSAF Summary The following versions of Rockwell Automation Logix Platform are affected: ControlLogix 5580 CompactLogix 5380 GuardLogix 5580 Compact GuardLogix 5380 CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automat

$> CISA⏱️ 1m
→

⚡ Tech/Dev

8
⚡ Tech/Dev

[webapps] Bludit CMS 3.20.0 - Reflected Cross-Site Scripting

Bludit CMS 3.20.0 - Reflected Cross-Site Scripting

$> Exploit-DB⏱️ 1m
→
⚡ Tech/Dev

[webapps] Metabase 0.61.0 - Authenticated Remote Code Execution

Metabase 0.61.0 - Authenticated Remote Code Execution

$> Exploit-DB⏱️ 1m
→
⚡ Tech/Dev

Agent Harness vs Agent Framework vs MCP: Which Layer Owns the Loop, State, Tools, Permissions, and Recovery

A practitioner's map of the 3 layers in a modern agent stack, with verified sources and an overlap analysis. The post Agent Harness vs Agent Framework vs MCP: Which Layer Owns the Loop, State, Tools, Permissions, and Recovery appeared first on MarkTe

$> MarkTechPost⏱️ 1m
→
⚡ Tech/Dev

Communicating Under Pressure: Best Practices for Service Providers

Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (

$> CISA⏱️ 1m
→
⚡ Tech/Dev

New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing

Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server's memory, so the processor keeps reading old encrypted data as if it wer

$> Hacker News⏱️ 1m
→
⚡ Tech/Dev

Meet Sonar: HackerNoon Company of the Week

Meet Sonar, the company that has been setting the standard for automated code review for 17+ years by unifying code quality and security into one platform.

$> Hacker Noon⏱️ 1m
→
⚡ Tech/Dev

Watch astronaut Christina Koch and Google’s James Manyika discuss space, technology, and discovery.

Christina Koch sits down with James Manyika, Google’s Senior Vice President of Research, Labs, Technology & Society.

$> Google AI⏱️ 1m
→
⚡ Tech/Dev

Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

The Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely. The post Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution appeared first on SecurityWeek.

$> SecurityWeek⏱️ 1m
→

🇲🇾 Malaysia/Lokal

2

🔬 Science/Research

1