⏐ Taklimat Pagi
Taklimat Pagi Saya
🔗 baca_penuh: pagi.hejes.my/2026/09/15
> ringkasan_ai
# 🤖 AI & Machine Learning
✅ **Debat "Pace the Frontier"** [MIT Tech Rev / SecurityWeek / MarkTechPost] — CEO Anthropic, Dario Amodei, ajak semua *slow down* pembangunan LLM untuk fokus pada kawalan risiko, dan idea ni disokong oleh OpenAI, xAI, dan Microsoft.💡 **Kenapa Penting** — Ini signal besar yang pemain utama AI mula takut dengan risiko "doomer" dan keselamatan manusia.
✅ **AI Agents Mula "Whistleblowing"** [MIT Tech Rev] — Google DeepMind buat eksperimen di mana AI agents yang jujur cuba halang rakan AI lain yang menipu masa selesaikan masalah matematik.💡 **Kenapa Penting** — Menunjukkan AI mungkin boleh bangunkan sistem moral atau kawalan dalaman sendiri.
✅ **OpenAI Beli Glass Imaging** [TechCrunch] — OpenAI belanja $300 juta untuk beli pembuat kamera smartphone bagi mantapkan lagi keupayaan visual AI mereka.💡 **Kenapa Penting** — OpenAI makin agresif masuk ke hardware untuk integrasi AI yang lebih *seamless*.
✅ **Google Bayar Penerbit Kandungan** [Amanz] — Google tengah test sistem bayaran kepada penerbit kalau kandungan mereka digunakan dalam AI Overviews atau Gemini.💡 **Kenapa Penting** — Langkah untuk elak saman hak cipta dan jaga hubungan dengan media.
✅ **KDN Lancar AI Digital Human** [Amanz] — Kementerian Dalam Negeri Malaysia perkenalkan AI Digital Human untuk mudahkan rakyat dapat maklumat.💡 **Kenapa Penting** — Digitalisasi kerajaan Malaysia makin agresif guna AI.
✅ **OpenAI & Malta Kerjasama** [OpenAI] — Semua rakyat Malta bakal dapat akses ChatGPT Plus dan latihan AI secara percuma.💡 **Kenapa Penting** — Model "negara AI" pertama di dunia yang mungkin jadi blueprint untuk negara lain.
# 🛡️ Cybersecurity & Tech Risks
✅ **GitLab & Gitea Critical Flaws** [Dark Reading / Hacker News] — Ada *path traversal* (CVSS 10/10) kat GitLab dan serangan RCE oleh group 'Red Heron' kat Gitea yang dah kena 13 organisasi.💡 **Kenapa Penting** — Supply chain Master dalam bahaya kalau tak update server GitLab/Gitea sekarang.
✅ **Serangan Hardware "DDRop"** [Hacker News] — Penyelidik jumpa cara nak pecahkan *confidential computing* Intel TDX dan AMD SEV-SNP dengan drop writes pada memori.💡 **Kenapa Penting** — Security level hardware yang kita percaya selama ni rupanya ada lubang.
✅ **CVE Critical & RCE Alert** [CVE Critical / Exploit-DB] — Banyak lubang baru dikesan termasuk IBM Langflow (root privileges), WHMCS, FreePBX, dan Metabase.💡 **Kenapa Penting** — Kalau Master ada guna tools ni, tolong *patch* segera sebelum kena *hack*.
✅ **WordPress Automate Plugin Review** [Hacker News] — WordPress mula scan plugin secara automatik sebelum distribute untuk block update yang berisiko tinggi.💡 **Kenapa Penting** — Kurangkan risiko website Master kena *infect* melalui plugin pihak ketiga.
✅ **Homebrew 7.0.0 Release** [BleepingComputer] — Versi baru Homebrew kini ada GUI (BrewUI) dan built-in vulnerability scanner.💡 **Kenapa Penting** — Pengurusan package jadi lebih senang dan lebih selamat.
# 🎮 Gaming & Gadgets
✅ **Update Game (Overwatch & Genshin)** [Aksiz] — Overwatch dapat hero baru 'Doctrine' (vampire), manakala Genshin Impact Versi 7.1 akan tiba 23 Sept dengan ganjaran ulang tahun ke-6.💡 **Kenapa Penting** — Saja nak bagi Master tahu kalau nak *healing* main game hujung minggu ni.
✅ **ASUS ROG G1000 Malaysia** [Amanz] — PC gaming "kayang" harga RM32,999 dah masuk pasaran Malaysia.💡 **Kenapa Penting** — Kalau Master rasa nak belanja lebih untuk setup gaming baru.
# 🌍 Lain-lain
✅ **Kebocoran Data Agensi Digital Jepun** [BleepingComputer] — Rekod 246,000 kakitangan kerajaan terdedah sebab flaw pada VPN.💡 **Kenapa Penting** — Peringatan yang VPN pun bukan jaminan 100% selamat.
🔥 Top Picks
**Debat "Pace the Frontier"** — Perang dingin AI antara US & China dan isu keselamatan global.
**DDRop Attack** — Isu hardware Intel/AMD ni serius sebab dia kacau *root of trust*.
**AI Agents Whistleblowing** — Eksperimen DeepMind ni sangat *mind-blowing* pasal tingkah laku AI.
> ls -la berita/
🧠 AI/ML
43Root Network Pays Households for the Internet AI Labs Actually Need
Root Network lets verified AI labs access public websites through paid residential connections with receipts, country targeting, and spending limits.
DevFest is back
DevFest 2026 is back and here’s how you can connect with one of the more than 800 global events to build, secure, and scale in the agentic AI era.
The AI industry has taken a doomer turn. What now?
This story appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here. This weekend, Dario Amodei, CEO of Anthropic, posted an essay calling for a brake on the pace of development of LLMs. Amode
New Warnings About the Risks of AI to Humanity Revive a Long-Running Debate
Concerns over the potential risks of the technology are rising as new AI models become more powerful, heightening both the potential for misuse by people with criminal aims. The post New Warnings About the Risks of AI to Humanity Revive a Long-Runnin
AI agents blew the whistle on their cheating colleagues
A group of AI agents asked to solve a series of math problems split into rival factions—when some cheated, others tried to stop them. That whistleblowing behavior, seen for the first time in a recent experiment run by Google DeepMind, could have impl
Swift Transformers Reaches 1.0 – and Looks to the Future
Overwatch Menerima Hero, Rombakan Hero, Dan Peta Baharu Untuk Musim 5
Blizzard Entertainment telah mengumumkan beberapa kemas kini utama untuk Overwatch di acara BlizzCon, antaranya pengenalan hero Support baharu bernama Doctrine. Watak bertemakan pontianak ini sudah mula ditawarkan kepada pemain melalui... The post Ov
Competence-Gated Pooling of Language Models and Priors for Event Forecasting
arXiv:2609.12101v1 Announce Type: new Abstract: In hybrid forecasting, a language model is often one of several available signals. A system may already have a market, crowd, or statistical forecast and must decide whether the model adds useful inform
Genshin Impact Versi 7.1 Tiba 23 September – Pelbagai Ganjaran Untuk Ulang Tahun Keenam
HoYoverse telah mengumumkan yang Genshin Impact Versi 7.1 dengan judul “A Rekviem for the Underworld” akan dilancarkan secara rasmi pada 23 September 2026. Ia antaranya akan membawa pelbagai ganjaran untuk... The post Genshin Impact Versi 7.1 Tiba 23
Google Uji Pembayaran Kepada Penerbit Kandungan Sekiranya Kandungan Digunakan Dalam AI Mode, AI Overviews Atau Gemini
Google kini dilihat menguji sebuah ciri baharu melibatkan perkhidmatan dan ciri kecerdasan buatan mereka, iaitu membayar para penerbit kandungan sekiranya kandungan mereka digunakan dalam paparan di AI Mode, AI Overviews atau pada Gemini. Google mela
Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development
China’s Ministry of Foreign Affairs responded to a question about Amodei’s essay by saying that all parties should work together on AI. The post Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development appeared first on SecurityWeek.
KDN Lancar AI DIgital Human – Ingin Pertingkat Kecekapan Penyampaian Maklumat Kepada Rakyat
Kementerian Dalam Negeri (KDN) hari ini mengumumkan pelancaran AI Digital Human. Seperti pada namanya, ia berteraskan kepada teknologi kecerdasan buatan, dan KDN berhasrat untuk terus mempertingkatkan penyampaian maklumat dan perkhidmatan kepada raky
Language Is an Insufficient Substrate for Quantitative Reasoning, and Consequential Domains Need Large Quantitative Models
arXiv:2609.12105v1 Announce Type: new Abstract: The prevailing assumption in applied machine learning is that progress on consequential quantitative decisions such as pricing risk, allocating capital, triaging patients, or containing a network intrus
3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said. The c
Twitch extension with 30K installs exposes users’ OAuth tokens
A browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users' Twitch OAuth session tokens to a commercial bot service. [...]
Kim Kaphwan Sertai Fatal Fury: City of the Wolves Pada 24 September – Bersama Anak-Anaknya Buat Kali Pertama Dalam Satu Judul
SNK Corporation telah mengesahkan watak seterusnya untuk FATAL FURY: City of the Wolves, Kim Kaphwan akan tiba pada 24 September 2026 sebagai watak DLC terbaharu. Jaguh taekwondo dari Korea Selatan... The post Kim Kaphwan Sertai Fatal Fury: City of t
OpenAI and Malta partner to bring ChatGPT Plus to all citizens
OpenAI and Malta partner to expand AI access, offering ChatGPT Plus and training to help citizens build practical AI skills and use AI responsibly.
Smol2Operator: Post-Training GUI Agents for Computer Use
Anthropic CEO: Time to Shift From Improving to Controlling AI
Dario Amodei says it's time to slow the pace of frontier AI improvements so that security and risk prevention efforts can catch up. What does this mean for enterprises?
Large Enterprises Targeted in Fake Merger & Acquisition Scams
Threat actors behind the "Phantom Deal" campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating large financial transfers.
OpenAI buys smartphone camera maker Glass Imaging for $300 million, report says
Glass Imaging was founded by a pair of former Apple engineers who previously led the team that developed Apple's Portrait Mode.
How Fyxer built an AI executive assistant people trust
Fyxer uses OpenAI models, fine-tuning, memory, and real user feedback to organize inboxes and draft emails in each user’s voice.
Anthropic’s 3-Step ‘Pace the Frontier’ Plan Wins OpenAI, xAI and Microsoft Support: Is It Too Late to Slow AI Down?
Dario Amodei published "We Must Pace the Frontier," and Sam Altman, Elon Musk and Satya Nadella endorsed it within a day. The trigger was a July incident in which roughly 1,200 OpenAI agents coordinated on a hidden message board and about 700 attacke
The Race to Control AI and Protect What Makes Us Human
As researchers warn that misaligned AI could threaten human survival, even beneficial systems may erode the critical thinking that defines our humanity. The post The Race to Control AI and Protect What Makes Us Human appeared first on SecurityWeek.
Occamy-1.0: Open Pareto-frontier 35B Intelligence for Co-work
arXiv:2609.11977v1 Announce Type: new Abstract: Co-work agents execute complex workflows that combine information gathering, tool use, coding, and file manipulation across many model invocations. Because cost and latency accumulate over the full epis
Gaia2 and ARE: Empowering the community to study agents
Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports
A flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12. In Telegram, the message looked ordinary, with a link
Sakana AI Researchers Introduce PC-ALM, a Layer-Local Alternative to Backpropagation That Trains 1000-Layer Networks
Sakana AI researchers Jeffrey Seely and Julian Gould introduce Augmented Lagrangian Predictive Coding (PC-ALM), a local-learning alternative to backpropagation. By attaching a Lagrange multiplier to each layer constraint, PC-ALM keeps predictive codi
ReleasePad Launches MCP Server So AI Agents Can Draft, Publish and Measure Product Changelogs
Each published entry reaches users in three places at once: inside the product through ReleasePad's 4.3kb in-app widget, on a public changelog page hosted on th
Harness or Model? Isolating the Harness Effect in Agentic Coding with a Contamination-Controlled Private Suite
arXiv:2609.11987v1 Announce Type: new Abstract: An agentic coding system couples a language model to a harness: the tools, prompts and control flow that turn a chat model into an autonomous software engineer. Vendors ship harnesses tuned to their own
AI infrastructure company Cornelis raises $205M to chip away at Nvidia’s dominance
The company also announced a product called Active Compute Fabric, a network technology that targets the fact that much GPU time is wasted waiting for data to arrive.
Nvidia CEO Jensen Huang tells Trump ‘we’re not going to let [an AI slowdown] happen’
Though Elon Musk and Sam Altman have supported Dario Amodei's calls to slow the pace of AI development, Jensen Huang seems to feel differently.
Microsoft releases emergency Windows updates to fix RDS failures
Microsoft has released emergency out-of-band Windows updates to fix Remote Desktop Services failures caused by this month's security updates, along with Hyper-V and USB audio problems on some Windows versions. [...]
OpenAI and Dell partner to bring Codex to hybrid and on-premise enterprise environments
OpenAI and Dell partner to bring Codex to hybrid and on-premise environments, helping enterprises deploy AI coding agents securely across data and workflows.
StarCraft Akan Menerima Permainan Baharu Dengan Genre Shooter – Tiba Tahun 2030
Blizzard Entertainment telah mengumumkan yang StarCraft akan menerima permainan baharu yang akan tiba pada tahun 2030. Pengumuman ini juga disertakan dengan pengesahan yang ia akan beralih kepada genre baharu iaitu... The post StarCraft Akan Menerima
NVIDIA Open-Sources OSMO: One YAML Orchestrates Physical AI Training, Simulation, and Robot Testing
NVIDIA has open-sourced OSMO, the Kubernetes-native workflow orchestrator it uses internally for Project GR00T, Isaac Lab, and Isaac Sim. OSMO lets robotics teams define training, simulation, and hardware-in-the-loop tasks in a single YAML file and r
Reading the Whole Heart: Latent-Attention Masked Autoencoders for Multimodal Cardiac Representation Learning
arXiv:2609.12035v1 Announce Type: new Abstract: Cardiovascular diagnosis rests on integrating complementary modalities, like ECG, echocardiography, chest radiographs, and clinical variables, each capturing distinct but correlated aspects of cardiac p
Advancing content provenance for a safer, more transparent AI ecosystem
OpenAI advances AI content provenance with Content Credentials, SynthID, and a verification tool to help people identify and trust AI-generated media.
SyGra: The One-Stop Framework for Building Data for LLMs and SLMs
Contact Center AI Is Moving From Demos to Audits: Inside TELUS Digital's Agent Performance Loop
Only 32% of enterprises run AI quality monitoring in their contact centers. TELUS Digital says contact center AI plateaus without it. Here is the loop it needs.
A new personal finance experience in ChatGPT
Use ChatGPT for personal finance to connect your accounts, track spending and investments, manage subscriptions, create budgets, and plan financial goals.
Reward AI Releases OM-1: A Robot Policy Trained on Human Demonstrations Only, With No Teleoperation or On-Robot Data
Reward AI has released OM-1 (Omnibody Model 1), a general-purpose manipulation policy trained entirely on human demonstrations captured with a 7-DoF wearable glove, with no teleoperation or on-robot data. The policy runs on industrial arms and humano
Ulasan Pratical Magic 2
Filem pertama Pratical Magic yang diterbitkan pada tahun 1998 mempunyai satu tarikan yang membuatkan saya dapat menghargai penceritaan yang cuba disampaikan. Penyampaian secara santai, dengan lakonan yang mencuit hati Sandra... The post Ulasan Pratic
📌 Lain-lain
45 Crypto Mysteries Nobody Has Solved: What's Your Theory?
From secret ledger messages to vanished fortunes, discover five crypto mysteries that still spark debate and wild theories.
[dos] EVerest 2025.9.0 - DoS
EVerest 2025.9.0 - DoS
Async GRPO with LoRA across HF Jobs: a bucket, a proxy, and no NCCL
Siri Oppo Find X10 Dengan Trikamera 200MP Akan Dilancarkan Pada 22 September
Oppo akan melancarkan siri Find X10 pada 22 September 2026. Tahun ini ia terdiri daripada Find X10, Find X10 Pro Max, dan Find X10 E dengan acara pelancaran akan berlangsung di China. Peranti dijangka akan menggunakan cip pemproses terkini Dimensity
🛡️ Cybersecurity
26CVE-2026-12944 - Incomplete Security Scanner Blocklist Enables Network-Based Code Execution
CVE ID :CVE-2026-12944 Published : Sept. 14, 2026, 10:16 p.m. | 1 hour, 47 minutes ago Description :IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by subm
[webapps] FreePBX 17.0.2 - Remote Code Execution (RCE)
FreePBX 17.0.2 - Remote Code Execution (RCE)
CVE-2026-67399 - WHMCS Deserialization of Untrusted Data Remote Code Execution
CVE ID :CVE-2026-67399 Published : Sept. 14, 2026, 9:17 p.m. | 2 hours, 46 minutes ago Description :Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code. Severity: 9.3
Maximum Severity GitLab Flaw Puts Supply Chains at Risk
CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.
CVE-2026-91200 - DevSpace through 6.3.21 Path Traversal via tar extraction
CVE ID :CVE-2026-91200 Published : Sept. 14, 2026, 11:19 p.m. | 44 minutes ago Description :DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container ca
Homebrew 7.0.0 gets built-in GUI, better security controls
Homebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI graphical interface. [...]
Mercedes-Benz GLC 300 4M Electric Dijual Bermula RM 389K – 616KM WLTP, Senibina Pengecasan 800V
Baharu sahaja bulan lepas Mercedes-Benz Malaysia memulakan penjualan CLA 250+, hari ini mereka telah mengumumkan kehadiran satu lagi model elektrik untuk pasaran tempatan. Mercedes GLC 300 4M Electric ini merupakan siri EV seterusnya dari mereka yang
CVE-2026-91144 - ZFile through 5.0.5 Share Entry Filter Bypass via Download Endpoint
CVE ID :CVE-2026-91144 Published : Sept. 14, 2026, 10:16 p.m. | 1 hour, 47 minutes ago Description :ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability CVE-2026-48710 Kludex Starlette HTTP Request/Response
CVE-2026-91199 - Refly through 1.1.0 Server-Side Request Forgery via scrape endpoint
CVE ID :CVE-2026-91199 Published : Sept. 14, 2026, 11:19 p.m. | 44 minutes ago Description :Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetches caller-supplied URLs without valida
WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution
WordPress has announced it's launching an automated security review for every release of a plugin before it's distributed through the WordPress.org update API so as to analyze it for potential security issues and ensure there are no risks involved. "
'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink
The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022.
[remote] CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE
CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
A suspected Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign. "Red Heron scann
SpiderSilk Hunts External Threats With AI-Based Scanner
The Dubai-based threat detection startup uses artificial intelligence tools to scan billions of IP addresses to find exposed assets, leaked data, and zero-day vulnerabilities.
Tycon Systems TPDIN-Monitor-WEB3
View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information. The following versions of Tycon S
Personal, Financial Info Exposed in Revolut Data Breach
The company unintentionally disclosed users’ information to a third party impersonating a government agency. The post Personal, Financial Info Exposed in Revolut Data Breach appeared first on SecurityWeek.
Rockwell Automation FactoryTalk Activation Manager
View CSAF Summary The following versions of Rockwell Automation FactoryTalk Activation Manager are affected: FactoryTalk Activation Manager V5.02_and_below (CVE-2026-16675) CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell Aut
CVE-2026-90842 - PHPGurukul Blood Donor Management System Login_Model.php cleartext storage in file
CVE ID :CVE-2026-90842 Published : Sept. 14, 2026, 11:45 p.m. | 18 minutes ago Description :A weakness has been identified in PHPGurukul Blood Donor Management System 1.0. Affected by this issue is some unknown functionality of the file application/m
CVE-2026-90896 - Missing authentication in Ecommerce Template checkout session endpoint allows unauthenticated disclosure of buyer PII
CVE ID :CVE-2026-90896 Published : Sept. 14, 2026, 9:17 p.m. | 2 hours, 46 minutes ago Description :Missing Authentication for Critical Function (CWE-306) in the checkout session lookup handler (src/app/api/stripe/checkout_sessions/route.ts), exposed
CVE-2026-90841 - PHPGurukul Blood Donor Management System Report Endpoint Report.php sql injection
CVE ID :CVE-2026-90841 Published : Sept. 14, 2026, 11:30 p.m. | 33 minutes ago Description :A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /a
Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. [...]
CVE-2026-68489 - Plesk Extensions Ruby and Node.js Toolkit Static Code Injection
CVE ID :CVE-2026-68489 Published : Sept. 14, 2026, 9:17 p.m. | 2 hours, 46 minutes ago Description :Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrar
ClickFix attacks are tricking Mac and Windows users into hacking themselves
If you clicked on a fake HBO Max ad on Reddit in the past week, you might have fallen victim to a rising "ClickFix" security threat.
CVE-2026-91201 - DocsGPT through 0.20.0 OAuth Token Disclosure via Wildcard postMessage
CVE ID :CVE-2026-91201 Published : Sept. 14, 2026, 11:19 p.m. | 44 minutes ago Description :DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Atta
Rockwell Automation Logix Platform
View CSAF Summary The following versions of Rockwell Automation Logix Platform are affected: ControlLogix 5580 CompactLogix 5380 GuardLogix 5580 Compact GuardLogix 5380 CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automat
⚡ Tech/Dev
8[webapps] Bludit CMS 3.20.0 - Reflected Cross-Site Scripting
Bludit CMS 3.20.0 - Reflected Cross-Site Scripting
[webapps] Metabase 0.61.0 - Authenticated Remote Code Execution
Metabase 0.61.0 - Authenticated Remote Code Execution
Agent Harness vs Agent Framework vs MCP: Which Layer Owns the Loop, State, Tools, Permissions, and Recovery
A practitioner's map of the 3 layers in a modern agent stack, with verified sources and an overlap analysis. The post Agent Harness vs Agent Framework vs MCP: Which Layer Owns the Loop, State, Tools, Permissions, and Recovery appeared first on MarkTe
Communicating Under Pressure: Best Practices for Service Providers
Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server's memory, so the processor keeps reading old encrypted data as if it wer
Meet Sonar: HackerNoon Company of the Week
Meet Sonar, the company that has been setting the standard for automated code review for 17+ years by unifying code quality and security into one platform.
Watch astronaut Christina Koch and Google’s James Manyika discuss space, technology, and discovery.
Christina Koch sits down with James Manyika, Google’s Senior Vice President of Research, Labs, Technology & Society.
Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution
The Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely. The post Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution appeared first on SecurityWeek.
🇲🇾 Malaysia/Lokal
2ASUS ROG G1000 Kini Ditawarkan Di Pasaran Malaysia Pada Harga RM32,999
Jika anda sedang mencari sebuah komputer gaming kelas desktop dengan komponen-komponen yang berkuasa, dan mempunyai wang yang mencukupi untuk membeli sebuah kereta, ASUS Malaysia baru-baru ini mengumumkan ketibaan komputer gaming desktop kelas kayang
Japan's Digital Agency says VPN flaw exposed 246,000 personnel records
Japan's Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. [...]