⏐ Taklimat Pagi
Taklimat Pagi Saya
🔗 baca_penuh: pagi.hejes.my/2026/09/17
> ringkasan_ai
# 🤖 AI & Machine Learning (The Hot Topic!)
✅ **Agentic AI: Dari Pembantu Jadi Penyerang** [SecurityWeek, BleepingComputer, Dark Reading, Hacker News] — Ada laporan pertama pasal AI agent yang berjaya buat *data breach* kat Sepanyol, dan serangan "BragJack" yang boleh hijack AI dalam browser. Malah, ada session AI coding assistant kena hijack sampai tersebar malware Shai-Hulud kat 100 repo.💡 **Kenapa Penting** — AI bukan setakat tolong tulis email dah, tapi dah mula boleh buat serangan autonomi yang kompleks.
✅ **OpenAI: Strategi Bisnes & Komuniti** [OpenAI] — OpenAI tengah push AI untuk advertising (Sponsored Agents) dan buat workshop untuk warga emas guna ChatGPT.💡 **Kenapa Penting** — OpenAI tengah cuba luaskan *market reach* mereka ke semua lapisan umur dan sektor bisnes.
✅ **Inovasi Model & Research** [HuggingFace, arXiv, MarkTechPost] — Ada model baru macam Palmyra-mini, Causilo (tabular model), dan Paper2Agent yang boleh tukar research paper jadi AI agent.💡 **Kenapa Penting** — Keupayaan AI untuk "membaca" paper akademik dan terus buat eksperimen akan percepatkan R&D Master.
✅ **Meta & Apple: Hardware AI** [Amanz] — Meta tengah buat smart glasses tanpa kamera, manakala Apple mungkin jual server M8 Ultra untuk developer AI.💡 **Kenapa Penting** — Perang hardware AI makin sengit, bukan setakat software je.
# 🛡️ Cybersecurity (Alert!)
✅ **Zero-Day & Critical Flaws** [SecurityWeek, Hacker News, CVE Feed] — Google dah patch zero-day Pixel Modem, tapi ada flaw kritikal kat Issabel Framework (CVSS 9.8) dan Parallels Desktop yang boleh bagi akses *root* kat Mac.💡 **Kenapa Penting** — Banyak *privilege escalation* berlaku; kena make sure semua system Master up-to-date.
✅ **Targeted Attacks** [Dark Reading, Hacker News] — Kumpulan APT Korea Utara target sektor media/automotif Korea Selatan, manakala tiga group lain (NightEagle, etc.) target enterprise kat Rusia.💡 **Kenapa Penting** — Geopolitik sentiasa jadi driver utama serangan cyber skala besar.
✅ **CMS Vulnerabilities** [Exploit-DB] — Payload CMS, Bludit CMS, dan Grav CMS semuanya ada vulnerability (SQLi, XSS, RCE).💡 **Kenapa Penting** — Kalau Master ada guna CMS ni, tolong update sekarang sebelum kena *pwn*.
# 💻 Tech & Dev
✅ **AM Radio Kembali?** [TechCrunch] — US mungkin paksa pengeluar kereta letak radio AM secara percuma balik.💡 **Kenapa Penting** — Kadang-kadang tech lama tetap penting untuk kecemasan.
✅ **Apple M8 Ultra Server** [Amanz] — Apple nak masuk market server AI untuk enterprise.💡 **Kenapa Penting** — Kalau jadi, kita mungkin tak payah bergantung sangat kat NVIDIA.
# 🌍 Lain-lain
✅ **Isu Penerbangan Domestik** [Amanz] — Kerajaan tengah bincang dengan MAS & Batik Air untuk ambil alih pasaran domestik AirAsia kalau ada masalah kewangan serius.💡 **Kenapa Penting** — Boleh affect harga tiket flight Master nanti.
🔥 Top Picks
**Agentic AI Data Breach** — Seram weh, AI dah boleh cari vulnerability dan login sendiri.
**Apple M8 Ultra Server** — Game changer untuk developer yang nak power Apple Silicon dalam skala server.
**Issabel Framework Flaw** — Score 9.8 tu memang bahaya gila, kena check kalau ada guna.
> ls -la berita/
🛡️ Cybersecurity
27Cyber Op Targets South Korean Media & Automotive Sectors
A likely North Korean advanced persistent threat (APT) group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications, and further exploit networks.
Pixel Modem Zero-Day Exploited in Targeted Attacks
Google announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15. The post Pixel Modem Zero-Day Exploited in Targeted Attacks appeared first on SecurityWeek.
[webapps] Payload CMS 3.72.0 - Blind SQL Injection
Payload CMS 3.72.0 - Blind SQL Injection
[webapps] Bludit CMS - Stored XSS
Bludit CMS - Stored XSS
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9
The true cost of a ransomware attack, with and without BCDR
The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a fa
[webapps] Wolf CMS 0.8.3.1 - RCE v
Wolf CMS 0.8.3.1 - RCE v
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by Ni
CVE-2026-61596 - djust has broken object-level access control (IDOR)
CVE ID :CVE-2026-61596 Published : Sept. 16, 2026, 11:16 p.m. | 57 minutes ago Description :djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's per-object auth
Wärtsilä FOS-Onboard
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to deliver an unauthorized update, execute code, or extract credentials to allow the attacker to impersonate a privileged client. The following versions of Wär
Malware bypasses browser checks to force install Chrome, Edge extensions
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. [...]
First Agentic AI Data Breach Reported to Spanish Regulator
Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous cyberattacks. The post First Agentic AI Data Breach Reported to Spanish Regulator app
CVE-2026-85789 - Rejected reason: This CVE ID has been rejected or
CVE ID :CVE-2026-85789 Published : Sept. 16, 2026, 11:16 p.m. | 57 minutes ago Description :Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Severity: 0.0 | NA Visit the link for more details, such as CVSS d
Axoflow Launches AxoDetect, Bringing Detection Into The Pipeline and Making The SIEM Optional
Now in early access, AxoDetect runs Sigma rules in stream - alerts travel to the SIEM, and full-fidelity logs land in AxoLake, a low-cost security data lake
CareCam CM2507
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access live video and sensitive device information, enable unauthorized services, execute arbitrary code, modify device operation, and recover stored creden
CVE-2026-61599 - djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount path
CVE ID :CVE-2026-61599 Published : Sept. 16, 2026, 11:16 p.m. | 57 minutes ago Description :djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the djust live transpor
[webapps] Grav CMS 2.0.7 - RCE
Grav CMS 2.0.7 - RCE
CVE-2026-65388 - Containerization Registry Credential Disclosure Vulnerability
CVE ID :CVE-2026-65388 Published : Sept. 16, 2026, 11:16 p.m. | 57 minutes ago Description :A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim
Virtual Event Today: Attack Surface Management Summit
Join SecurityWeek today for a virtual summit exploring the strategies and tools organizations need to discover, prioritize, and defend their expanding attack surfaces. The post Virtual Event Today: Attack Surface Management Summit appeared first on S
Using Cyber Decoys to Strengthen Detection and Response
CISA developed this guidance to help defensive teams at varying levels of cybersecurity maturity plan and implement cyber decoy strategies that strengthen their detection and response capabilities. Many organizations struggle to detect adversaries wh
CVE-2026-92596 - Nodemailer before 9.1.0 Denial of Service via addressparser
CVE ID :CVE-2026-92596 Published : Sept. 16, 2026, 10:18 p.m. | 1 hour, 57 minutes ago Description :Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial
CVE-2026-92594 - Craft CMS before 5.11.0 Unauthenticated PII Disclosure via GraphQL
CVE ID :CVE-2026-92594 Published : Sept. 16, 2026, 10:18 p.m. | 1 hour, 57 minutes ago Description :Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of requiring the
Siemens Reyrolle 7SR5
View CSAF Summary Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version. The following versions of Siemens Reyrolle 7SR5 are aff
CVE-2026-92599 - Joi before 17.13.7 and 18.2.6 ReDoS via isoDate
CVE ID :CVE-2026-92599 Published : Sept. 16, 2026, 10:18 p.m. | 1 hour, 57 minutes ago Description :joi (npm package `joi`, hapi.js) versions >=17.2.0 =18.0.0 Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected produc
Siemens Mendix SAML
View CSAF Summary Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update
CVE-2026-61589 - djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path
CVE ID :CVE-2026-61589 Published : Sept. 16, 2026, 11:16 p.m. | 57 minutes ago Description :djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the WebSocket `handle_m
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. [...]
⚡ Tech/Dev
7Fighting Your Dragons Through Tough Tech Times
Cybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and self-doubt and shares how to build meaningful connections during historical tech industry downturns.
How I Tested Amana Across Locations in the iOS Simulator
How an iOS developer used simctl, WeatherKit, and location changes to capture realistic App Store screenshots without mocking the sky.
US automakers could soon be forced to include AM radio for free
The House of Representatives, in rare bipartisan support, overwhelmingly approved legislation that would require new vehicles to include AM radio.
Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
Parallels Desktop for Mac has a flaw that lets an ordinary local account run code as root, the highest level of access on a Mac, software company JFrog said this week. The attack needs code already running on the machine as a normal user, so it does
Apple Pertimbang Menjual Pelayan AI Dikuasakan Cip M8 Ultra Kepada Pembangun Dan Perusahaan
Apple kini dilaporkan sedang bangunkan perancangan untuk menjual pelayan dikuasakan cip Apple M8 Ultra yang memfokuskan kepada kecerdasan buatan janaan, dan ditujukan kepada pengguna perusahaan atau pembangun. Langkah ini dilihat selari dengan permin
Knowledgator Releases GLiFormer: A 575M-Parameter Encoder That Hits 91.10 F1 on Nested JSON Extraction Without Generating Tokens
GLiFormer Large scores 91.10 F1 on nested JSON, near GPT-5.6-luna's 91.96, while grounding every value in source spans. The post Knowledgator Releases GLiFormer: A 575M-Parameter Encoder That Hits 91.10 F1 on Nested JSON Extraction Without Generating
[webapps] miniOrange 5.4.3 - Unauthenticated Auth Bypass
miniOrange 5.4.3 - Unauthenticated Auth Bypass
🧠 AI/ML
35Root-Cause Attribution Is a Search Problem: Continual Search for Long-Horizon Agent Failures
arXiv:2609.13463v1 Announce Type: new Abstract: The increasing deployment of AI agents in long-horizon tasks yields massive execution logs. Diagnosing failures within these records is crucial for reliability, as it transforms outcome-level signals in
Reimagining advertising with AI
Explore new AI-powered advertising experiences from OpenAI, including Sponsored Agents, tools for marketers, and integrations with HubSpot and Shopify.
How workers are unlocking new ways of working
New OpenAI Economic Research shows how workers use AI beyond traditional roles and which new activities become recurring parts of their work.
EU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media
Ursula von der Leyen warns that advanced AI could unleash hacking on an unprecedented scale as Europe prepares new protections against social media’s “capture” of children. The post EU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media
Fine-tune Any LLM from the Hugging Face Hub with Together AI
Spain's data agency gets first report of AI-powered data breach
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). [...]
Kerajaan Berbincang Dengan Malaysia Airlines dan Batik Air Untuk Ambil Alih Pasaran Domestik AirAsia
Kerajaan Malaysia sedang berbincang dengan Malaysia Airlines dan Batik Air sebagai sebahagian daripada perancangan untuk kemungkinan mengambil alih pasaran domestik AirAsia sekiranya berlaku masalah kewangan serius menurut laporan Reuters. Perancanga
Adobe Kini Mempunyai 1 Bilion Pengguna Aktif Bulanan
Adobe merupakan salah satu jenama yang tidak asing bagi ramai yang terlibat dalam arena kreatif. Mereka mempunyai sejumlah perisian dibawah mereka, termasuk antara yang popular adalah Adobe Photoshop, Adobe Illustrator, Adobe Indesign, Adobe Premiere
AIUC Raises $40 Million to Certify Enterprise AI Agents
The company provides a standard for AI systems, testing them against risks such as jailbreaks, prompt injections, and unauthorized actions. The post AIUC Raises $40 Million to Certify Enterprise AI Agents appeared first on SecurityWeek.
Meta Sedang Bangunkan Kaca Mata Pintar Baharu Tanpa Kamera
Meta pada hari ini sedia menerajui arena kaca mata pintar, dan mempunyai beberapa penawaran model berbeza. Kaca mata pintar yang ditawarkan hadir dengan sokongan kamera terbina, membolehkan pengguna menggunakannya dalam merakamkan gambar dan juga vid
Some of the Best Security Features Slow You Down on Purpose
Banking-style cooling-off periods could make AI agents safer by delaying high-risk actions and allowing time for review and cancellation.
BragJack Attack Can Turn a Browser's Agentic AI Against It
A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.
TimeThink: Eliciting Compositional Reasoning in Timeseries Large Language Models
arXiv:2609.13457v1 Announce Type: new Abstract: Timeseries multimodal large language models (TS-MLLMs) have recently begun leveraging the reasoning capabilities of large language models (LLMs) for question-answering tasks. However, these models often
Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories. Before the repository spread, the assistant recommended sof
One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claud
How to connect AI usage to business value
Learn how ChatGPT Work and Codex analytics help teams understand AI usage and spend, identify training needs, and connect adoption to business outcomes.
Al Gore has a surprisingly calm take on the AI data center backlash
In an interview with TechCrunch, Al Gore suggested he isn't losing sleep over AI data center emissions — he's more worried about the AI industry's own warnings about where the technology is headed.
CVE-2026-92598 - Nodemailer before 9.1.0 IDN/Punycode Domain Allow-list Bypass
CVE ID :CVE-2026-92598 Published : Sept. 16, 2026, 10:18 p.m. | 1 hour, 57 minutes ago Description :Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a differe
Noise wants to help everyday people become paid content creators
Marketing platform Noise is on a mission to help anyone with a smart phone make money from their content.
Governing at Machine Speed: An Adaptive Intelligence Architecture for Real-Time AI Policy Enforcement
arXiv:2609.13466v1 Announce Type: new Abstract: Enterprise AI adoption has reached 78% of organizations globally, yet the infrastructure to govern that adoption has not kept pace. This paper identifies and characterizes the attestation deficit, a str
BASIS.pro Expands On-Chain Infrastructure with XDC Network Partnership and Zypher DAO
New developments extend BASIS across real-world asset and AI-native infrastructure while introducing automated reward restaking for BTC, ETH, SOL, and PAXG part
Tricks from OpenAI gpt-oss YOU 🫵 can use with transformers
OrchSLM: Probing the Dynamics of Small Language Model Orchestration
arXiv:2609.13470v1 Announce Type: new Abstract: Although large language models (LLMs) have demonstrated remarkable capabilities, their reliance on cloud-scale infrastructure poses fundamental challenges for deployment in agentic pipelines, including
Helping older adults use AI in everyday life
OpenAI and AARP are bringing free, hands-on ChatGPT workshops to 1,000 older adults across 10 U.S. cities to build practical AI skills safely.
AI Security Spending Jumps as Fear Outpaces Proof of Value
CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?
Jupyter Agents: training LLMs to reason with notebooks
Windows 11 KB5124008 update breaks domain trust for some users
Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. [...]
Building the materials foundation for AI
The AI boom is becoming a materials challenge. As AI pushes computing into new territory, the materials behind that infrastructure are becoming just as crucial as the algorithms running on it. Semiconductors and data centers are approaching physical
Nums AI Releases Causilo: A Tabular Foundation Model That Tops TabArena Among Single Models
Nums AI has released Causilo, a pretrained tabular foundation model for classification and regression with a scikit-learn interface. It posts the top TabArena Elo among single models, ahead of Google's TabFM and LG's EXAONE Tabular. The code is Apach
Pengasas ByteDance, Zhang Yiming Kini Menjadi Manusia Terkaya Di Asia
Pengasas ByteDance, syarikat sebalik TikTok dan sejumlah perkhidmatan lain, Zhang Yiming kini menjadi manusia terkaya di dunia. Zhang Yiming berusia 43 tahun, kini mempunyai nilai kekayaan mencapai lebih $105 bilion, sekaligus mendahului Gautam Adani
Our framework for reporting model misalignment
OpenAI shares a framework for tracking, investigating, and disclosing model misalignment, alongside six reports of unexpected or concerning model behavior.
AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours
The incident demonstrates how frontier AI agents can dramatically compress an attack timeline and coordinate a large-scale breach, according to researchers.
CVE-2026-92597 - Nodemailer before 9.1.0 Email Domain Validation Bypass via RFC 5322 Comment
CVE ID :CVE-2026-92597 Published : Sept. 16, 2026, 10:18 p.m. | 1 hour, 57 minutes ago Description :Nodemailer versions >= 6.9.16 and Severity: 8.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Prior Labs Releases TabPFN-3.5: A Tabular Foundation Model That Beats the Winning Otto Kaggle Solution With Default Settings
Prior Labs released TabPFN-3.5, a tabular foundation model pretrained only on synthetic data that beats Otto's winning solution. The post Prior Labs Releases TabPFN-3.5: A Tabular Foundation Model That Beats the Winning Otto Kaggle Solution With Defa
Data Broker Radaris Loses Domains in Privacy Fight
The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radar
📌 Lain-lain
5Pulley, a Carta rival, is shutting down
Cap table management platform Pulley, backed by General Catalyst, Stripe, and Founders Fund, announced that it's closing shop in December.
Introducing the Palmyra-mini family: Powerful, lightweight, and ready to reason!
Visible Watermarking with Gradio
Musk’s long-time backer is giving SpaceX stock to its investors
Valor Equity Partners is handing out stock to its LPs instead of cash returns.
What SpaceX’s Empty Insider Filing Record Says About Lock-Up Expiries
SpaceX affiliates became eligible to sell after a lock-up release, but SEC filings show no post-listing insider transactions so far.
🔬 Science/Research
2Stanford Researchers Release Paper2Agent: Turning Research Papers Into AI Agents That Reproduce Results and Run on New Data
Paper2Agent, published in Nature, converts papers into validated MCP tools, scoring 91.2% on 300 questions across 74 papers. The post Stanford Researchers Release Paper2Agent: Turning Research Papers Into AI Agents That Reproduce Results and Run on N
LabAgent: Customize Any Research Hubs for Scientific Discoveries Using AI Agents
arXiv:2609.13437v1 Announce Type: new Abstract: Scientific research is a continuous process that emphasizes inheritance. Methods developed by predecessors are often expanded upon by new researchers to explore more novel and in-depth scientific questi