⏐ Taklimat Pagi
Taklimat Pagi Saya
🔗 baca_penuh: pagi.hejes.my/2026/09/19
> ringkasan_ai
# 🛡️ Cybersecurity (Kecoh Sikit Hari Ni)
✅ **Microsoft Patch Critical Flaws** [Hacker News/SecurityWeek] — Microsoft baru *patch* 18 lubang sekuriti, termasuk satu flaw CVSS 10.0 kat Azure AI Foundry yang boleh buat *privilege escalation*.💡 **Kenapa Penting** — Kalau Master guna Azure AI, kena pastikan semua *up-to-date* sebab skor 10.0 tu memang bahaya gila.
✅ **Gyazo Data Breach** [BleepingComputer] — 23.6 juta rekod user Gyazo kena curi sebab ada *server vulnerability*.💡 **Kenapa Penting** — Peringatan untuk kita jangan simpan data sensitif kat platform *image-sharing*.
✅ **Cisco Zero-Day & API Issues** [Dark Reading] — Ada *authentication bypass* (CVE-2026-76460) kat Cisco ISE dengan skor CVSS 10/10.💡 **Kenapa Penting** — API yang tak secure boleh jadi pintu masuk utama untuk *attacker*.
✅ **Pelbagai CVE Kritikal (ProFTPD, Acode, Totolink, OpenShift)** [Exploit-DB/CVE Feed] — Banyak *critical flaws* baru dikesan melibatkan RCE, *buffer overflow*, dan SSRF kat pelbagai software.💡 **Kenapa Penting** — Master kena alert kalau ada *legacy system* yang guna software ni.
✅ **Fake LastPass Repos on GitHub** [BleepingComputer] — Ada kempen malware guna repo GitHub palsu untuk sebar *infostealer* bernama Rapuncel.💡 **Kenapa Penting** — Jangan main *clone* je repo GitHub, kena check betul-betul siapa *owner* dia.
# 🤖 AI & Machine Learning (Makin Power)
✅ **Anthropic's Bio Lab & AI Research** [TechCrunch/Amanz] — Anthropic dah buka makmal biologi sendiri dan Claude kini handle 26% kerja pembangunan AI generasi seterusnya.💡 **Kenapa Penting** — AI bukan setakat tulis kod, tapi dah mula masuk bidang sains fizikal/biologi secara serius.
✅ **Jina AI & PrismML Model Releases** [MarkTechPost] — Jina AI keluar `jina-ocr-v1` untuk parse dokumen ke Markdown, manakala PrismML keluar `Ternary Bonsai 2 27B` yang sangat ringan (5.9GB) tapi perform.💡 **Kenapa Penting** — Model makin efisien, GPU bajet pun dah boleh run model power.
✅ **AI Agents in Enterprise** [Dark Reading/MarkTechPost/Hacker Noon] — Salesforce Agentforce cuba bawa AI agent ke tahap *production-grade*, tapi survey EY tunjuk implementasi AI sekarang lebih laju daripada sistem pengawasan (*oversight*).💡 **Kenapa Penting** — Bahaya kalau kita bagi AI agent kuasa penuh tanpa ada *guardrails* yang betul.
✅ **ChatGPT Adoption 2026** [OpenAI] — Penggunaan ChatGPT makin meluas dalam kalangan user 35 tahun ke atas dan lebih seimbang dari segi gender.💡 **Kenapa Penting** — AI dah betul-betul jadi *mainstream tool*, bukan untuk budak tech je.
# 💻 Tech & Dev (Update Ringkas)
✅ **Linux Kernel Local Root Exploits** [Hacker News] — Kod exploit untuk 4 flaw kernel Linux yang boleh bagi akses *root* dah dilepaskan kepada umum.💡 **Kenapa Penting** — Cepat-cepat *update* kernel Linux Master kalau tak nak kena *hijack*.
✅ **HP OmniBook Ultra 14 & Razer Tartarus V2 Pro** [Amanz] — Laptop Intel "Panther Lake" dan keypad gaming Razer terbaru dah masuk market Malaysia.💡 **Kenapa Penting** — Saja nak bagi Master tahu kalau Master rasa nak *upgrade* gear baru.
# 🔬 Science & Research
✅ **Interdisciplinary AI Research** [arXiv/HuggingFace] — Ada kajian baru pasal *systematic generalization* dan benchmark `BioPhys-Bridge` untuk reasoning sains biologi-fizik.💡 **Kenapa Penting** — AI mula belajar cara "berfikir" macam saintis manusia, bukan sekadar teka perkataan.
🔥 Top Picks
**Microsoft Azure AI Foundry Flaw (CVSS 10.0)** — Paling kritikal, wajib tahu.
**Anthropic's Bio Lab** — Menarik tengok AI mula buat eksperimen biologi realiti.
**PrismML Ternary Bonsai 2** — Model 27B tapi cuma 5.9GB? Ini *game changer* untuk local LLM.
> ls -la berita/
🛡️ Cybersecurity
24[remote] CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE
CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE
Gyazo server flaw exploited to steal 23.6 million user records
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records. [...]
Webinar: Which Google Workspace security controls actually matter?
Fast-growing companies face countless recommendations for securing Google Workspace, but not every control provides the same value. This webinar examines real-world breaches to explore which security controls matter most, which may be overrated, and
Best Open-Source Agent Harnesses for Local LLMs in 2026
Which open-source harness works with Ollama, LM Studio, or llama.cpp? 11 verified picks with licenses and setup rules. The post Best Open-Source Agent Harnesses for Local LLMs in 2026 appeared first on MarkTechPost.
CVE-2026-93738 - Totolink A3002MU formSchedule buffer overflow
CVE ID :CVE-2026-93738 Published : Sept. 18, 2026, 9:18 p.m. | 3 hours, 11 minutes ago Description :A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a
CVE-2026-93740 - Totolink A3002MU formWlEncrypt buffer overflow
CVE ID :CVE-2026-93740 Published : Sept. 18, 2026, 10:17 p.m. | 2 hours, 7 minutes ago Description :A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The ma
CVE-2026-75885 - Openshift/console: openshift/console: unauthenticated ssrf and resource exhaustion via devfile parser endpoint
CVE ID :CVE-2026-75885 Published : Sept. 18, 2026, 10:17 p.m. | 2 hours, 12 minutes ago Description :A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attack
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0.
Microsoft Teams will let admins block custom file extensions
Microsoft Teams will soon let administrators tweak the list of file extensions commonly associated with security threats to meet their company's security requirements. [...]
Schneider Electric Modicon M340 Controller and Communication Modules
View CSAF Summary Schneider Electric is aware of a vulnerability in its Modicon M340 https://www.se.com/ww/en/product-range/1468-modicon-m340-pac/, BMXNOR0200H https://www.se.com/us/en/product/BMXNOR0200H/communication-module-modicon-m340-iec-6087051
In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
Noteworthy stories that might have slipped under the radar: Mandiant's 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited. The post In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack
AI Agent Breaches Spanish Organization, Modifies Personal Data
AI-driven cyberattacks used to be exotic. Soon, it'll be odd if threat actors aren't using agents to do all of their bidding.
CVE-2026-93921 - SiYuan through 3.8.4 Access Control Bypass via Dynamic Icon Endpoint
CVE ID :CVE-2026-93921 Published : Sept. 18, 2026, 11:12 p.m. | 1 hour, 12 minutes ago Description :SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access docume
CVE-2026-93739 - Totolink A3002MU formWlAc buffer overflow
CVE ID :CVE-2026-93739 Published : Sept. 18, 2026, 10:17 p.m. | 2 hours, 12 minutes ago Description :A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a ma
Salesforce Agentforce: Bridging the Enterprise AI Gap from ‘Vibe Coding’ to Battle-Tested Orchestration
Building an AI prototype is easy, but operating autonomous agents at scale requires production-grade tooling. Salesforce Agentforce bridges the gap from "vibe coding" to enterprise reliability by combining synthetic stress-testing, real-time optimiza
CVE-2026-93923 - SiYuan through 3.8.4 Stored XSS via Heading Style Attribute
CVE ID :CVE-2026-93923 Published : Sept. 18, 2026, 11:12 p.m. | 1 hour, 12 minutes ago Description :SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Att
CVE-2026-88097 - Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE ID :CVE-2026-88097 Published : Sept. 18, 2026, 9:18 p.m. | 3 hours, 11 minutes ago Description :Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally. Severity: 8.1 | HIGH Visit the link f
Cisco Zero-Day Highlights API Endpoint Authentication Issues
The authentication bypass flaw CVE-2026-76460 impacts Cisco's Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.
[webapps] CubeCart 6.7.4 - Stored XSS
CubeCart 6.7.4 - Stored XSS
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler ThreatLabz
CVE-2026-77875 - Hide Photos - Secure vault 4.1.0 - Insecure storage of vault media and wallet records in shared external storage
CVE ID :CVE-2026-77875 Published : Sept. 18, 2026, 11:29 p.m. | 54 minutes ago Description :The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary. A local actor w
23 Million User Records Compromised in Gyazo Data Breach
Gyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access. The post 23 Million User Records Compromised in Gyazo Data Breach appeared first on SecurityWeek.
Meet the Writer: Hacker Noon's Contributor Atindra Girish, Cyber Security Enthusiast
No tech degree, no theory background: Atindra Girish writes deep dives to force himself to learn cybersecurity properly.
CVE-2026-93922 - SiYuan through 3.8.4 Stored XSS via notebook names
CVE ID :CVE-2026-93922 Published : Sept. 18, 2026, 11:12 p.m. | 1 hour, 12 minutes ago Description :SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the
🧠 AI/ML
30Jina AI Releases jina-ocr-v1: A 3.4B MoE Document Parser With Built-In Speculative Decoding for Low-Budget GPUs
Jina AI has released jina-ocr-v1, a visual document parser that converts PDFs, scans, tables, charts and invoices into Markdown. The model has 3.4B total parameters, with about 570M active per token, and builds on DeepSeek-OCR. A built-in FastMTP spe
Generate Images with Claude and Hugging Face
AI-Assisted Software Development at Scale: From Code Generation to Engineering Agents
Explore how generative AI supports enterprise refactoring, testing and CI/CD, and why validation and engineering oversight remain essential.
Arm & ExecuTorch 0.7: Bringing Generative AI to the masses
How ChatGPT adoption broadened in early 2026
ChatGPT adoption surged in Q1 2026, with fastest growth among users over 35 and more balanced gender usage, signaling broader mainstream AI adoption.
New experts join Google’s AI & Economy team
We are expanding our AI & Economy team with world-class academic advisors, fellows, and core internal researchers.
PrismML Releases Ternary Bonsai 2 27B: A 5.9 GB Apache 2.0 Model Retaining 98.2% of Qwen3.8 27B Performance
PrismML has released Ternary Bonsai 2 27B, a ternary-weight version of Qwen3.8 27B. The language model occupies 5.93 GB, against 53.80 GB in FP16. PrismML reports that it keeps 98.2% of the parent model’s average across 20 benchmarks. The model accep
What Parameter Golf taught us about AI-assisted research
Parameter Golf brought together 1,000+ participants and 2,000+ submissions to explore AI-assisted machine learning research, coding agents, quantization, and novel model design under strict constraints.
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone c
EY Survey Finds Autonomous AI Implementation Outpaces Oversight
A new survey of senior AI execs shows that while organizations are rapidly deploying AI and autonomous systems, their process and controls are not keeping pace.
ABB Ability Edgenius
View CSAF Summary ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fa
HP OmniBook Ultra 14 Kini Dijual Di Pasaran Tempatan – Warna Deep Espresso Eksklusif Di Harvey Norman
HP baru-baru ini telah memperkenalkan siri komputer riba HP OmniBook Ultra 14 yang dikuasakan oleh cip pemprosesan Intel Core Ultra 300 “Panther Lake”, dan yang menariknya, khusus untuk kedai elektronik Harvey Norman, mereka juga akan menjual pilihan
Anthropic is operating a lab that conducts biology experiments
AI leaders have been promising that AI is the key to curing human disease. Anthropic researchers have also been warning that AI might kill us all.
Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks
The new program expands Vectra AI's partner strategy as increasingly complex security environments and the growing use of AI create demand for broader AI expertise, services, and security outcomes.
Pad Kekunci Gaming Razer Tartarus V2 Pro Kini Ditawarkan Di Malaysia Pada Harga RM929
Jenama aksesori gaming Razer baru-baru ini telah memperkenalkan sebuah lagi aksesori gaming baru, iaitu pad kekunci gaming Razer Tartarus V2 Pro, yang merupakan sebuah pad kekunci yang tersuai dan dibina khas untuk peminat-peminat tegar genre permain
Laporan Oleh Ookla Dan OpenSignal Memperlihatkan U Mobile Sebagai Pengendali Rangkaian 5G Terbaik Di Malaysia
Sejak mengendalikan rangkaian 5G kedua Malaysia, dan memperkenalkan rangkaian ULTRA5G mereka tersendiri, U Mobile dilihat telah tampil sebagai salah satu daripada syarikat telekomunikasi tempatan yang terbaik di Malaysia, menurut laporan-laporan oleh
An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.
In July 2025, someone registered a domain that used to belong to a content delivery network. The CDN had been wound down years earlier, and the domain it served assets from was allowed to expire. What it had not lost were its callers. Thousands of we
Could AI really kill us all? Your questions, answered.
On Wednesday, MIT Technology Review hosted a live Roundtables event for subscribers that asked the question everyone’s asking right now: Could AI really kill us all? But attendees had so many more questions than we had time to answer in the 30 minute
Claude Kini Menerajui 1/4 Pembangunan Dan Penyelidikkan Untuk AI Generasi Seterusnya
Anthropic berkongsi menyatakan Claude kini menerajui 1/4 kerja-kerja pembangunan dan penyelidikkan, atau sekitar 26% tugasan. Ini sekaligus membolehkan Claude melakukan sejumlah besar tugasan dibawah pemantauan manusia dalam pembangunan AI dan teknol
Context is King: Long Live Context Engineering
Better models require less prompt engineering per task, but they also unlock higher-value results that sophisticated prompting can reach
Position: It is Time to Virtualize Foundation Models with a Self-evolving Operating System Layer
arXiv:2609.19203v1 Announce Type: new Abstract: AI applications have shifted from single, monolithic foundation models (FM) to compound agentic systems. Yet today's stacks remain fragmented: even as protocols (e.g., MCP, A2A) ease tool/agent connecti
What Happens When AI Agents Inherit Your Company’s Office Politics?
AI agents can turn conflicting departmental goals into automated decisions. How leaders can clarify priorities, authority and responsibility before deployment.
Anthropic Membentuk Makmal Untuk Kajian Biologi
Anthropic kini telah membuka sebuah makmal khusus di Amerika Syarikat, dengan tujuan memfokuskan kepada kajian dan kerja-kerja melibatkan biologi. Ini juga turut membuatkan Anthropic turut memperluaskan misi mereka melangkaui arena kecerdasan buatan
AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts. The post AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code appeared first on SecurityWeek.
AutoScout24 scales engineering with AI-powered workflows
Learn how AutoScout24 Group uses Codex and ChatGPT to speed development cycles, improve code quality, and expand AI adoption.
Alibaba Qwen Releases Qwen3.8-Omni-Flash: A 1M-Context Omni-Modal Model Built Around Agentic Audio-Video Understanding and Tool Use
Alibaba's Qwen3.8-Omni-Flash understands audio and video, plans tasks, calls tools, and reports about 45.7% fewer tokens on OmniVideoBench. The post Alibaba Qwen Releases Qwen3.8-Omni-Flash: A 1M-Context Omni-Modal Model Built Around Agentic Audio-Vi
Tilly Norwood’s press tour is going about as well as you’d expect for an AI
In one particularly odd interview, Norwood seems to malfunction and begin speaking Chinese.
What Do We Expect from LLMs? Mapping the Design of LLM Benchmarks
arXiv:2609.19182v1 Announce Type: new Abstract: Benchmarks are central to how progress in large language models (LLMs) is assessed and communicated. Yet model rankings alone reveal little about how evaluation requirements themselves are changing. The
AI hallucination nearly triggers US military operation
“It’s important for service members to understand the uncertainty inherent to LLMs," a GovAI research scholar warns.
Hex turns complex analysis into visual reports with GPT‑6 Astra
GPT-6 Astra helps Hex’s data agents turn answers into interactive visualizations that employees are proud to share.
⚡ Tech/Dev
12CVE-2026-68928 - Acode: Exported TerminalService (bundled terminal plugin) lets any installed app execute arbitrary shell commands as Acode
CVE ID :CVE-2026-68928 Published : Sept. 18, 2026, 9:17 p.m. | 3 hours, 12 minutes ago Description :Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an
Co-creating the future of fashion with Google
Google worked side-by-side with designers Jane Wade and Sergio Hudson to custom-design Google Flow tools to prep for NYFW.
[webapps] Langflow 1.8.4 - Path Traversal to Remote Code Execution
Langflow 1.8.4 - Path Traversal to Remote Code Execution
Secure enterprise sharing with access reviews for Microsoft 365
Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. tenfold Software explains how centralized access governance
A startup that builds other startups raised $100M, and is all-in on physical AI
UP.Labs, now doing business under the name Vantora, is building startups for industrial corporations.
Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. [...]
[webapps] CubeCart 6.7.4 - Cross-Site Scripting
CubeCart 6.7.4 - Cross-Site Scripting
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine. Kernel maintainers have fixed all four over the past few weeks, so a system running an
Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority. The post Microsoft Patches 18 Vulnerabilities in AI, Cloud Products appeared first on SecurityWeek.
[webapps] Linksys E1200_2.0.04 - Unauthenticated OS Command Injection
Linksys E1200_2.0.04 - Unauthenticated OS Command Injection
Schneider Electric PowerChute Serial Shutdown
View CSAF Summary Schneider Electric is aware of vulnerabilities in its PowerChute Serial Shutdown product. The PowerChute Serial Shutdown product is a UPS management software enabling graceful system shutdown and energy management capabilities for d
NightmareStresser DDoS Service Disrupted in International Operation
Active since at least 2022, NightmareStresser was one of the longest-running DDoS-for-hire services in the world. The post NightmareStresser DDoS Service Disrupted in International Operation appeared first on SecurityWeek.
📌 Lain-lain
5From Zero to GPU: A Guide to Building and Scaling Production-Ready CUDA Kernels
MFA Won't Save You From OAuth Consent Abuse
MFA is essential, but it cannot replace OAuth governance, least-privilege scopes, consent monitoring, and rapid revocation.
CT3 to Participate as Speaker at CoinFerenceX Singapore 2026
Participation in the conference will be an important step for CT3 in increasing the project’s visibility and attracting greater attention from
Kimina-Prover-RL
Anthropic’s first embedded evaluator is … Accenture?
Accenture is about to take on its most high-risk consulting engagement ever.
🔬 Science/Research
5Regularized Emphatic Temporal-Difference Learning: Stability under Constant Stepsizes
arXiv:2609.19170v1 Announce Type: new Abstract: Emphatic temporal-difference learning (ETD) stabilizes the expected off-policy TD update and changes its projection geometry, but neither property determines constant-stepsize sampled dynamics. We const
What Do Current Systematic Generalization Tasks Miss? A Reasoning-Centered Analysis
arXiv:2609.19212v1 Announce Type: new Abstract: Systematic generalization, the ability to solve novel problems by recombining known atomic elements, is central to human intelligence but difficult to study rigorously under controlled settings. Existin
BioPhys-Bridge: A Benchmark for Interdisciplinary Scientific Reasoning in Physics-Grounded Biological Research
arXiv:2609.19180v1 Announce Type: new Abstract: Language models face unique challenges in analyzing interdisciplinary scientific research literature. In biophysics research, faithful answers require grounding observed data in source evidence, interpr
How NVIDIA engineers and researchers build with Codex
Teams use Codex with GPT-5.5 to ship production systems and turn research ideas into runnable experiments.
MCP for Research: How to Connect AI to Research Tools