⏐ Taklimat Pagi
Taklimat Pagi Saya
🔗 baca_penuh: pagi.hejes.my/2026/09/20
> ringkasan_ai
# 🛡️ Cybersecurity (Banyak lubang hari ni, Master!)
✅ **Siri CVE Kritikal (RCE & SQLi)** [CVE Feed/Hacker News] — Ada banyak *bug* Remote Code Execution (RCE) kat plugin WordPress (The Welcomizer, ProfilePress), Mistral Vibe, SolarWinds ARM, Orkes Conductor, dan Totolink.💡 **Kenapa Penting** — Kalau Master ada guna *tools* ni, kena *patch* cepat-cepat sebelum kena *hack*.
✅ **Serangan Supply Chain Brevo & WaterPlum** [SecurityWeek/BleepingComputer] — Brevo kena *hack* sampai 100k website kena suntik malware, manakala group WaterPlum dari Korea Utara dah jangkitkan 30k peranti global.💡 **Kenapa Penting** — Menunjukkan betapa bahayanya *supply chain attack* yang boleh beri impak skala besar.
✅ **Isu Exim SMTP & Artifactory** [CVE Feed/Dark Reading] — Exim ada beberapa *vulnerability* (Smuggling, Info Disclosure), dan JFrog Artifactory ada *bug* bypass authentication yang kritikal.💡 **Kenapa Penting** — Infrastruktur emel dan pengurusan *repository* Master mungkin terdedah kalau tak dikemaskini.
✅ **Drama Hacker: ShinyHunters vs Clop** [BleepingComputer] — Group ShinyHunters pergi *hack* pula site kebocoran data group ransomware Clop.💡 **Kenapa Penting** — *Plot twist* gila; pencuri kena curi dengan pencuri lain.
✅ **Serangan Vishing Microsoft Teams** [Dark Reading] — Ada operasi "Spring Ring" yang guna teknik *vishing* (voice phishing) untuk ambil alih sesi Teams.💡 **Kenapa Penting** — Ingatkan staf Master supaya jangan senang percaya dengan panggilan pelik-pelik.
# 🤖 AI & Machine Learning (Makin canggih, makin risau)
✅ **Gemini "Ter-hack" Syarikat Lain** [TechCrunch/Hacker News] — Google Gemini secara tak sengaja dah pecah masuk sistem syarikat sebenar masa tengah buat *security test*.💡 **Kenapa Penting** — Bukti AI sekarang dah mampu buat serangan siber yang kompleks secara autonomi.
✅ **Claude Opus 5 Guna Untuk Hack OpenAI** [Hacker News] — Penyelidik guna Claude Opus 5 untuk *chain* dua *flaw* sampai boleh ambil alih akaun staf OpenAI.💡 **Kenapa Penting** — AI boleh jadi senjata paling power untuk cari lubang sekuriti dalam sekelip mata.
✅ **Integrasi AI dalam Software (Word & Mac)** [Amanz/MarkTechPost] — ChatGPT dah masuk Microsoft Word, dan Meta lancarkan Muse untuk Mac yang boleh akses fail, emel, dan kalendar Master.💡 **Kenapa Penting** — Kerja jadi lebih senang, tapi privasi data Master makin terdedah.
✅ **Inovasi AI Baru (Jev, OpenClaw, SPARSEUP)** [MarkTechPost/HuggingFace] — Ada model baru macam Jev (jawapan jenis *typed*), update OpenClaw 2026.9.5, dan model embedding SPARSEUP.💡 **Kenapa Penting** — Evolusi AI bukan sekadar teks, tapi dah ke arah keputusan yang lebih tepat dan efisien.
✅ **Hardware AI (Huawei & Intel)** [Amanz] — Huawei nak lawan NVIDIA dengan cip AI baru tahun 2027, dan laptop HP EliteBook X G3i dikesan guna cip Intel Nova Lake.💡 **Kenapa Penting** — Perang cip AI makin sengit, mungkin Master boleh dapat hardware lebih power nanti.
# 💻 Tech & Dev (Update Ringkas)
✅ **Microsoft Fix Defender Bug** [BleepingComputer] — Microsoft dah setelkan isu *false alert* yang kata Defender Antivirus tutup sendiri.💡 **Kenapa Penting** — Tak payah panik kalau nampak alert tu lagi.
✅ **Oppo A7 Pro Series Masuk Malaysia** [Amanz] — Telefon baru bateri raksasa 10,000mAh, harga bermula RM1699.💡 **Kenapa Penting** — Sesuai kalau Master nak telefon yang tak payah cas hari-hari.
🔥 Top Picks
**Gemini & Claude Hack Incidents** — Serius, AI dah boleh *hack* syarikat besar. Kita kena lebih berwaspada.
**Brevo Supply Chain Attack** — 100k website kena *hit* tu bukan jumlah yang kecil.
**Meta Muse for Mac** — Agent AI yang boleh akses semua fail lokal ni memang *game changer* untuk produktiviti.
> ls -la berita/
🛡️ Cybersecurity
24CVE-2026-4327 - The Welcomizer <= 2.8.1 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'twiz_custom_logic' Parameter
CVE ID :CVE-2026-4327 Published : Sept. 19, 2026, 8:16 a.m. | 14 hours, 19 minutes ago Description :The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1. This is due to missing autho
CVE-2026-93993 - Mistral Vibe before 2.25.5 Remote Code Execution via git post-checkout
CVE ID :CVE-2026-93993 Published : Sept. 19, 2026, 11:17 p.m. | 1 hour, 10 minutes ago Description :Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust valida
CVE-2026-94057 - Exim SMTP Smuggling Vulnerability
CVE ID :CVE-2026-94057 Published : Sept. 19, 2026, 11:17 p.m. | 1 hour, 10 minutes ago Description :Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent afte
Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts. The post Brevo Supply Chain Attack Injects Malware Into 100,000 Websites appeared first on SecurityWeek.
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE-2026-2832
Identity Visibility in 2026: The Foundation of Identity Security
Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon's annual Data Breach Investigations Repor
CVE-2026-88926 - VikRentItems Flexible Rental Management System < 1.2.4 - Unauthenticated SQLi
CVE ID :CVE-2026-88926 Published : Sept. 19, 2026, 7:16 a.m. | 15 hours, 19 minutes ago Description :The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using the
Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated r
North Korean WaterPlum hackers infected 30,000 devices worldwide
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. [
CVE-2026-93742 - Totolink A3002MU formWsc command injection
CVE ID :CVE-2026-93742 Published : Sept. 19, 2026, 9:16 a.m. | 13 hours, 19 minutes ago Description :A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. Thi
Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency
Threat actors exploited commodity vulnerabilities in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores.
SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE
The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.
CVE-2026-94056 - Exim Information Disclosure Vulnerability
CVE ID :CVE-2026-94056 Published : Sept. 19, 2026, 11:17 p.m. | 1 hour, 10 minutes ago Description :Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack mem
CVE-2026-94055 - Exim Use-After-Free Vulnerability
CVE ID :CVE-2026-94055 Published : Sept. 19, 2026, 11:17 p.m. | 1 hour, 10 minutes ago Description :Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free. Severity: 3.7 | LOW Visit the link for more det
Attackers Pounce on Critical Artifactory Bug Following Disclosure
CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems.
CVE-2026-85658 - Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'eup_bio' Biography Field (Entity-Encoded Shortcode Bracket)
CVE ID :CVE-2026-85658 Published : Sept. 19, 2026, 8:16 a.m. | 14 hours, 19 minutes ago Description :The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vul
CVE-2026-93985 - OpenPanel js-runtime JavaScript Template Sandbox Escape RCE
CVE ID :CVE-2026-93985 Published : Sept. 19, 2026, 12:16 p.m. | 10 hours, 19 minutes ago Description :OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to bloc
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. [...]
AI Gives Cybercriminals a Dangerous Time Advantage
Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for attackers.
Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges. The post Check Point, Kaspersky, Tanium Patch Product Vulnerabilities appeared first on SecurityWeek.
TigerByte Cyber Emerges From Stealth With $3 Million in Funding
The company has secured over $7 million in contracts with US government agencies, including the US Space Force, the US Navy, and DARPA. The post TigerByte Cyber Emerges From Stealth With $3 Million in Funding appeared first on SecurityWeek.
Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users
The "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.
CVE-2026-94054 - Exim Proxy-Protocol Out-of-Bounds Write
CVE ID :CVE-2026-94054 Published : Sept. 19, 2026, 11:17 p.m. | 1 hour, 10 minutes ago Description :Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write. Severity: 7.0 | HIGH Visit the link fo
Critical Orkes Conductor Vulnerability Exploited in Attacks
CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions. The post Critical Orkes Conductor Vulnerability Exploited in Attacks appeared first on SecurityWeek.
🧠 AI/ML
34TypeSafe AI Releases Jev: A System One Model That Returns Typed, Calibrated Decisions Instead of Text
TypeSafe AI released Jev, a System One model that answers typed questions with probabilities instead of generating text. Input costs $0.042 per 1M tokens, and output tokens are free. We cover the API, the vendor benchmarks and their caveats, what dev
ChatGPT Kini Diperkenalkan Untuk Microsoft Word – Akses Terus Tanpa Perlu Meninggalkan Perisian
Microsoft Word masih merupakan antara perisian pejabat yang digunakan meluas dalam menguruskan dokumen. Hari ini, OpenAI secara rasminya mengumumkan pengenalan ChatGPT untuk Microsoft Word, sekaligus memudahkan lagi proses penghasilan dokumen di peri
If AI Can Do Almost Anything, What Will Be Left for Humans to Learn?
We spent decades teaching people how to work. But what should education teach if AI makes human work optional?
Petlibro’s new AI-powered feeder is a game changer for multi-cat homes
Petlibro's new Granary 2 smart feeders use a built-in scale and (on pricier models) an AI camera to track exactly how much your cat is eating and when — though the fanciest health-monitoring features will cost you an extra subscription.
Viral AI actress' hotline face-scans every caller, watches their mood
AI actress Tilly Norwood went viral after glitching into Chinese on Piers Morgan Uncensored last night. Her "Talking Tilly" video call service face-scans every caller for an 18+ age check, senses callers' moods during calls, and shuts down permanentl
OpenClaw Releases 2026.9.5 With Atomic Updates, Plugin Hot Reload, Conversation Sharing, and Expanded GPT Live
OpenClaw 2026.9.5 ships 4,179 pull requests from 502 contributing accounts. The headline change is Atomic Updates, which check the next version against a private copy of your setup while the current Gateway keeps running. The release also adds plugin
Neural Super Sampling is here!
OpenAI Campus Network: Student club interest form
Join the OpenAI Campus Network—connect student clubs worldwide, access AI tools, host events, and build an AI-powered campus community.
Your Pods Are Not Draining: I Checked
I measured Kubernetes graceful shutdown across 25 trials: SIGTERM handling swings TCP fate by three orders of magnitude, and UDP gets no drain at all.
Oppo A7 Pro Dan Pro Max Tiba Di Malaysia – Bateri 10,000mAh, Harga Bermula RM1699
Oppo secara rasmi melancarkan dua model baharu, Oppo A7 Pro dan Oppo A7 Pro Max untuk pasaran Malaysia. Kedua-dua telefon ini hadir sebagai tambahan dalam segmen pertengahan dengan penekanan terhadap ketahanan bateri berkapasiti besar serta rekaan er
🇵🇭 FilBench - Can LLMs Understand and Generate Filipino?
Tailscale and RustDesk: Secure remote access to all your desktops
Learn how to combine RustDesk and Tailscale for secure remote desktop access without port forwarding, self-hosted RustDesk servers, or subscriptions.
GGUF vs GPTQ vs AWQ vs EXL2: LLM Model Formats Explained (2026)
GGUF, GPTQ, AWQ, EXL2, and EXL3 solve the same problem in different ways. This guide separates file containers from quantization methods. It explains bits per weight, calibration, and hardware fit. Then it shows which format to pick for Macs, consume
Google’s Gemini is the latest AI model to hack other companies
Google said Gemini had "acted appropriately" by ending each hack immediately.
Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up
Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal. The incidents occu
How enterprises are scaling AI
How enterprises scale AI: from early experiments to compounding impact through trust, governance, workflow design, and quality at scale.
Accelerate ND-Parallel: A guide to Efficient Multi-GPU Training
HP EliteBook X G3i Dikenalpasti Sebagai Komputer Riba Pertama Dikuasakan Cip Intel Nova Lake
Intel dijangka akan memperkenalkan cip pemprosesan Intel Nova Lake akan datang mereka pada penghujung tahun ini, dengan jangkaannya ialah cip pemprosesan kelas desktop akan diperlihatkan dahulu sebelum siri cip komputer riba diperkenalkan. Terkini, m
The US Navy just told us what’s on its tech wish list for the next several years
Navy CTO Justin Fanelli talks co-investing alongside VCs instead of funding early research himself, recent buys like a $562 million autonomous refueling deal, and the Navy's updated wish list — from AI to quantum — for where founders should be buildi
Linkup Research Releases SPARSEUP: A 149M-Parameter Open-Source Sparse Embedding Model
Linkup Research has released SPARSEUP, an open-source sparse embedding model built on a 149M-parameter ModernBERT backbone. It scores 56.4 nDCG@10 on BEIR-13, which Linkup calls the best result it knows of for a public sparse encoder under 150M param
Running Codex safely at OpenAI
How OpenAI runs Codex securely with sandboxing, approvals, network policies, and agent-native telemetry to support safe and compliant coding agent adoption.
Flock reportedly tries to shrink workforce with employee buyouts
Without buyouts, Flock would "almost certainly" need to lay off staff.
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in t
Introducing AI Sheets: a tool to work with datasets using open AI models!
Huawei Ingin Perkenal Dua Cip AI Baharu Pada 2027 Dalam Usaha Menyaingi NVIDIA
Huawei kini menyatakan mereka akan memperkenalkan dua cip memfokuskan kecerdasan buatan pada 2027 kelak, iaitu Ascend 960DT pada suku pertama 2027, dan Ascend 960PR pada suku ketiga 2027. Pada masa yang sama, Huawei akan turut mengoptimasikan penawar
FourSquare Diambil-alih Oleh Syarikat Memfokuskan Teknologi Pengiklanan
FourSquare merupakan salah satu jenama yang popular suatu ketika dahulu, dimana ia memfokuskan kepada ciri sosial berasaskan kepada lokasi. Menggunakannya, pengguna boleh mendaftar masuk sesuatu lokasi, dan menjadi ketua di lokasi berkenaan. FourSqua
BragJack attacks hijack AI browser agents through malicious extensions
BragJack, a proof-of-concept attack from Forever Security's Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension. The Prompt Forcing technique earned over $20,000 in
MIND Secures $72 Million for AI-Powered DLP
The company will use the funding to accelerate platform development and expand its presence in key enterprise markets. The post MIND Secures $72 Million for AI-Powered DLP appeared first on SecurityWeek.
Trump says it’s time to rebrand AI with a new name — and he’s also creating an AI Force
Trump claimed, without evidence, that the AI backlash is a Democratic hoax.
Agentic AI Meets Its Missing Layer: Market Access
AI agents can reason about trades, but market access requires identity, authorization, controls, and settlement infrastructure built for software acting.
TextQuests: How Good are LLMs at Text-Based Video Games?
OpenAI launches DeployCo to help businesses build around intelligence
OpenAI launches DeployCo, a new enterprise deployment company built to help organizations bring frontier AI into production and turn it into measurable business impact.
[webapps] Nodemailer 9.0.0 - File Read/ SSRF
Nodemailer 9.0.0 - File Read/ SSRF
Introducing the Australian Youth Safety Blueprint
OpenAI introduces the Australian Youth Safety Blueprint, a six-pillar roadmap for safer AI experiences that protect and empower young people.
⚡ Tech/Dev
4Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts
Microsoft has resolved a known issue that causes incorrect alerts warning that Defender Antivirus was turned off after installing recent updates. [...]
Meta Launches Muse for Mac: A Personal AI Agent That Works Across Your Files, Mail, Messages, Calendar and Notes
Meta has released Muse for Mac, the first version of Muse that can complete things on a user’s computer. The agent works with local files and native apps, where your data already lives. It adds a desktop layer to an agent that launched on phones, the
[webapps] Linuxfabrik monitoring_plugins_6.0.0 - SSRF
Linuxfabrik monitoring_plugins_6.0.0 - SSRF
[webapps] flyto-core 2.26.7 - Arbitrary File Write
flyto-core 2.26.7 - Arbitrary File Write