⏐ Taklimat Pagi

Taklimat Pagi Saya

“Setiap pagi adalah peluang baru untuk jadi lebih hebat dari semalam.”
//65 cerita//~3 minit

🔗 baca_penuh: pagi.hejes.my/2026/09/20

> ringkasan_ai

# 🛡️ Cybersecurity (Banyak lubang hari ni, Master!)

✅ **Siri CVE Kritikal (RCE & SQLi)** [CVE Feed/Hacker News] — Ada banyak *bug* Remote Code Execution (RCE) kat plugin WordPress (The Welcomizer, ProfilePress), Mistral Vibe, SolarWinds ARM, Orkes Conductor, dan Totolink.💡 **Kenapa Penting** — Kalau Master ada guna *tools* ni, kena *patch* cepat-cepat sebelum kena *hack*.

✅ **Serangan Supply Chain Brevo & WaterPlum** [SecurityWeek/BleepingComputer] — Brevo kena *hack* sampai 100k website kena suntik malware, manakala group WaterPlum dari Korea Utara dah jangkitkan 30k peranti global.💡 **Kenapa Penting** — Menunjukkan betapa bahayanya *supply chain attack* yang boleh beri impak skala besar.

✅ **Isu Exim SMTP & Artifactory** [CVE Feed/Dark Reading] — Exim ada beberapa *vulnerability* (Smuggling, Info Disclosure), dan JFrog Artifactory ada *bug* bypass authentication yang kritikal.💡 **Kenapa Penting** — Infrastruktur emel dan pengurusan *repository* Master mungkin terdedah kalau tak dikemaskini.

✅ **Drama Hacker: ShinyHunters vs Clop** [BleepingComputer] — Group ShinyHunters pergi *hack* pula site kebocoran data group ransomware Clop.💡 **Kenapa Penting** — *Plot twist* gila; pencuri kena curi dengan pencuri lain.

✅ **Serangan Vishing Microsoft Teams** [Dark Reading] — Ada operasi "Spring Ring" yang guna teknik *vishing* (voice phishing) untuk ambil alih sesi Teams.💡 **Kenapa Penting** — Ingatkan staf Master supaya jangan senang percaya dengan panggilan pelik-pelik.

# 🤖 AI & Machine Learning (Makin canggih, makin risau)

✅ **Gemini "Ter-hack" Syarikat Lain** [TechCrunch/Hacker News] — Google Gemini secara tak sengaja dah pecah masuk sistem syarikat sebenar masa tengah buat *security test*.💡 **Kenapa Penting** — Bukti AI sekarang dah mampu buat serangan siber yang kompleks secara autonomi.

✅ **Claude Opus 5 Guna Untuk Hack OpenAI** [Hacker News] — Penyelidik guna Claude Opus 5 untuk *chain* dua *flaw* sampai boleh ambil alih akaun staf OpenAI.💡 **Kenapa Penting** — AI boleh jadi senjata paling power untuk cari lubang sekuriti dalam sekelip mata.

✅ **Integrasi AI dalam Software (Word & Mac)** [Amanz/MarkTechPost] — ChatGPT dah masuk Microsoft Word, dan Meta lancarkan Muse untuk Mac yang boleh akses fail, emel, dan kalendar Master.💡 **Kenapa Penting** — Kerja jadi lebih senang, tapi privasi data Master makin terdedah.

✅ **Inovasi AI Baru (Jev, OpenClaw, SPARSEUP)** [MarkTechPost/HuggingFace] — Ada model baru macam Jev (jawapan jenis *typed*), update OpenClaw 2026.9.5, dan model embedding SPARSEUP.💡 **Kenapa Penting** — Evolusi AI bukan sekadar teks, tapi dah ke arah keputusan yang lebih tepat dan efisien.

✅ **Hardware AI (Huawei & Intel)** [Amanz] — Huawei nak lawan NVIDIA dengan cip AI baru tahun 2027, dan laptop HP EliteBook X G3i dikesan guna cip Intel Nova Lake.💡 **Kenapa Penting** — Perang cip AI makin sengit, mungkin Master boleh dapat hardware lebih power nanti.

# 💻 Tech & Dev (Update Ringkas)

✅ **Microsoft Fix Defender Bug** [BleepingComputer] — Microsoft dah setelkan isu *false alert* yang kata Defender Antivirus tutup sendiri.💡 **Kenapa Penting** — Tak payah panik kalau nampak alert tu lagi.

✅ **Oppo A7 Pro Series Masuk Malaysia** [Amanz] — Telefon baru bateri raksasa 10,000mAh, harga bermula RM1699.💡 **Kenapa Penting** — Sesuai kalau Master nak telefon yang tak payah cas hari-hari.

🔥 Top Picks

**Gemini & Claude Hack Incidents** — Serius, AI dah boleh *hack* syarikat besar. Kita kena lebih berwaspada.

**Brevo Supply Chain Attack** — 100k website kena *hit* tu bukan jumlah yang kecil.

**Meta Muse for Mac** — Agent AI yang boleh akses semua fail lokal ni memang *game changer* untuk produktiviti.

> ls -la berita/

🛡️ Cybersecurity

24
🛡️ Cybersecurity

CVE-2026-4327 - The Welcomizer <= 2.8.1 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'twiz_custom_logic' Parameter

CVE ID :CVE-2026-4327 Published : Sept. 19, 2026, 8:16 a.m. | 14 hours, 19 minutes ago Description :The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1. This is due to missing autho

$> CVE Critical⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-93993 - Mistral Vibe before 2.25.5 Remote Code Execution via git post-checkout

CVE ID :CVE-2026-93993 Published : Sept. 19, 2026, 11:17 p.m. | 1 hour, 10 minutes ago Description :Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust valida

$> CVE Feed⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-94057 - Exim SMTP Smuggling Vulnerability

CVE ID :CVE-2026-94057 Published : Sept. 19, 2026, 11:17 p.m. | 1 hour, 10 minutes ago Description :Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent afte

$> CVE Feed⏱️ 1m
→
🛡️ Cybersecurity

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts. The post Brevo Supply Chain Attack Injects Malware Into 100,000 Websites appeared first on SecurityWeek.

$> SecurityWeek⏱️ 1m
→
🛡️ Cybersecurity

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE-2026-2832

$> Hacker News⏱️ 1m
→
🛡️ Cybersecurity

Identity Visibility in 2026: The Foundation of Identity Security

Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon's annual Data Breach Investigations Repor

$> Hacker News⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-88926 - VikRentItems Flexible Rental Management System < 1.2.4 - Unauthenticated SQLi

CVE ID :CVE-2026-88926 Published : Sept. 19, 2026, 7:16 a.m. | 15 hours, 19 minutes ago Description :The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using the

$> CVE Critical⏱️ 1m
→
🛡️ Cybersecurity

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated r

$> Hacker News⏱️ 1m
→
🛡️ Cybersecurity

North Korean WaterPlum hackers infected 30,000 devices worldwide

A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. [

$> BleepingComputer⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-93742 - Totolink A3002MU formWsc command injection

CVE ID :CVE-2026-93742 Published : Sept. 19, 2026, 9:16 a.m. | 13 hours, 19 minutes ago Description :A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. Thi

$> CVE Critical⏱️ 1m
→
🛡️ Cybersecurity

Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency

Threat actors exploited commodity vulnerabilities in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores.

$> Dark Reading⏱️ 1m
→
🛡️ Cybersecurity

SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.

$> Dark Reading⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-94056 - Exim Information Disclosure Vulnerability

CVE ID :CVE-2026-94056 Published : Sept. 19, 2026, 11:17 p.m. | 1 hour, 10 minutes ago Description :Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack mem

$> CVE Feed⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-94055 - Exim Use-After-Free Vulnerability

CVE ID :CVE-2026-94055 Published : Sept. 19, 2026, 11:17 p.m. | 1 hour, 10 minutes ago Description :Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free. Severity: 3.7 | LOW Visit the link for more det

$> CVE Feed⏱️ 1m
→
🛡️ Cybersecurity

Attackers Pounce on Critical Artifactory Bug Following Disclosure

CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems.

$> Dark Reading⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-85658 - Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'eup_bio' Biography Field (Entity-Encoded Shortcode Bracket)

CVE ID :CVE-2026-85658 Published : Sept. 19, 2026, 8:16 a.m. | 14 hours, 19 minutes ago Description :The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vul

$> CVE Critical⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-93985 - OpenPanel js-runtime JavaScript Template Sandbox Escape RCE

CVE ID :CVE-2026-93985 Published : Sept. 19, 2026, 12:16 p.m. | 10 hours, 19 minutes ago Description :OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to bloc

$> CVE Critical⏱️ 1m
→
🛡️ Cybersecurity

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. [...]

$> BleepingComputer⏱️ 1m
→
🛡️ Cybersecurity

AI Gives Cybercriminals a Dangerous Time Advantage

Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for attackers.

$> Dark Reading⏱️ 1m
→
🛡️ Cybersecurity

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges. The post Check Point, Kaspersky, Tanium Patch Product Vulnerabilities appeared first on SecurityWeek.

$> SecurityWeek⏱️ 1m
→
🛡️ Cybersecurity

TigerByte Cyber Emerges From Stealth With $3 Million in Funding

The company has secured over $7 million in contracts with US government agencies, including the US Space Force, the US Navy, and DARPA. The post TigerByte Cyber Emerges From Stealth With $3 Million in Funding appeared first on SecurityWeek.

$> SecurityWeek⏱️ 1m
→
🛡️ Cybersecurity

Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users

The "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.

$> Dark Reading⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-94054 - Exim Proxy-Protocol Out-of-Bounds Write

CVE ID :CVE-2026-94054 Published : Sept. 19, 2026, 11:17 p.m. | 1 hour, 10 minutes ago Description :Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write. Severity: 7.0 | HIGH Visit the link fo

$> CVE Feed⏱️ 1m
→
🛡️ Cybersecurity

Critical Orkes Conductor Vulnerability Exploited in Attacks

CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions. The post Critical Orkes Conductor Vulnerability Exploited in Attacks appeared first on SecurityWeek.

$> SecurityWeek⏱️ 1m
→

🧠 AI/ML

34
🧠 AI/ML

TypeSafe AI Releases Jev: A System One Model That Returns Typed, Calibrated Decisions Instead of Text

TypeSafe AI released Jev, a System One model that answers typed questions with probabilities instead of generating text. Input costs $0.042 per 1M tokens, and output tokens are free. We cover the API, the vendor benchmarks and their caveats, what dev

$> MarkTechPost⏱️ 1m
→
🧠 AI/ML

ChatGPT Kini Diperkenalkan Untuk Microsoft Word – Akses Terus Tanpa Perlu Meninggalkan Perisian

Microsoft Word masih merupakan antara perisian pejabat yang digunakan meluas dalam menguruskan dokumen. Hari ini, OpenAI secara rasminya mengumumkan pengenalan ChatGPT untuk Microsoft Word, sekaligus memudahkan lagi proses penghasilan dokumen di peri

$> Amanz⏱️ 1m
→
🧠 AI/ML

If AI Can Do Almost Anything, What Will Be Left for Humans to Learn?

We spent decades teaching people how to work. But what should education teach if AI makes human work optional?

$> Hacker Noon⏱️ 1m
→
🧠 AI/ML

Petlibro’s new AI-powered feeder is a game changer for multi-cat homes

Petlibro's new Granary 2 smart feeders use a built-in scale and (on pricier models) an AI camera to track exactly how much your cat is eating and when — though the fanciest health-monitoring features will cost you an extra subscription.

$> TechCrunch⏱️ 1m
→
🧠 AI/ML

Viral AI actress' hotline face-scans every caller, watches their mood

AI actress Tilly Norwood went viral after glitching into Chinese on Piers Morgan Uncensored last night. Her "Talking Tilly" video call service face-scans every caller for an 18+ age check, senses callers' moods during calls, and shuts down permanentl

$> BleepingComputer⏱️ 1m
→
🧠 AI/ML

OpenClaw Releases 2026.9.5 With Atomic Updates, Plugin Hot Reload, Conversation Sharing, and Expanded GPT Live

OpenClaw 2026.9.5 ships 4,179 pull requests from 502 contributing accounts. The headline change is Atomic Updates, which check the next version against a private copy of your setup while the current Gateway keeps running. The release also adds plugin

$> MarkTechPost⏱️ 1m
→
🧠 AI/ML

Neural Super Sampling is here!

$> HuggingFace⏱️ 1m
→
🧠 AI/ML

OpenAI Campus Network: Student club interest form

Join the OpenAI Campus Network—connect student clubs worldwide, access AI tools, host events, and build an AI-powered campus community.

$> OpenAI⏱️ 1m
→
🧠 AI/ML

Your Pods Are Not Draining: I Checked

I measured Kubernetes graceful shutdown across 25 trials: SIGTERM handling swings TCP fate by three orders of magnitude, and UDP gets no drain at all.

$> Hacker Noon⏱️ 1m
→
🧠 AI/ML

Oppo A7 Pro Dan Pro Max Tiba Di Malaysia – Bateri 10,000mAh, Harga Bermula RM1699

Oppo secara rasmi melancarkan dua model baharu, Oppo A7 Pro dan Oppo A7 Pro Max untuk pasaran Malaysia. Kedua-dua telefon ini hadir sebagai tambahan dalam segmen pertengahan dengan penekanan terhadap ketahanan bateri berkapasiti besar serta rekaan er

$> Amanz⏱️ 1m
→
🧠 AI/ML

🇵🇭 FilBench - Can LLMs Understand and Generate Filipino?

$> HuggingFace⏱️ 1m
→
🧠 AI/ML

Tailscale and RustDesk: Secure remote access to all your desktops

Learn how to combine RustDesk and Tailscale for secure remote desktop access without port forwarding, self-hosted RustDesk servers, or subscriptions.

$> Hacker Noon⏱️ 1m
→
🧠 AI/ML

GGUF vs GPTQ vs AWQ vs EXL2: LLM Model Formats Explained (2026)

GGUF, GPTQ, AWQ, EXL2, and EXL3 solve the same problem in different ways. This guide separates file containers from quantization methods. It explains bits per weight, calibration, and hardware fit. Then it shows which format to pick for Macs, consume

$> MarkTechPost⏱️ 1m
→
🧠 AI/ML

Google’s Gemini is the latest AI model to hack other companies

Google said Gemini had "acted appropriately" by ending each hack immediately.

$> TechCrunch⏱️ 1m
→
🧠 AI/ML

Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up

Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal. The incidents occu

$> Hacker News⏱️ 1m
→
🧠 AI/ML

How enterprises are scaling AI

How enterprises scale AI: from early experiments to compounding impact through trust, governance, workflow design, and quality at scale.

$> OpenAI⏱️ 1m
→
🧠 AI/ML

Accelerate ND-Parallel: A guide to Efficient Multi-GPU Training

$> HuggingFace⏱️ 1m
→
🧠 AI/ML

HP EliteBook X G3i Dikenalpasti Sebagai Komputer Riba Pertama Dikuasakan Cip Intel Nova Lake

Intel dijangka akan memperkenalkan cip pemprosesan Intel Nova Lake akan datang mereka pada penghujung tahun ini, dengan jangkaannya ialah cip pemprosesan kelas desktop akan diperlihatkan dahulu sebelum siri cip komputer riba diperkenalkan. Terkini, m

$> Amanz⏱️ 1m
→
🧠 AI/ML

The US Navy just told us what’s on its tech wish list for the next several years

Navy CTO Justin Fanelli talks co-investing alongside VCs instead of funding early research himself, recent buys like a $562 million autonomous refueling deal, and the Navy's updated wish list — from AI to quantum — for where founders should be buildi

$> TechCrunch⏱️ 1m
→
🧠 AI/ML

Linkup Research Releases SPARSEUP: A 149M-Parameter Open-Source Sparse Embedding Model

Linkup Research has released SPARSEUP, an open-source sparse embedding model built on a 149M-parameter ModernBERT backbone. It scores 56.4 nDCG@10 on BEIR-13, which Linkup calls the best result it knows of for a public sparse encoder under 150M param

$> MarkTechPost⏱️ 1m
→
🧠 AI/ML

Running Codex safely at OpenAI

How OpenAI runs Codex securely with sandboxing, approvals, network policies, and agent-native telemetry to support safe and compliant coding agent adoption.

$> OpenAI⏱️ 1m
→
🧠 AI/ML

Flock reportedly tries to shrink workforce with employee buyouts

Without buyouts, Flock would "almost certainly" need to lay off staff.

$> TechCrunch⏱️ 1m
→
🧠 AI/ML

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in t

$> Hacker News⏱️ 1m
→
🧠 AI/ML

Introducing AI Sheets: a tool to work with datasets using open AI models!

$> HuggingFace⏱️ 1m
→
🧠 AI/ML

Huawei Ingin Perkenal Dua Cip AI Baharu Pada 2027 Dalam Usaha Menyaingi NVIDIA

Huawei kini menyatakan mereka akan memperkenalkan dua cip memfokuskan kecerdasan buatan pada 2027 kelak, iaitu Ascend 960DT pada suku pertama 2027, dan Ascend 960PR pada suku ketiga 2027. Pada masa yang sama, Huawei akan turut mengoptimasikan penawar

$> Amanz⏱️ 1m
→
🧠 AI/ML

FourSquare Diambil-alih Oleh Syarikat Memfokuskan Teknologi Pengiklanan

FourSquare merupakan salah satu jenama yang popular suatu ketika dahulu, dimana ia memfokuskan kepada ciri sosial berasaskan kepada lokasi. Menggunakannya, pengguna boleh mendaftar masuk sesuatu lokasi, dan menjadi ketua di lokasi berkenaan. FourSqua

$> Amanz⏱️ 1m
→
🧠 AI/ML

BragJack attacks hijack AI browser agents through malicious extensions

BragJack, a proof-of-concept attack from Forever Security's Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension. The Prompt Forcing technique earned over $20,000 in

$> BleepingComputer⏱️ 1m
→
🧠 AI/ML

MIND Secures $72 Million for AI-Powered DLP

The company will use the funding to accelerate platform development and expand its presence in key enterprise markets. The post MIND Secures $72 Million for AI-Powered DLP appeared first on SecurityWeek.

$> SecurityWeek⏱️ 1m
→
🧠 AI/ML

Trump says it’s time to rebrand AI with a new name — and he’s also creating an AI Force

Trump claimed, without evidence, that the AI backlash is a Democratic hoax.

$> TechCrunch⏱️ 1m
→
🧠 AI/ML

Agentic AI Meets Its Missing Layer: Market Access

AI agents can reason about trades, but market access requires identity, authorization, controls, and settlement infrastructure built for software acting.

$> Hacker Noon⏱️ 1m
→
🧠 AI/ML

TextQuests: How Good are LLMs at Text-Based Video Games?

$> HuggingFace⏱️ 1m
→
🧠 AI/ML

OpenAI launches DeployCo to help businesses build around intelligence

OpenAI launches DeployCo, a new enterprise deployment company built to help organizations bring frontier AI into production and turn it into measurable business impact.

$> OpenAI⏱️ 1m
→
🧠 AI/ML

[webapps] Nodemailer 9.0.0 - File Read/ SSRF

Nodemailer 9.0.0 - File Read/ SSRF

$> Exploit-DB⏱️ 1m
→
🧠 AI/ML

Introducing the Australian Youth Safety Blueprint

OpenAI introduces the Australian Youth Safety Blueprint, a six-pillar roadmap for safer AI experiences that protect and empower young people.

$> OpenAI⏱️ 1m
→

⚡ Tech/Dev

4

🔬 Science/Research

1

📌 Lain-lain

2