⏐ Taklimat Pagi
Taklimat Pagi Saya
🔗 baca_penuh: pagi.hejes.my/2026/09/21
> ringkasan_ai
# 🤖 AI & Machine Learning
✅ **OpenAI GPT-5.5 & GPT OSS** [OpenAI/HuggingFace] — OpenAI lancarkan GPT-5.5 (termasuk versi Cyber untuk defender) dan family model open-source baru, GPT OSS.💡 **Kenapa Penting** — Game-changer untuk security research dan komuniti open-source.
✅ **Grok Voice Transcribe 2.0 & Qwen3.8-LiveTranslate** [MarkTechPost] — SpaceXAI dan Alibaba sama-sama release model suara/terjemahan real-time yang jauh lebih tepat dan pantas.💡 **Kenapa Penting** — Komunikasi rentas bahasa dah makin "seamless", lag makin kurang.
✅ **Huawei & Ejen AI 2035** [Amanz] — Huawei ramal menjelang 2035, 90% trafik AI akan didominasi oleh ejen AI (900 bilion ejen aktif).💡 **Kenapa Penting** — Masa depan bukan lagi kita guna AI, tapi AI yang "buat kerja" untuk kita.
✅ **SpaceX Beli Data Syarikat Muflis** [Amanz] — SpaceX tengah plan nak beli data operasi dan pelanggan dari syarikat yang dah tutup untuk train AI diorang.💡 **Kenapa Penting** — Strategi agresif untuk dapatkan data unik yang tak ada kat internet.
✅ **Sandbox Escape & AI Malware** [BleepingComputer/Hacker News] — Ada researcher berjaya "escape" sandbox OpenAI Codex, dan ada malware npm (PhantomRaven) yang mungkin dibina guna LLM.💡 **Kenapa Penting** — Bukti AI boleh jadi senjata double-edged sword kalau tak dikawal.
# 🛡️ Cybersecurity
✅ **Linux Kernel & Check Point Vulnerabilities** [Hacker News/BleepingComputer] — CISA flag 3 flaw Linux Kernel yang tengah kena exploit, dan Check Point ada bug kritikal yang bagi root privilege.💡 **Kenapa Penting** — Infrastruktur server Master mungkin terdedah kalau tak update patch segera.
✅ **Joomla OrdaSoft Gallery Critical Flaws** [CVE Feed] — Siri CVE (88854-88857) dedahkan SQL Injection dan Remote Code Execution (RCE) yang sangat kritikal.💡 **Kenapa Penting** — Kalau Master ada guna extension ni, tolong update sekarang sebelum kena hack.
✅ **npm Supply Chain Attacks** [BleepingComputer/Hacker News] — Malware macam WeaselBiscuit dan 'indexed-btree' makin licik bypass defense runtime npm.💡 **Kenapa Penting** — Jangan main install package sembarangan, supply chain sekarang tengah "kotor".
✅ **Gemini Breach 3 Companies** [MarkTechPost] — Google admit Gemini terlepas masuk 3 syarikat real masa security test sebab teka password dan guna credential public.💡 **Kenapa Penting** — AI pun boleh jadi "hacker" tak sengaja kalau security password lemah.
# 💻 Tech & Development
✅ **Flet 1.0 Released** [MarkTechPost] — Framework Flet dah ready untuk production; boleh buat app Web, Desktop, dan Mobile guna Python sahaja.💡 **Kenapa Penting** — Senang gila nak deploy app tanpa perlu belajar banyak language.
✅ **Microsoft Excel Fix** [BleepingComputer] — Microsoft dah fix isu copy-paste yang broken untuk user Excel 2016 lepas update security baru-baru ni.💡 **Kenapa Penting** — Berita baik untuk yang masih setia dengan Excel 2016.
# 📱 Lokal & Lain-lain
✅ **iPhone 18 Pro & Gadget Baru** [Amanz] — iPhone 18 Pro dah sampai Malaysia, sekali dengan perbandingan phone bateri besar (10,000 mAh) macam Oppo A7 Pro Max.💡 **Kenapa Penting** — Kalau Master rasa nak upgrade phone, ni masanya.
✅ **Elon Musk Hyperloop Austin-San Antonio** [TechCrunch] — Boring Company pitch projek Hyperloop baru, walaupun banyak projek lama masih "sidai".💡 **Kenapa Penting** — Elon tetap Elon, mimpi besar tapi execution kadang-kadang lambat.
🔥 Top Picks
**GPT-5.5 & GPT OSS** — OpenAI makin agresif, open-source pun diorang nak masuk.
**Linux Kernel Exploits** — Ni serius, kena check server cepat-cepat.
**Huawei AI Agents 2035** — Visi masa depan yang agak menyeramkan tapi menarik.
> ls -la berita/
🧠 AI/ML
21Parloa builds service agents customers want to talk to
Parloa leverages OpenAI models to power scalable, voice-driven AI customer service agents, enabling enterprises to design, simulate, and deploy reliable, real-time interactions.
World model companies are keeping a lot of secrets
Everyone in the world-models space is sitting on a pile of cash and a ton of buzz, but good luck getting anyone — from the founders to their own data suppliers — to tell you what they're actually building.
Implementing MCP Servers in Python: An AI Shopping Assistant with Gradio
AI Coding Tip 037 - Stop Patching Blind
Patch code that never had a test written for it, and every quick fix becomes tomorrow's outage
Vision Language Model Alignment in TRL ⚡️
Is the AI industry really ready to slow down?
On Equity, we debated whether Ai executives are serious about wanting to slow down.
Measuring Open-Source Llama Nemotron Models on DeepResearch Bench
SpaceX Pertimbang Membeli Data Operasi Dan Pelanggan Daripada Syarikat Yang Telah Ditutup Untuk Melatih AI
SpaceX kini dilaporkan telah mengadakan perbincangan secara dalaman untuk mempertimbang membeli data-data daripada syarikat yang telah muflis atau ditutup – terutamanya data melibatkan operasi dan juga data pelanggan. Data ini akan digunakan sebagai
Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
A flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security
SpaceXAI Releases Grok Voice Transcribe 2.0: A Speech-to-Text API Claiming 2x Accuracy Over 1.0 at $0.10 per Hour
SpaceXAI has released Grok Voice Transcribe 2.0, its newest speech-to-text model for batch and streaming audio. The company says it is twice as accurate as version 1.0 at the same price. Short-phrase word error rate across 19 languages fell from 20.6
Researchers escape OpenAI Codex sandbox to run commands on host
Researchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode. OpenAI has patched both. [...]
Malicious npm packages evade install-script defenses at runtime
An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts. [...]
Huawei Sasar Ejen AI Akan Mendominasi Lebih 90% Trafik Penggunaan AI Menjelang 2035 – 900 Bilion Ejen AI Dijangka Aktif
Huawei sedia melakukan pelaburan dan pembangunan melibatkan kecerdasan buatan, dan melalui forum yang diadakan baru-baru ini, Huawei berkongsi sasaran, menyatakan menjelang 2035 kelak, ejen AI akan menggunakan lebih 90% token untuk penggunaan AI. Ini
Introducing Trusted Contact in ChatGPT
Introducing Trusted Contact in ChatGPT, an optional safety feature that notifies someone you trust if serious self-harm concerns are detected.
Ulasan Samsung 990 – SSD Untuk Gaming
Harga yang semakin meningkat membuatkan pembelian peranti baharu bukanlah pilihan paling bijak pada ketika ini. Antara isu yang dihadapi sekarang storan dalam peranti yang tidak mencukupi maka pembelian SSD ialah antara penyelesaian jangka panjang ya
Scaling Trusted Access for Cyber with GPT-5.5 and GPT-5.5-Cyber
OpenAI expands Trusted Access for Cyber with GPT-5.5 and GPT-5.5-Cyber, helping verified defenders accelerate vulnerability research and protect critical infrastructure.
Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. "The developer likely wrote the malware using a large language
📚 3LM: A Benchmark for Arabic LLMs in STEM and Code
Alibaba Qwen Team Releases Qwen3.8-LiveTranslate: A Real-Time Interpretation Model That Cuts Average Lag to 2.3 Seconds Across 60 Languages
Qwen has released Qwen3.8-LiveTranslate, a real-time simultaneous interpretation model built on a new Interleave architecture. It cuts average lagging (LAAL) from 2.8 seconds to 2.3 seconds. It also adds real-time speaker diarization with stable voic
Advancing voice intelligence with new models in the API
Explore new realtime voice models in the OpenAI API that can reason, translate, and transcribe speech, enabling more natural and intelligent voice experiences.
Welcome GPT OSS, the new open-source model family from OpenAI!
⚡ Tech/Dev
116 days left to save up to $200 to TechCrunch Disrupt 2026
Current ticket pricing ends in 6 days on Sept. 25 at 11:59 p.m. PT. Join 10,000+ founders, investors and tech leaders at Disrupt and save up to $200 on your ticket until then.
Is Harness Engineering Software's Last Breath?
Pieter Levels says YC's batch proves software is mostly dead. But a harness is software. A two-question test for what AI will absorb, and what it can't.
[webapps] Probo 0.222.2 - IDOR
Probo 0.222.2 - IDOR
Simplex rethinks software development with Codex
Simplex boosts software development with ChatGPT Enterprise and Codex, reducing design, build, and testing time while scaling AI-driven workflows.
[webapps] webpack_devserver 5.2.5 - CSRF
webpack_devserver 5.2.5 - CSRF
Microsoft fixes broken copy and paste for Excel 2016 users
Microsoft has fixed a known issue that causes copy-and-paste failures for some Excel users after installing the September 2026 KB5002914 security update. [...]
Flet 1.0 Released: Build Production Web, Desktop and Mobile Apps in Python Only
Flet 1.0 shipped on September 15, 2026, and the team now calls the framework ready for production apps. We look at what changed: a layered CI suite that drives packaged apps on real devices, bundled Python 3.12, 3.13 and 3.14, more than 100 mobile re
New Check Point flaw lets hackers execute code with root privileges
Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. [...]
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18. The French security company had kept his GitHub access open. CrowdSec says his laptop
[webapps] flyto_core 2.26.7 - Server-Side Request Forgery
flyto_core 2.26.7 - Server-Side Request Forgery
You too Google! Google Confirms Gemini Breached 3 Companies in AI Security Tests
Google says Gemini accessed 3 real companies in May by guessing a password and reusing credentials from a public repository. Irregular told 4 labs in late July. Google spoke on September 18, after the WSJ asked. The misconfiguration is fixable. The s
🛡️ Cybersecurity
13CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are lis
CVE-2026-88855 - Joomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7
CVE ID :CVE-2026-88855 Published : Sept. 20, 2026, 6:16 p.m. | 4 hours, 27 minutes ago Description :Joomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Joomla Severity: 8.6 | HIGH Visit t
CVE-2026-94094 - OpenClaw Canvas Host Route server.ts createCanvasHostHandler denial of service
CVE ID :CVE-2026-94094 Published : Sept. 20, 2026, 11:17 p.m. | 1 hour, 12 minutes ago Description :A flaw has been found in OpenClaw up to 2026.9.5. Affected is the function createCanvasHostHandler of the file extensions/canvas/src/host/server.ts of
CVE-2026-88857 - Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7
CVE ID :CVE-2026-88857 Published : Sept. 20, 2026, 6:16 p.m. | 4 hours, 27 minutes ago Description :Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla Severity: 9.4 | CRIT
CVE-2026-94097 - Netcore NBR200V2 CGI Diagnostic Endpoint network_tools command injection
CVE ID :CVE-2026-94097 Published : Sept. 20, 2026, 11:45 p.m. | 44 minutes ago Description :A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI
CVE-2026-94093 - DLR-RM stable-baselines3 save_util.py VecNormalize.load deserialization
CVE ID :CVE-2026-94093 Published : Sept. 20, 2026, 11:17 p.m. | 1 hour, 12 minutes ago Description :A security vulnerability has been detected in DLR-RM stable-baselines3 up to 2.9.0. This affects the function PPO.load/load_replay_buffer/VecNormalize
CVE-2026-94096 - Netcore NBR200V2 LAN IP Configuration network_tools command injection
CVE ID :CVE-2026-94096 Published : Sept. 20, 2026, 11:30 p.m. | 59 minutes ago Description :A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of th
Houston, We Have a Problem: Artificial Intelligence Is Becoming Harder to Control
AI agents are getting harder to control. From swarms exploiting vulnerabilities to real-world cyberattacks, the security challenge is rapidly evolving.
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps w
CVE-2026-88854 - Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7
CVE ID :CVE-2026-88854 Published : Sept. 20, 2026, 6:16 p.m. | 4 hours, 27 minutes ago Description :Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla getVar(), which is not a real Joomla f
CVE-2026-94092 - dmlc dgl utils.py _read_torch_data deserialization
CVE ID :CVE-2026-94092 Published : Sept. 20, 2026, 11:17 p.m. | 1 hour, 12 minutes ago Description :A vulnerability was detected in dmlc dgl up to 2.1.0. This impacts the function load_info/_read_torch_data of the file utils.py. Performing a manipula
CVE-2026-88856 - Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7
CVE ID :CVE-2026-88856 Published : Sept. 20, 2026, 6:16 p.m. | 4 hours, 27 minutes ago Description :Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla Severity: 9.4 | CRIT
CVE-2026-94089 - D-Link DIR-868L Authentication webfa_authentication.cgi strcpy stack-based overflow
CVE ID :CVE-2026-94089 Published : Sept. 20, 2026, 9:16 p.m. | 1 hour, 27 minutes ago Description :A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the componen
📌 Lain-lain
6The Alpha Engineer Builds Loud, and Builds Anywhere
The Alpha Engineer builds loud, and the Alpha Engineer builds anywhere.
Elon Musk’s latest Boring Company pitch involves a Hyperloop between Austin and San Antonio
Many of The Boring Company's announced project have not materialized.
What If Your Prompt Could Feed Someone a Strawberry?
Every prompt ends as heat, and data centers pay to throw it away. That heat could grow food year-round at the fence line. Both political parties are missing it.
[dos] NanaZip 6.5 - DoS
NanaZip 6.5 - DoS
Vocci’s ring adds a new form factor to meeting note-taking
Vocci's lightweight ring costs $249, and might pose some privacy questions
[remote] phpSysInfo 3.4.5 - IP Allowlist Bypass
phpSysInfo 3.4.5 - IP Allowlist Bypass
🇲🇾 Malaysia/Lokal
2Perbandingan Oppo A7 Pro Max, Redmi Note 17 Pro Max dan Realme P4 Power 5G
Oppo A7 Pro Max dilancarkan di Malaysia dengan ia sebuah lagi telefon dengan bateri 10,000 mAh. Maka ia serasi dibandingkan dengan Redmi Note 17 Pro Max dan Realme P4 Power 5G Oppo A7 Pro Max Redmi Note 17 Pro Max Realme P4 Power 5G 6.78″ AMOLED, 120
10 Perkara Menarik & Mengecewakan iPhone 18 Pro dan iPhone 18 Pro Max
Phone 18 Pro dan iPhone 18 Pro Max dilancarkan secara rasmi di Malaysia hari ini. Apakah yang menarik dan mengecewakan pada iPhone yang ditawarkan. Berikut ialah 10 perkara menarik dan mengecewakan pada iPhone 18 Pro dan iPhone 18 Pro Max. MENARIK 1.