⏐ Taklimat Pagi
Taklimat Pagi Saya
🔗 baca_penuh: pagi.hejes.my/2026/09/22
> ringkasan_ai
# 🤖 AI & Machine Learning
✅ **OpenAI Tubuh Kumpulan Penasihat Matematik** [TechCrunch/OpenAI] — OpenAI buat *advisory group* baru sebab AI dorang dah berjaya selesaikan lebih 100 masalah matematik yang terbuka.💡 **Kenapa Penting** — AI dah mula masuk level *advanced reasoning* yang serius, bukan setakat sembang kosong.
✅ **Meta Muse vs ChatGPT** [TechCrunch] — Agent AI baru Meta, Muse, dilaporkan lebih cepat naik *downloads* dan *active users* berbanding ChatGPT masa awal pelancaran mobile dulu.💡 **Kenapa Penting** — Persaingan AI agent makin sengit, Meta tengah *aggressive* sekarang.
✅ **GPT-6 Astra & Higgsfield AI** [OpenAI] — Higgsfield AI guna GPT-6 Astra untuk buat *video ad* untuk bisnes kecil dengan jauh lebih pantas.💡 **Kenapa Penting** — GPT-6 dah mula *deploy* dalam tool kreatif, *workflow* buat video makin senang.
✅ **Isu 'Virtual Wall' Sempadan AS** [MIT Tech Rev] — Siasatan dedahkan banyak kematian berlaku dekat kawasan pengawasan kamera canggih, tapi sistem tu gagal selamatkan mangsa.💡 **Kenapa Penting** — Bukti yang teknologi pengawasan mahal tak semestinya efektif kalau tak ada respon manusia.
✅ **Update vLLM (Siri CVE)** [CVE Feed] — Ada banyak *vulnerability* kritikal (DoS & Memory Exhaustion) dikesan dalam vLLM versi 0.29.0.💡 **Kenapa Penting** — Kalau Master ada guna vLLM untuk *deploy* model, kena *patch* cepat-cepat sebelum kena *attack*.
# 🛡️ Cybersecurity
✅ **Google Kena Denda €403 Juta** [SecurityWeek/BleepingComputer] — EU denda Google sebab langgar peraturan privasi GDPR berkaitan pengendalian data lokasi pengguna.💡 **Kenapa Penting** — EU memang tak main-main pasal data privasi, *big tech* pun boleh tumbang.
✅ **Serangan 'Click2Shell' WordPress** [BleepingComputer] — Ada *flaw* baru yang bagi hacker execute PHP terus kat server guna teknik CSRF.💡 **Kenapa Penting** — WordPress ni ramai guna, so risiko *mass exploitation* sangat tinggi.
✅ **Fake LastPass Installer & 'Rapuncel' Stealer** [SecurityWeek/Hacker News] — Hacker guna installer palsu untuk matikan antivirus/EDR guna *kernel-level driver* sebelum curi data.💡 **Kenapa Penting** — Teknik ni bahaya sebab dia 'bunuh' security software dulu sebelum buat kerja.
✅ **Kempen 'Contagious Interview' Korea Utara** [Hacker News] — Lebih 30,000 peranti kena *compromise* dan $10.71 juta kripto hilang hasil kerja *threat actor* dari NK.💡 **Kenapa Penting** — *Social engineering* guna tawaran kerja masih jadi senjata paling ampuh.
# 💻 Tech & Dev
✅ **AWS Strands Harness** [MarkTechPost] — AWS release *open-source agent harness* yang boleh kurangkan kos token sampai 28% dengan accuracy yang sama.💡 **Kenapa Penting** — Boleh jimat bajet API kalau Master nak bina AI agent sendiri.
✅ **Microsoft 365 Companion Apps Bersara** [BleepingComputer] — App Calendar, People, dan Files akan ditamatkan pada 16 Disember ni.💡 **Kenapa Penting** — Kena *update* admin atau tukar cara kerja sebelum app ni hilang.
# 📱 Gadget & Lokal
✅ **Vivo Launch Produk Baru** [Amanz] — Vivo lancarkan OriginOS 7 (Android 17), Vivo Watch 6 (Titanium), dan Buds Clip.💡 **Kenapa Penting** — Trend *wearables* sekarang makin fokus pada material premium dan integrasi AI.
✅ **Huawei Watch GT7 Masuk Malaysia** [Amanz] — Bakal tiba 29 September ni, fokus untuk gaya hidup aktif.💡 **Kenapa Penting** — Pilihan baru untuk Master kalau nak tukar jam tangan *sporty*.
🔥 Top Picks
**vLLM Critical CVEs** — Wajib check kalau Master ada *infra* AI.
**GPT-6 Astra** — Menarik tengok macam mana AI video evolve.
**Click2Shell WordPress** — Warning untuk semua yang maintain website.
> ls -la berita/
⚡ Tech/Dev
14Google Hit With $463 Million Fine for EU Location Data Rule Breach
Google has been fined 403 million euros ($463 million) for breaching the European Union’s strict privacy rules because it mishandled users’ location data. The post Google Hit With $463 Million Fine for EU Location Data Rule Breach appeared first on S
Google Fined €403 Million Over GDPR Violations Tied to Location Data
Google has been fined €403 million for breaking the EU's data protection law, the GDPR, in the way three of its features handled people's location data from May 2018 to February 2020. Ireland's Data Protection Commission (DPC), Google's lead regulato
Best Voice Cloning APIs in 2026: Speaker Similarity, Consent Checks, and Price per 1M Characters
We cloned one 10-second voice on 7 platforms and ranked them on reference audio, consent, licensing, and cost. The post Best Voice Cloning APIs in 2026: Speaker Similarity, Consent Checks, and Price per 1M Characters appeared first on MarkTechPost.
How we made the first comprehensive map of deaths along the US border’s “virtual wall”
Our 15-month investigation into death and surveillance along the US-Mexico border began with a simple question: Why did so many people die near government surveillance towers meant to help track and apprehend them? This story is part of Dying on Came
AWS Strands Agents Team Releases Strands Harness: An Open-Source Agent Harness With 28% Lower Token Cost at Comparable Accuracy
Many developers find that an agent idea works inside Claude Code or Codex, then struggles once they rebuild it with their own loop. The Strands Agents team at AWS is targeting that gap with Strands harness, a fully assembled, general-purpose agent ha
Microsoft to retire Microsoft 365 Companion apps in December
Microsoft will retire the Calendar, People, and Files Microsoft 365 companion apps on December 16 and has asked admins to remove them from managed devices. [...]
[webapps] Joomla JCE_2.9.15 - Remote Code Execution
Joomla JCE_2.9.15 - Remote Code Execution
Google fined €403 million over location data privacy violations
Ireland's Data Protection Commission (DPC) has fined Google €403 million ($463M) for multiple GDPR violations related to processing users' location data. [...]
[remote] ipTIME A3004T - Remote Code Execution
ipTIME A3004T - Remote Code Execution
tokenizers v1: encode, decode and scaling, measured
Discover what’s next: 5 days left to save up to $200 on your TechCrunch Disrupt 2026 ticket
Five days left to save up to $200 on your TechCrunch Disrupt 2026 pass + 50% off a second one. Join 10,000+ founders, investors, and operators at San Francisco’s Moscone West, October 13-15. Grab your ticket savings before prices go up on September 2
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs
[webapps] Duplicati 2.2.0.3 - JWT Signing Key Leak
Duplicati 2.2.0.3 - JWT Signing Key Leak
The man who built Apple’s stores doesn’t buy Silicon Valley’s bet on AI shopping
Apple Store architect Ron Johnson says Apple's secret sauce has always been its people.
🧠 AI/ML
33OpenAI forms math advisory group as its AI resolves more than 100 open problems
The group won't be given leeway to slow down or redirect OpenAI's ongoing mathematical research.
Three iOS WebKit Traps That Blacked Out My AR Game, and How I Caught Them
AURADUEL's camera went black on my iPhone in three ways. The evidence, the two fixes that failed, and the rule that worked: one video element per stream.
Say hello to `hf`: a faster, friendlier Hugging Face CLI ✨
LoRA Enhanced Contrastive Learning with SAS Vision Transformers
arXiv:2609.21061v1 Announce Type: new Abstract: Automatic target recognition (ATR) with synthetic aperture sonar (SAS) supports advanced naval capabilities, but deep learning is constrained by scarce target imagery, background clutter, and human-in-t
She died at the San Diego border. A surveillance camera was in plain sight
She had only walked for a couple of hours, and already she was lost. It was early afternoon on Sept. 14, 2025, when 30-year-old Graciela Gómez Hernández crossed the border from the eastern edge of Tijuana into Southern California, sending voice messa
Pruning LLMs Like a Physicist: Block Removal as an Ising Optimization Problem
Expanding OpenAI Academy with new learning paths
Explore new OpenAI Academy learning paths for employees, developers, leaders, educators, and students to build and demonstrate practical AI skills.
My AI Agent Distorted the Truth in Three Different Ways, but Only One Was a Hallucination
AI agents helped audit a Unity game for Google Play, then introduced five subtler errors through fabrication, amplification, and compression.
CVE-2026-94626 - vLLM through 0.29.0 Memory Exhaustion via Unvalidated NIXL tp_size
CVE ID :CVE-2026-94626 Published : Sept. 21, 2026, 10:17 p.m. | 45 minutes ago Description :vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate un
The US spent billions on border surveillance. Why can’t it catch people before they die?
When José Morales Bernal crossed the border into the United States on April 8, 2024, the day before his 32nd birthday, it should have triggered a chain of technological alerts and human responses. As he walked through the desert in southern New Mexic
4 ways to address the failures we found along the US border’s “virtual wall”
MIT Technology Review today published our investigation into how many people have died near the “virtual wall” of surveillance towers that the US government has installed along the US-Mexico border. We found cases of people who walked undetected thro
Attention-Aware Routing: Coupling Routing and Attention in MoEs
arXiv:2609.20974v1 Announce Type: new Abstract: In Mixture-of-Experts language models, the router typically selects and weights experts based on the token's hidden state, utilizing limited contextual information. We propose Attention-Aware Routing (A
Meta’s Muse is outpacing ChatGPT’s early mobile launch
Meta’s new AI agent Muse has racked up more downloads and daily active users in the U.S. and Canada than ChatGPT did over the same period after its mobile debut, according to new estimates from Appfigures.
Vivo Buds Clip Diumumkan Dengan Rekaan Subang Dan Bateri 42 Jam
Vivo turut memasuki segmen aksesori audio berbentuk subang melalui Buds Clip baharu. Aksesori audio ini hadir dengan gabungan fungsi moden untuk gaya kontemporari dan penggunaan berpanjangan. Ia juga hadir dalam dua versi iaitu versi standard dan ver
Building standards for the next phase of AI
OpenAI outlines a path to shared global AI standards, calling for coordinated evaluation, reporting, and governance to improve safety.
Rogue Behavior: OpenAI Reveals More Model Misalignment Incidents
The AI giant disclosed six examples of concerning model activity and published a new framework for investigating and disclosing such incidents.
Higgsfield AI ships new video features in a day with GPT-6 Astra
With GPT-6 Astra, Higgsfield AI makes video ad creation easier for small businesses and brings new creative tools to market faster.
ShinyHunters Hacked Clop. Now What About Clop's Victims?
ShinyHunters defaced Clop's Dark Web site and claims to have stolen victim data, potentially exposing organizations that paid ransoms to renewed extortion attempts.
OriginOS7 Dilancarkan Untuk Peranti Vivo Global
vivo memperkenalkan OriginOS 7 secara global yang juga mula tersedia hari ini dalam Preview Program (beta terbuka). Berasaskan Android 17, sistem operasi ini menekankan kelancaran jangka panjang, integrasi AI, antara muka menarik, sambungan ekosistem
⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks
Vivo Watch 6 Dilancarkan Dengan Tubuh Titanium Dan eSIM
Vivo Watch 6 telah diumumkan secara rasmi sebagai jam tangan pintar terbaharu jenama ini. Ia menampilkan peningkatan dari segi bahan binaan premium serta ciri kecergasan yang lebih canggih. Vivo Watch 6 hadir dengan binaan premium melalui gabungan sk
Kairos Power gets up to $100M from Samsung group to build nuclear reactor for Google
Future Google supplier Kairos Power inked a deal with Samsung C&T to help build its first 50-megawatt nuclear power plant.
RBS-Attention: Radius-Bounded Sparse Prefill for Long-Context Large Language Models
arXiv:2609.20971v1 Announce Type: new Abstract: Long-context large language model inference is increasingly limited by prefill, where dense self-attention processes the entire prompt before generation begins. Sparse block selection can reduce this co
Advisory Group on Mathematics and Artificial Intelligence
OpenAI is working with an independent Advisory Group on Mathematics and Artificial Intelligence to guide the review and communication of emerging AI results.
Introducing Trackio: A Lightweight Experiment Tracking Library from Hugging Face
RatHat Android Trojan Uses AI for Automation
The malware relies on AI for real-time device navigation and control, increasing adaptability and evasion. The post RatHat Android Trojan Uses AI for Automation appeared first on SecurityWeek.
Detecting Hallucination in LLMs: Tracing the Topological Signatures of Impaired Context Sharing
arXiv:2609.21096v1 Announce Type: new Abstract: In this work, we examine the topology of information flow patterns within attention graphs to effectively distinguish hallucinated from non-hallucinated responses. We analyze the Forman-Ricci curvature
Alibaba Qwen Releases Qwen-Image-2.1: A 7B Open-Weight Model for Image Generation and Editing
Alibaba's Qwen team has released Qwen-Image-2.1, a 7B diffusion transformer that handles text-to-image generation, multi-reference editing, and native RGBA transparency in one checkpoint. A prefix KV cache speeds up edits with up to 10 reference imag
How AI Agents Can Trigger Runaway Costs for Enterprises
Unbounded consumption is an issue that OWASP currently ranks sixth in its Top 10 for LLM Applications, and it could be an extremely costly one.
Vivo X500 Pro Max, X500 Pro Dan X500 Kini Rasmi – Cip Dimensity 9600 Pro, Kamera 200MP ZEISS
Vivo telah melancarkan siri baharu X500 yang terdiri daripada tiga model iaitu X500, X500 Pro dan X500 Pro Max. Ketiga-tiganya merupakan telefon mercu dengan spesifikasi berkuasa sesuai untuk pengguna yang mementingkan kualiti kamera serta prestasi p
CaLR: Causal Latent Revision for Robust Diffusion Reasoning
arXiv:2609.20981v1 Announce Type: new Abstract: Autoregressive (AR) models suffer from local greediness, while diffusion language models (DLMs) often lack the strict causal structure required for reasoning. To combine the advantages and overcome the
StepFun Launches Step 5 Preview: A 600B-Total, 27B-Active MoE Model With 1M Context for Long-Horizon Agentic Work
StepFun has released Step 5 Preview, a sparse Mixture-of-Experts model with 600B total parameters and 27B active per token. It supports a 1M-token context window and accepts text, image, and video input. The model targets long-horizon agentic work in
How V7 gives AI agents institutional memory
Using GPT-5.6, V7 turns scattered company files into context agents can use to complete complex, source-linked work.
🛡️ Cybersecurity
18Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer
The attackers impersonate at least 40 companies and disable 145 security products to deploy infostealer malware. The post Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer appeared first on SecurityWeek.
Dragos Completes NetRise and runZero Acquisitions Following Accenture Deal
The transaction is part of the $4.1 billion deal in which Accenture acquired a majority stake in Dragos in an OT cybersecurity push. The post Dragos Completes NetRise and runZero Acquisitions Following Accenture Deal appeared first on SecurityWeek.
CISA alerts of active exploitation of three Linux kernel flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical. [...]
BigCommerce alerts merchants of data breach linked to Ribon apps
Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. [...]
CVE-2026-94622 - vLLM through 0.29.0 Denial of Service via Incomplete NIXL KV Transfer Metadata
CVE ID :CVE-2026-94622 Published : Sept. 21, 2026, 10:17 p.m. | 43 minutes ago Description :vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated deployments.
TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts. The backdoor "automatically harvests and exfiltrates business document
CVE-2026-94623 - vLLM through 0.29.0 Denial of Service via NIXL Multi-Prompt Assertion Failure
CVE ID :CVE-2026-94623 Published : Sept. 21, 2026, 10:17 p.m. | 43 minutes ago Description :vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block cou
CVE-2026-94572 - OpenStack Octavia Amphora Provider Driver Improper Input Validation Configuration Injection
CVE ID :CVE-2026-94572 Published : Sept. 21, 2026, 9:17 p.m. | 1 hour, 42 minutes ago Description :In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The va
CVE-2026-94426 - xuxueli xxl-job insert cross site scripting
CVE ID :CVE-2026-94426 Published : Sept. 21, 2026, 10:30 p.m. | 31 minutes ago Description :A vulnerability was determined in xuxueli xxl-job up to 3.5.0. The impacted element is an unknown function of the file /jobgroup/insert. This manipulation of
CVE-2026-94624 - vLLM through 0.29.0 Denial of Service via Unbounded P2P KV Offloading Sessions
CVE ID :CVE-2026-94624 Published : Sept. 21, 2026, 10:17 p.m. | 45 minutes ago Description :vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a pe
WordPress Click2Shell flaw lets hackers execute PHP on the server
Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component. [...]
CVE-2026-94625 - vLLM through 0.29.0 Resource Exhaustion via Ownerless Mooncake Transfer Placeholders
CVE ID :CVE-2026-94625 Published : Sept. 21, 2026, 10:17 p.m. | 45 minutes ago Description :vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders t
Cybercriminals Are Hiding New Malware in Torrents for Popular Films
Victims have been identified in Africa, including in Kenya and Uganda.
Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
The North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new j
CVE-2026-94571 - OpenStack Octavia Amphora Provider Driver HAProxy Configuration Injection Vulnerability
CVE ID :CVE-2026-94571 Published : Sept. 21, 2026, 9:17 p.m. | 1 hour, 42 minutes ago Description :In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fie
CVE-2026-61652 - Zapros: Streaming decoders ignored the requested chunk size, allowing a single compressed response chunk to allocate unbounded memory (decompression bomb)
CVE ID :CVE-2026-61652 Published : Sept. 21, 2026, 10:16 p.m. | 43 minutes ago Description :Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service via memory exhaustion. The issue affects all callers who streamed com
CVE-2026-94627 - vLLM through 0.29.0 GPU KV Cache Leak via Mooncake Transfer ID Collision
CVE ID :CVE-2026-94627 Published : Sept. 21, 2026, 10:17 p.m. | 45 minutes ago Description :vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in pref
CISO Conversations: Noopur Davis – The Accidental Global CISO at Comcast
Noopur Davis never planned a career in cybersecurity. She was a developer at Intergraph, and for many years that was all she wanted to be. The post CISO Conversations: Noopur Davis – The Accidental Global CISO at Comcast appeared first on SecurityWee
📌 Lain-lain
6Parquet Content-Defined Chunking
Zoomex to Host Traders After Party During TOKEN2049 Singapore, Connecting Traders and the Web3 Space
Centering on the theme “CRYPTO TRADING · WEB3 · LIVE MUSIC · NETWORKING,” the event seamlessly blends market discussions with an elevated party
Building Isolyne (Part 7): Designing Dark Mode for High-Velocity Dev Teams
Isolyne replaces scattered styling decisions with centralized React Native tokens for color, elevation, spacing, typography, radius, motion, and interaction. The same primitives also keep its core interface and RevenueCat paywall visually consistent.
Designing “Memory Rescue” With OneSignal (Without Turning Slovo Into a Notification Machine)
Slovo uses OneSignal tags, deep links, exit rules, and a holdout group to test whether timely review reminders improve language-learning retention.
[dos] Nmap 7.99 - Extension Header Integer Underflow
Nmap 7.99 - Extension Header Integer Underflow
[remote] D-Link DNS_340L - OS Command Injection
D-Link DNS_340L - OS Command Injection