⏐ Taklimat Pagi
Taklimat Pagi Saya
🔗 baca_penuh: pagi.hejes.my/2026/09/23
> ringkasan_ai
# 🤖 AI & Machine Learning
✅ **Claude Opus 5.5 Dilancarkan** [Amanz / MarkTechPost] — Anthropic keluarkan model baru yang setara dengan Fable 5.1 tapi kos operasi 40% lebih murah.💡 **Kenapa Penting** — Performance tinggi tapi bajet rendah, memang berbaloi untuk *scaling*.
✅ **GPT-6 Sol, Luna & Astra** [OpenAI] — OpenAI perkenalkan siri GPT-6 baru; Astra terbukti potong masa & kos kajian sampai separuh, siap ada *prompt caching* yang lebih mantap.💡 **Kenapa Penting** — OpenAI makin agresif buat model yang lebih spesifik ikut keperluan kerja.
✅ **Grok 4.7 Kini Tiba** [MarkTechPost] — SpaceXAI lancarkan model flagship baru untuk coding dan agentic tasks dengan harga yang sama macam versi 4.6.💡 **Kenapa Penting** — Lebih power untuk buat kerja-kerja teknikal tanpa kena bayar lebih.
✅ **Snapdragon 8 Elite Gen 6** [Amanz / TechCrunch] — Qualcomm lancarkan cip baru yang boleh run model AI 30B secara lokal dalam phone (Xiaomi 18 Pro antara yang terawal).💡 **Kenapa Penting** — AI makin lama makin "tinggal" dalam poket, tak payah bergantung sangat kat cloud.
✅ **Malware ClosedQuorum Guna AI** [BleepingComputer] — Ada malware baru guna Gemini, DeepSeek, dan Mistral untuk buat keputusan serangan secara autonomi.💡 **Kenapa Penting** — Penjahat siber pun dah guna AI untuk "berfikir", bukan sekadar skrip biasa.
# 🛡️ Cybersecurity (Amaran Keras!)
✅ **Krisis Zero-Day: Check Point, FBI & WordPress** [Hacker News / BleepingComputer] — Banyak lubang besar dikesan; Check Point kena target, ShinyHunters dakwa hack FBI guna Oracle PeopleSoft, dan WordPress baru je patch flaw kritikal.💡 **Kenapa Penting** — Sistem besar pun boleh bocor, Master kena pastikan semua *patch* dah update.
✅ **Bifrost AI Gateway & IBM FTM Vulnerabilities** [Hacker News / CVE Feed] — Bifrost ada flaw yang bagi attacker run command tanpa password, manakala IBM Financial Transaction Manager ada banyak CVE kritikal (RCE & info leak).💡 **Kenapa Penting** — Kalau Master guna gateway AI atau sistem IBM ni, tolong check cepat-cepat.
✅ **Serangan Supply Chain & Phishing** [Hacker News / Dark Reading] — Ada pakej npm palsu menyamar jadi tool Twilio, dan Microsoft baru je tumbangkan servis phishing "EvilTokens" yang guna AI.💡 **Kenapa Penting** — Jangan main install je library npm, takut kena curi credentials.
✅ **Isu Industri & Infrastruktur (Siemens & OpenPLC)** [CISA] — Banyak produk Siemens dan OpenPLC ada flaw yang boleh bawa kepada *account takeover* atau kawalan fizikal PLC.💡 **Kenapa Penting** — Bahaya kalau sistem kawalan industri kena hijack, boleh kacau operasi fizikal.
# 💻 Tech & Development
✅ **Apple Nak Buat Fitness Tracker?** [TechCrunch] — Ada report kata Apple tengah develop tracker baru untuk lawan Whoop.💡 **Kenapa Penting** — Apple mungkin nak kuasai lagi data kesihatan pengguna.
✅ **Meta "Inspirasi" OpenClaw untuk Muse** [TechCrunch] — Meta mengaku AI assistant Muse mereka banyak terpengaruh dengan OpenClaw sampai nama fail pun hampir sama.💡 **Kenapa Penting** — Drama "copy-paste" dalam dunia AI ni memang tak habis-habis.
✅ **Microsoft Defender Exploit** [SecurityWeek] — Bekas pekerja Microsoft (Nightmare Eclipse) dedahkan exploit baru untuk Microsoft Defender.💡 **Kenapa Penting** — Orang dalam yang buat leak ni paling bahaya sebab dia tahu selok-belok sistem.
🔥 Top Picks
**Claude Opus 5.5** (Sebab kos murah tapi performance gila).
**Malware ClosedQuorum** (Sebab AI dah mula jadi "otak" untuk serangan siber).
**Krisis Zero-Day (FBI/WordPress)** (Sebab skala serangan yang sangat luas).
> ls -la berita/
🧠 AI/ML
35Anthropic Perkenal Claude Opus 5.5 – Dikatakan Setara Fable 5.1, Tetapi Kos Lebih Rendah
Anthropic hari ini memperkenalkan model kecerdasan buatan terbaru mereka, iaitu Opus 5.5 Model ini kini sudah boleh diakses pengguna seluruh dunia melalui perkhidmatan Claude AI. Anthropic menyatakan Opus 5.5 merupakan antara model berkuasa mereka pa
Parallel cut research time and cost in half with GPT‑6 Astra
GPT‑6 Astra allowed Parallel’s agents to research and synthesize labor-market data in half the time and at half the cost vs. prior models.
Anthropic Releases Claude Opus 5.5: Fable 5.1-Level Performance at 40% Lower Running Cost Than Opus 5
Anthropic has released Claude Opus 5.5, the first model in its new Claude 5.5 family. The team states it performs at the level of Claude Fable 5.1 on most work. It also costs 40% less to run than Opus 5 on typical workloads at default settings. On An
SpaceXAI Releases Grok 4.7: A Larger Base Model at the Same $2/$6 Price as Grok 4.6
SpaceXAI has released Grok 4.7, its new flagship model for coding, agentic tasks, and knowledge work. Grok 4.7 is built on a larger base model and a longer reinforcement learning run. It still ships at the same price and speed as Grok 4.6. Is it depl
The $500 CLI: Why Version 1.0 Was a Disaster [And How Procrastination Almost Killed It]
We spent money on student dev hours plus dozens of my own unpaid hours wrestling with Node.js scripts. But it was not a waste of time or money.
New ClosedQuorum Windows malware uses AI for attack decisions
A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack. [...]
The Real Value of Event-Driven Architecture Isn't Technology: It's Cost Reduction
EDA is a strategic approach that helps organizations reduce costs, accelerate delivery, and improve scalability while maintaining flexibility for future growth.
Jun Kim, oMLX creator and maintainer, joins Hugging Face to support the MLX community
Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data
Threat actors stole 170 private repositories using an OAuth token stolen from a former employee's computer through the TanStack npm supply chain attack.
Edge Computing, The Rise of Decentralized Models, and More
Regulatory bans, export controls, and reliability failures are forcing AI developers to move inference to the edge.
Decoupling Internal Representational Changes and Causal Importance in Fine-Tuned Large Language Models
arXiv:2609.21113v1 Announce Type: new Abstract: Fine-tuning has emerged as a widely adopted approach for adapting LLMs to a variety of downstream tasks. However, how it reshapes their internal mechanisms remains poorly understood. To address this, we
Transformers now runs llama.cpp quants
Cyera Raises $400 Million at $12+ Billion Valuation
The data security company received the new investment from Goldman Sachs Alternatives, extending its Series G funding round. The post Cyera Raises $400 Million at $12+ Billion Valuation appeared first on SecurityWeek.
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization from the U.S. District Court for
Qualcomm launches two new smartphone chips with emphasis on AI
Qualcomm said that its new top chip can run 30B mixture-of-expert model locally.
Introducing GPT-6 Sol and Luna
Meet GPT-6 Sol and Luna, two models that bring frontier intelligence to everyday work with different balances of capability and cost.
Siri Xiaomi 18 Pro dan Motorola Signature 27 Peranti Terawal Menggunakan Snapdragon 8 Elite Gen 6
Di Snapdragon Summit pagi ini, Snapdragon 8 Elite Gen 6 dan Snapdragon 8 Elite Extreme Gen 6 dilancarkan secara rasmi sebagai cip peranti mudah alih pertama mencecah kelajuan 5GHz. Dalam acara yang sama, dua peranti terawal menggunakan siri Snapdrago
TechCrunch Founder Summit’s agenda revealed: Unlock fundraising, hiring, and AI insights in Boston on November 4
Founders shouldn't have to learn the hardest lessons the hardest way. TechCrunch Founder Summit is designed to make the challenges of starting a company easier and the highs that much greater.
Can Agents Design Better Chips with a Higher Level Abstraction?
arXiv:2609.21157v1 Announce Type: new Abstract: Large Language Model (LLM) agents are increasingly being explored for chip design, but most existing approaches operate directly at RTL. We ask whether agents can design better chips by leveraging highe
[remote] PraisonAI praisonaiagents 1.6.77 - Remote Code Execution
PraisonAI praisonaiagents 1.6.77 - Remote Code Execution
Amid Ongoing Rogue Incidents, Debate Over AI Safety Gets Real
As more reports of misalignment incidents underscore AI risks, large AI labs, regular businesses, and even nations are searching for better ways to keep control and be secure.
Better prompt caching for GPT-6
Learn how GPT-6 improves prompt caching with higher cache hit rates, new diagnostics, explicit breakpoints, and controls that reduce latency and costs.
Snorkel AI triples valuation to $3.5B as demand for AI training data booms
The seven-year-old startup has raised a $350 million Series E to fuel its data-as-a-service approach.
TinyCeNN-LM: Quality-Gated Conversion of Pretrained Attention with CeNN-Inspired Cellular-Recurrent Layers
arXiv:2609.21139v1 Announce Type: new Abstract: Replacing attention in a pretrained language model is a compatibility problem: a plausible substitute may alter representations expected by later layers. TinyCeNN-LM introduces a \emph{quality-gated pos
Relays Are Masking Chinese Access to Frontier AI Models in the US
More than 80,000 AI relay servers are helping users in China mask their identities while they access cutting-edge large language models (LLMs), probably to clone them.
SpecOpt: Contact-Diff Reasoning for Agentic Molecule Optimization Toward Binding Specificity
arXiv:2609.21165v1 Announce Type: new Abstract: Off-target protein binding is a major source of adverse effects for small-molecule drugs, yet most structure-based molecular design methods focus on generating selective compounds de novo rather than im
How UK AISI and EvalEval Are Making Benchmark Results Reproducible
Don’t be fooled by this summer of AI hype
It’s been a busy few months for AI hype. At the end of April, Anthropic claimed that its model Claude Mythos is better at finding software vulnerabilities than most security experts. Then we had the OpenAI–Hugging Face hacking incident, after which A
Priorities and principles for effective third party assessments
OpenAI outlines priorities and principles for rigorous, secure, and independent third-party AI safety assessments of frontier models and safeguards.
Qualcomm Snapdragon 8 Elite Extreme Gen 6 Dilancarkan – Cip Terpantas Dunia
Snapdragon 8 Elite Extreme Gen 6 turut diumumkan bersama Snapdragon 8 Elite Gen 6 pagi ini dengan ia merupakan cip yang mempunyai prestasi lebih tinggi. Ia masih menggunakan teknologi 2nm yang meningkatkan prestasi serta pada waktu yang sama lebih ce
Clinician-Grounded Quality Assurance for AI-Assisted Psychiatric Intake
arXiv:2609.21149v1 Announce Type: new Abstract: Before patients can use AI-assisted psychiatric intake systems, health systems need practical ways to routinely evaluate these tools against their clinical standards for quality assurance. Because clini
Trump : Amerika Syarikat Akan Menggunakan Terma “Super Intelligence (SI)” Ganti “AI”
Donald Trump hari ini mengumumkan kerajaan Amerika Syarikat akan menggunakan terma “Super Intelligence” menggantikan terma “Artificial Intelligence” atau AI. Penggunaan terma baharu ini berkuat-kuasa bermula hari ini pada pelbagai penggunaan komunika
TimeScope: How Long Can Your Video Large Multimodal Model Go?
How ChatGPT learns about the world while protecting privacy
Learn how ChatGPT safeguards your privacy, reduces personal data in training, and gives you control over whether your conversations improve AI models.
MapReduce: The Abstraction Layer That Still Shapes How AI Workloads Scale
How MapReduce shaped modern AI infrastructure, from distributed computing and fault tolerance to data movement, scheduling, and scaling LLM workloads
🛡️ Cybersecurity
27Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE
Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scrip
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. [...]
More Than a Third of Industrial Orgs See Cybersecurity Risk as a Top Obstacle to Growth, Study Finds
Industrial companies are increasing cybersecurity investment as connected operations, AI adoption, and IT/OT convergence expand operational risk.
CVE-2026-95820 - anirbandutta9 College-Notes-Gallery userprofile.php admin1 unrestricted upload
CVE ID :CVE-2026-95820 Published : Sept. 22, 2026, 10:30 p.m. | 42 minutes ago Description :A vulnerability was found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this issue is some unknown functi
CVE-2026-18173 - IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE ID :CVE-2026-18173 Published : Sept. 22, 2026, 10:20 p.m. | 52 minutes ago Description :IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper enforcement of mutu
Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive
CVE-2026-18137 - IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE ID :CVE-2026-18137 Published : Sept. 22, 2026, 10:17 p.m. | 49 minutes ago Description :IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary ESQL commands due to improper neutralization o
CVE-2026-18176 - IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE ID :CVE-2026-18176 Published : Sept. 22, 2026, 10:21 p.m. | 51 minutes ago Description :IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of se
[webapps] Blocksy Companion 2.1.46 - RCE
Blocksy Companion 2.1.46 - RCE
CVE-2026-18095 - IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE ID :CVE-2026-18095 Published : Sept. 22, 2026, 10:17 p.m. | 49 minutes ago Description :IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow. S
CVE-2026-18154 - IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE ID :CVE-2026-18154 Published : Sept. 22, 2026, 10:17 p.m. | 49 minutes ago Description :IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to the use of a hard-coded or p
CVE-2026-19202 - Token Cache Reuse in mcp-toolbox-sdk-python
CVE ID :CVE-2026-19202 Published : Sept. 22, 2026, 10:17 p.m. | 49 minutes ago Description :A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK causes the same Google ID token to be cached and reused across different audience
Siemens Industrial Edge Management
View CSAF Summary Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification. Sie
Siemens SIPLUS and SIMATIC Products
View CSAF Summary Multiple Siemens products are vulnerable to the "Copy Fail" vulnerability. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions an
[webapps] WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload
WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload
OpenPLC Runtime v3
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller and the phy
Sweden fines Miljödata $183,000 over breach affecting 2.2 million
Sweden's data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people. [...]
Rogue external MFA providers can steal passwords during logins
Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users' passwords during legitimate login attempts. [...]
CVE-2026-18131 - IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE ID :CVE-2026-18131 Published : Sept. 22, 2026, 10:17 p.m. | 49 minutes ago Description :IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary JavaScript in an authenticated user's browser
Siemens WTV676 and WTV776
View CSAF Summary The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the dev
CVE-2026-95828 - Mstfakts College-Management-System Authentication server.php session_start session fixiation
CVE ID :CVE-2026-95828 Published : Sept. 22, 2026, 10:45 p.m. | 27 minutes ago Description :A vulnerability was determined in Mstfakts College-Management-System. This affects the function session_start of the file Front-end/server.php of the componen
Chinese hackers exploit WordPress, Zyxel flaws to steal govt data
A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases. [...]
lwIP (Lightweight IP)
View CSAF Summary Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system. The following versions of lwIP (Lightweight IP) are affected: API >=
Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
A Chinese threat actor has exploited the bug to exfiltrate sensitive information from nearly 1,000 ZyXEL switches. The post Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers appeared first on SecurityWeek.
CVE-2026-95819 - anirbandutta9 College-Notes-Gallery login.php sql injection
CVE ID :CVE-2026-95819 Published : Sept. 22, 2026, 10:17 p.m. | 55 minutes ago Description :A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this vulnerability is an unk
BigCommerce Data Stolen via Ribon Apps Hack
The attackers used a compromised BigCommerce application key held by Ribon to access customer data. The post BigCommerce Data Stolen via Ribon Apps Hack appeared first on SecurityWeek.
⚡ Tech/Dev
9Apple could take on Whoop with a new fitness tracker, report says
Apple may be developing a new fitness tracker as part of its new generation of hardware devices.
Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity
Abdelhamid Naceri, a former Microsoft Germany employee, is the exploit leaker Nightmare Eclipse, aka Chaotic Eclipse. The post Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity appeared first on SecurityWeek.
Microsoft Disrupts EvilTokens Device Code Phishing Service
Microsoft seized 50 websites and disabled more than 150 domains as part of a coordinated disruption effort against a phishing-as-a-service platform targeting Microsoft 365 accounts.
Meta admits Muse’s likeness to OpenClaw isn’t a coincidence
Meta says Muse was built from scratch, but acknowledges the AI assistant was "heavily inspired" by OpenClaw — down to some of its workspace filenames and content.
WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing the attacker to run their own code. The fix ship
Roundtables: The Deadly Failures of The Virtual Border Wall
The US has spent billions building a “virtual wall” of surveillance towers along its southern border over the past 25 years, promising they will help detect and apprehend border crossers and save lives. But a groundbreaking investigation by MIT Techn
[webapps] Apache Gravitino 1.2.1 - SSRF
Apache Gravitino 1.2.1 - SSRF
Only 13% of OT Network Segments Are Fully Isolated: Analysis
Forescout’s new network segmentation research shows that OT and medical devices often share network segments with other enterprise assets. The post Only 13% of OT Network Segments Are Fully Isolated: Analysis appeared first on SecurityWeek.
Qualcomm Snapdragon 8 Elite Gen 6 Dilancarkan – Cip 2nm Dengan Peningkatan Prestasi Sehingga 35%
Qualcomm melancarkan Snapdragon 8 Elite Gen 6 pagi ini dengan ia cip yang bersaing secara terus dengan Dimensity 9600 dan Apple A20 Pro . Ia menggunakan teknologi 2nm yang meningkatkan prestasi serta pada waktu yang sama lebih cekap menggunakan kuasa
📌 Lain-lain
3Fast LoRA inference for Flux with Diffusers and PEFT
[remote] mcp-server-kubernetes 3.8.x - Argument Injection
mcp-server-kubernetes 3.8.x - Argument Injection
Understanding GLiFormer’s Benchmarks and Schema-Driven Extraction
Explore GLiFormer Large v1’s extraction tasks, reported benchmarks, Python examples, and limitations across entities, relations, and structured records.