⏐ Taklimat Pagi

Taklimat Pagi Saya

“Baca dulu, baru decide. Jangan biar orang lain fikirkan untuk ko.”
//59 cerita//~3 minit

🔗 baca_penuh: pagi.hejes.my/2026/09/27

> ringkasan_ai

# 🤖 AI & Machine Learning

✅ **GPT-5.5 Instant & Claude Opus 5.5** [OpenAI / BleepingComputer] — OpenAI lancar GPT-5.5 Instant yang lebih *smart* dan kurang halusinasi, manakala Claude Opus 5.5 kini menulis dengan gaya lebih natural (kurang gaya "AI").💡 **Kenapa Penting** — Model AI makin *human-like* dan efisien, Master boleh guna untuk kerja yang lebih kompleks.

✅ **OpenAI & Isu Privasi/Keselamatan** [SecurityWeek / BleepingComputer] — AI agents OpenAI kantoi akses laman web kerajaan US dan terlepas *upload* gambar user ke site pihak ketiga.💡 **Kenapa Penting** — Master kena hati-hati dengan data sensitif bila guna AI agents.

✅ **MRC (Multipath Reliable Connection)** [OpenAI] — Protokol networking baru untuk buat *training* AI skala besar jadi lebih stabil dan laju.💡 **Kenapa Penting** — Ini kunci untuk lahirkan model AI yang jauh lebih power lepas ni.

✅ **Muse Integrasi Spotify & TenPayGo Tencent** [Amanz] — Meta bawa Muse masuk Spotify untuk kawalan suara, manakala Tencent mudahkan pelancong guna kad bank luar di China.💡 **Kenapa Penting** — Ekosistem digital makin *seamless*, tak payah pening fikir pasal *payment* atau butang.

✅ **SmolLM3 & Julia 1** [HuggingFace / MarkTechPost] — Model AI kecil (small models) yang power untuk *reasoning* dan boleh jalan atas CPU biasa.💡 **Kenapa Penting** — AI tak semestinya kena guna GPU mahal; model kecil pun dah cukup *kick*.

# 🛡️ Cybersecurity (Hati-hati Master!)

✅ **Serangan Oracle PeopleSoft & ShinyHunters** [BleepingComputer / Hacker News] — Geng ShinyHunters guna trik *bypass* WAF untuk eksploitasi CVE-2026-35273 dan tanam *web shells*.💡 **Kenapa Penting** — *Firewall* biasa mungkin tak cukup kalau *attacker* guna trik *encoding*.

✅ **Kritikal: WordPress & Joomla Vulnerabilities** [CVE Feed / Hacker News] — Banyak *plugin* (Elementor, miniOrange, UP plugin) ada lubang besar yang boleh bawa kepada *Remote Code Execution* (RCE) dan *Privilege Escalation*.💡 **Kenapa Penting** — Kalau Master ada site WordPress/Joomla, tolong *update* semua *plugin* sekarang juga!

✅ **SalesBleed & Salesforce Agentforce** [SecurityWeek] — Tiga lubang keselamatan dalam Salesforce Agentforce benarkan *zero-click data exfiltration*.💡 **Kenapa Penting** — AI agents dalam korporat pun boleh kena *hijack* untuk curi data.

✅ **Elasticsearch & Kibana DoS** [CVE Feed] — Beberapa CVE baru (CVE-2026-94398 dll) boleh buatkan servis Elasticsearch/Kibana *crash* (Denial of Service).💡 **Kenapa Penting** — Boleh ganggu kestabilan *database* dan *monitoring* sistem Master.

# 💻 Tech, Dev & Gadgets

✅ **Apple & Qualcomm Renew License** [Amanz] — Dua gergasi ni sambung lagi perjanjian lesen paten sampai 2027.💡 **Kenapa Penting** — Modem 5G dalam iPhone akan terus stabil tanpa drama mahkamah.

✅ **Honor X9e Pro Masuk Malaysia** [Amanz] — Telefon tahan lasak dengan bateri raksasa 11,000 mAh, harga bermula RM1899.💡 **Kenapa Penting** — Sesuai kalau Master nak phone yang tak payah cas selalu dan tak pecah kalau terjatuh.

✅ **Microsoft Pause Update KB5002907** [BleepingComputer] — Update Office terbaru buatkan lesen Office 2016/2019 hilang tiba-tiba.💡 **Kenapa Penting** — Jangan *update* Office dulu kalau tak nak lesen *deactivate* sendiri.

# 🌍 Lain-lain

✅ **TikTok Bayar $100M Settlement** [TechCrunch] — TikTok setuju bayar denda di Alabama sebab didakwa buat budak-budak ketagih.💡 **Kenapa Penting** — Tekanan undang-undang terhadap *social media* makin kuat.

🔥 Top Picks

**GPT-5.5 Instant & Claude Opus 5.5** (AI makin bijak, Master kena *keep up*!)

**Oracle PeopleSoft & ShinyHunters** (Amaran keras untuk *security* infrastruktur).

**Honor X9e Pro** (Bateri 11,000 mAh tu memang gila, Master!)

> ls -la berita/

🧠 AI/ML

28
🧠 AI/ML

Claude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer

Anthropic's Claude Opus 5.5 appears to be changing how it writes, with new analysis showing fewer obvious AI writing patterns, shorter sentences, and simpler wording compared with Opus 5. [...]

$> BleepingComputer⏱️ 1m
→
🧠 AI/ML

Three Mighty Alerts Supporting Hugging Face’s Production Infrastructure

$> HuggingFace⏱️ 1m
→
🧠 AI/ML

Muse Diintegrasikan Ke Spotify Untuk Kawalan Audio Melalui Arahan Suara

Meta sebelum ini telah memperkenalkan Muse sebagai agen peribadi pintar. Melalui kemas kini terkini, Muse mula diintegrasikan ke dalam Spotify. Kehadiran Muse ini menjadikan kawalan audio lebih mudah kerana pengguna boleh memainkan lagu, mendengar po

$> Amanz⏱️ 1m
→
🧠 AI/ML

Levoit’s new air purifier is for the pet odors that have taken over your apartment

This $189.99 air purifier is specifically designed to tackle pet odors, removing up to 70% in one hour.

$> TechCrunch⏱️ 1m
→
🧠 AI/ML

SmolLM3: smol, multilingual, long-context reasoner

$> HuggingFace⏱️ 1m
→
🧠 AI/ML

I created an interactive digital avatar of myself — and you can talk to it

After obtaining an interactive avatar and training it to discuss venture fraud, I have mixed feelings about making AI clones of ourselves.

$> TechCrunch⏱️ 1m
→
🧠 AI/ML

New ways to buy ChatGPT ads

OpenAI expands ChatGPT ads with a beta self-serve Ads Manager, CPC bidding, and enhanced measurement tools—built to protect privacy and keep conversations separate from ads.

$> OpenAI⏱️ 1m
→
🧠 AI/ML

GPT-5.5 Instant System Card

$> OpenAI⏱️ 1m
→
🧠 AI/ML

New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions. The post New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining appeared first on SecurityWeek.

$> SecurityWeek⏱️ 1m
→
🧠 AI/ML

OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure

OpenAI’s CEO said there is an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation.” The post OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure appeare

$> SecurityWeek⏱️ 1m
→
🧠 AI/ML

AI-Assisted Genealogy: Using AI to Trace My Family Tree

I continue working on my tree, and I have deepened my understanding of the subject. In this post, I want to share again.

$> Hacker Noon⏱️ 1m
→
🧠 AI/ML

Unlocking large scale AI training networks with MRC (Multipath Reliable Connection)

OpenAI introduces MRC (Multipath Reliable Connection), a new supercomputer networking protocol released via OCP to improve resilience and performance in large-scale AI training clusters.

$> OpenAI⏱️ 1m
→
🧠 AI/ML

Sarvam AI Releases Saaras V4: A Speech-to-Text Model for All 22 Indian Languages and Global English

Sarvam AI's Saaras V4 is a speech-to-text model covering all 22 Indian languages plus global English. It pairs an audio encoder with a 3B hybrid state-space decoder. It adds keyterm prompting for up to 50 terms, 5 output modes from 1 model, and strea

$> MarkTechPost⏱️ 1m
→
🧠 AI/ML

Tencent Lancarkan TenPayGo Untuk Pelancong Gunakan Kad Bank dan Dompet Digital Tempatan Di China

Melancong ke China ialah seperti pergi ke Marikh kerana ia adalah negara nirtunai sepenuhnya sehingga pengemis mempunyai kod QR untuk menerima derma. Isu yang berlaku ialah sistem nirtunai di China tidak menyokong kad kredit, debit atau dompet digita

$> Amanz⏱️ 1m
→
🧠 AI/ML

When Your Voice Agent Enters the Scene, Ft. GPT-Live

A starship docking game is where the user can collaborate with a AI agent using voice. The game examplifies how to build voice agents with GPT-Live.

$> Hacker Noon⏱️ 1m
→
🧠 AI/ML

Advancing youth safety and wellbeing in EMEA

Explore OpenAI’s European Youth Safety Blueprint and EMEA Youth & Wellbeing Grants, advancing safe, responsible AI for teens, families, and educators.

$> OpenAI⏱️ 1m
→
🧠 AI/ML

Zero Trust for AI Agents Starts With Fixing Zero Visibility

The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a str

$> Hacker News⏱️ 1m
→
🧠 AI/ML

Infinix Lancar Alat Kalawan GT NX Controller Dan Dok GT NX Station – Harga Bermula RM299

Infinix telah melancarkan siri aksesori GT NX yang terdiri daripada GT NX Controller dan GT NX Station. Kedua-dua perkakasan ini memfokuskan kepada memberikan alat kawalan terbaik dan juga menyelesaikan masalah... The post Infinix Lancar Alat Kalawan

$> Aksiz⏱️ 1m
→
🧠 AI/ML

GPT-5.5 Instant: smarter, clearer, and more personalized

GPT-5.5 Instant updates ChatGPT’s default model with smarter, more accurate answers, reduced hallucinations, and improved personalization controls.

$> OpenAI⏱️ 1m
→
🧠 AI/ML

Upskill your LLMs With Gradio MCP Servers

$> HuggingFace⏱️ 1m
→
🧠 AI/ML

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which describ

$> Hacker News⏱️ 1m
→
🧠 AI/ML

Supersonic Labs Releases Julia 1: A 144.3M-Parameter Open Decision Model That Runs on a CPU

Supersonic Labs has released Julia 1, a 144.3M-parameter decision model built on mmBERT-small. It takes context, a question, and 2 to 20 options, then returns one choice with probabilities. The model runs on a CPU and ships under Apache 2.0. It beat

$> MarkTechPost⏱️ 1m
→
🧠 AI/ML

China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks

The US and China agreed to set up a communication mechanism for artificial intelligence-related incidents. The post China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks appeared first on SecurityWeek.

$> SecurityWeek⏱️ 1m
→
🧠 AI/ML

GitHub Actions re-enabled with Mini Shai-Hulud payload still active

Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code. [...]

$> BleepingComputer⏱️ 1m
→
🧠 AI/ML

OpenAI's AI agents accidentally uploaded user-provided images to third-party sites

OpenAI says its AI agents uploaded user-provided images to third-party image-hosting services while carrying out research and evaluation tasks. [...]

$> BleepingComputer⏱️ 1m
→
🧠 AI/ML

Insurers claim AI is already increasing healthcare costs

Blue Cross Blue Shield says hospital use of AI tools led to an additional $942M in healthcare spending over a two-year period.

$> TechCrunch⏱️ 1m
→
🧠 AI/ML

Announcing NeurIPS 2025 E2LM Competition: Early Training Evaluation of Language Models

$> HuggingFace⏱️ 1m
→
🧠 AI/ML

Microsoft Menamatkan Penjenamaan Copilot+ PC

Dua tahun lalu, penjenamaan Copilot+ PC diperkenalkan dengan ia menggantikan penjenamaan AI PC sebelumnya. Pada ketika itu, Copilot+ PC ialah penjenamaan yang digunakan pada komputer Windows 11 yang memenuhi keperluan minima kuasa memproses 45 TOPS u

$> Amanz⏱️ 1m
→

⚡ Tech/Dev

7
⚡ Tech/Dev

Qualcomm dan Apple Melanjutkan Perjanjian Lesen Paten

Qualcomm dan Apple telah memperbaharui perjanjian lesen paten global mereka, yang akan berkuat kuasa mulai 1 April 2027. Pengumuman ini dibuat oleh Qualcomm pagi ini dalam satu siaran media yang pendek. Qualcomm tidak mendedahkan butiran kewangan, te

$> Amanz⏱️ 1m
→
⚡ Tech/Dev

Meta and YouTube say they will run ads for ‘Musk’ documentary after all

Two companies now say they will accept advertising for director Alex Gibney’s upcoming documentary about Elon Musk, following earlier reporting that a number of social media platforms had rejected the ads.

$> TechCrunch⏱️ 1m
→
⚡ Tech/Dev

Microsoft pauses KB5002907 update after Office license deactivations

Microsoft has paused the rollout of the KB5002907 Microsoft 365 update after users report that it deactivated, or in some cases completely removed, perpetual Office 2016 and Office 2019 installations. [...]

$> BleepingComputer⏱️ 1m
→
⚡ Tech/Dev

When Does Working Software Actually Become Legacy Software?

Working software can still become legacy. Learn how security, maintenance, knowledge gaps, dependencies, and change costs reveal when software is aging.

$> Hacker Noon⏱️ 1m
→
⚡ Tech/Dev

End-to-End Multimodal Data Augmentation and Adversarial Robustness Benchmark with AugLy for Images, Text, Audio, and PyTorch

Discover how to build a comprehensive multimodal augmentation and adversarial robustness workflow using AugLy for images, text, audio, and PyTorch datasets. The post End-to-End Multimodal Data Augmentation and Adversarial Robustness Benchmark with Au

$> MarkTechPost⏱️ 1m
→
⚡ Tech/Dev

The Wanted Man Tiba Di Apple TV Januari 2027 – Hugh Laurie, Thandiwe Newton, Fionn Whitehead

Apple TV telah mengumumkan siri drama jenayah lapan episod terbaharu dengan judul The Wanted Man yang diterajui dan diterbitkan secara eksekutif oleh pelakon terkenal Hugh Laurie, bintang siri House dan... The post The Wanted Man Tiba Di Apple TV Jan

$> Aksiz⏱️ 1m
→
⚡ Tech/Dev

Exa Launches Agent Ultra: A Subagent Swarm Deep Research API Built for Exhaustive List Building

Exa has released Agent Ultra, the highest effort mode of its Exa Agent API. It coordinates subagents across thousands of sources for list building and entity enrichment. Exa reports it beats Opus 5.5, GPT-6 Astra, and Perplexity Agent on 4 benchmarks

$> MarkTechPost⏱️ 1m
→

🛡️ Cybersecurity

19
🛡️ Cybersecurity

SASE Converges Network & Security Into One Cloud Solution

Enterprise computing is moving to the edge. Keeping it secure requires tactics far beyond putting up firewalls. (Second in a three-part series.)

$> Dark Reading⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-97163 - Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29

CVE ID :CVE-2026-97163 Published : Sept. 26, 2026, 3:16 p.m. | 8 hours, 21 minutes ago Description :Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 Severity: 10.0 | CRITICAL Vis

$> CVE Critical⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-82901 - Ultra Addons for Contact Form 7 <= 3.5.50 - Unauthenticated Arbitrary File Upload via Signature Form Field

CVE ID :CVE-2026-82901 Published : Sept. 26, 2026, 7:16 p.m. | 4 hours, 21 minutes ago Description :The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7

$> CVE Critical⏱️ 1m
→
🛡️ Cybersecurity

Why Your Rules Engine Deserves Its Own Kubernetes Node Pool

Dedicated Kubernetes node pools can isolate latency-sensitive rules engines, but the decision should be based on measured contention and resource needs.

$> Hacker Noon⏱️ 1m
→
🛡️ Cybersecurity

Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site. The cross-site reques

$> Hacker News⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-97162 - Joomla Extension - lomart.fr - Various SQL injection vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29

CVE ID :CVE-2026-97162 Published : Sept. 26, 2026, 3:16 p.m. | 8 hours, 21 minutes ago Description :Joomla Extension - lomart.fr - Various SQL injection vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 Severity: 8.3 | HIGH Visit the link for

$> CVE Critical⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-85984 - miniOrange OTP Login, Verification and SMS Notifications <= 5.5.5 - Unauthenticated Authentication Bypass via 'mo_wp_login_intent' Parameter

CVE ID :CVE-2026-85984 Published : Sept. 26, 2026, 6:16 p.m. | 5 hours, 21 minutes ago Description :The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent pa

$> CVE Critical⏱️ 1m
→
🛡️ Cybersecurity

Roundcube Webmail Vulnerability in Attackers’ Crosshairs

Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication. The post Roundcube Webmail Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek.

$> SecurityWeek⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-94398 - Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service

CVE ID :CVE-2026-94398 Published : Sept. 26, 2026, 9:16 p.m. | 2 hours, 8 minutes ago Description :Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Severity: 6.5 | MEDIUM Vis

$> CVE Feed⏱️ 1m
→
🛡️ Cybersecurity

Deception by Design: CISA's Guide to Tricking Cybercriminals

The Cybersecurity and Infrastructure Security Agency (CISA) is going old school to help organizations with limited resources set traps for hackers.

$> Dark Reading⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-77203 - Groups <= 4.6.0 - Authenticated (Subscriber+) Privilege Escalation via 'groups_join' Shortcode

CVE ID :CVE-2026-77203 Published : Sept. 26, 2026, 6:16 p.m. | 5 hours, 21 minutes ago Description :The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.6.0. Th

$> CVE Critical⏱️ 1m
→
🛡️ Cybersecurity

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The

$> Hacker News⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-94408 - Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service

CVE ID :CVE-2026-94408 Published : Sept. 26, 2026, 9:16 p.m. | 2 hours, 8 minutes ago Description :Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Severity: 4.9 | MEDIUM Vis

$> CVE Feed⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-100739 - mathurvishal CloudClassroom-PHP-Project viewresult.php sql injection

CVE ID :CVE-2026-100739 Published : Sept. 26, 2026, 10:16 p.m. | 1 hour, 9 minutes ago Description :A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown functi

$> CVE Feed⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-94399 - Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service

CVE ID :CVE-2026-94399 Published : Sept. 26, 2026, 9:16 p.m. | 2 hours, 8 minutes ago Description :Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Severity: 6.5 | MEDIUM Vis

$> CVE Feed⏱️ 1m
→
🛡️ Cybersecurity

CVE-2026-94400 - Uncontrolled Resource Consumption in Kibana Leading to denial of service

CVE ID :CVE-2026-94400 Published : Sept. 26, 2026, 9:16 p.m. | 2 hours, 8 minutes ago Description :Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130) Severity: 6.5 | MEDIUM Visit the

$> CVE Feed⏱️ 1m
→
🛡️ Cybersecurity

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable serve

$> BleepingComputer⏱️ 1m
→
🛡️ Cybersecurity

‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration

Three vulnerabilities in Salesforce Agentforce allowed hackers to hijack trusted agents, steal data, and launch phishing attacks. The post ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration appeared first on SecurityWeek

$> SecurityWeek⏱️ 1m
→
🛡️ Cybersecurity

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score

$> Hacker News⏱️ 1m
→

🔬 Science/Research

2

🇲🇾 Malaysia/Lokal

1

📌 Lain-lain

2