⏐ Taklimat Pagi
Taklimat Pagi Saya
🔗 baca_penuh: pagi.hejes.my/2026/09/27
> ringkasan_ai
# 🤖 AI & Machine Learning
✅ **GPT-5.5 Instant & Claude Opus 5.5** [OpenAI / BleepingComputer] — OpenAI lancar GPT-5.5 Instant yang lebih *smart* dan kurang halusinasi, manakala Claude Opus 5.5 kini menulis dengan gaya lebih natural (kurang gaya "AI").💡 **Kenapa Penting** — Model AI makin *human-like* dan efisien, Master boleh guna untuk kerja yang lebih kompleks.
✅ **OpenAI & Isu Privasi/Keselamatan** [SecurityWeek / BleepingComputer] — AI agents OpenAI kantoi akses laman web kerajaan US dan terlepas *upload* gambar user ke site pihak ketiga.💡 **Kenapa Penting** — Master kena hati-hati dengan data sensitif bila guna AI agents.
✅ **MRC (Multipath Reliable Connection)** [OpenAI] — Protokol networking baru untuk buat *training* AI skala besar jadi lebih stabil dan laju.💡 **Kenapa Penting** — Ini kunci untuk lahirkan model AI yang jauh lebih power lepas ni.
✅ **Muse Integrasi Spotify & TenPayGo Tencent** [Amanz] — Meta bawa Muse masuk Spotify untuk kawalan suara, manakala Tencent mudahkan pelancong guna kad bank luar di China.💡 **Kenapa Penting** — Ekosistem digital makin *seamless*, tak payah pening fikir pasal *payment* atau butang.
✅ **SmolLM3 & Julia 1** [HuggingFace / MarkTechPost] — Model AI kecil (small models) yang power untuk *reasoning* dan boleh jalan atas CPU biasa.💡 **Kenapa Penting** — AI tak semestinya kena guna GPU mahal; model kecil pun dah cukup *kick*.
# 🛡️ Cybersecurity (Hati-hati Master!)
✅ **Serangan Oracle PeopleSoft & ShinyHunters** [BleepingComputer / Hacker News] — Geng ShinyHunters guna trik *bypass* WAF untuk eksploitasi CVE-2026-35273 dan tanam *web shells*.💡 **Kenapa Penting** — *Firewall* biasa mungkin tak cukup kalau *attacker* guna trik *encoding*.
✅ **Kritikal: WordPress & Joomla Vulnerabilities** [CVE Feed / Hacker News] — Banyak *plugin* (Elementor, miniOrange, UP plugin) ada lubang besar yang boleh bawa kepada *Remote Code Execution* (RCE) dan *Privilege Escalation*.💡 **Kenapa Penting** — Kalau Master ada site WordPress/Joomla, tolong *update* semua *plugin* sekarang juga!
✅ **SalesBleed & Salesforce Agentforce** [SecurityWeek] — Tiga lubang keselamatan dalam Salesforce Agentforce benarkan *zero-click data exfiltration*.💡 **Kenapa Penting** — AI agents dalam korporat pun boleh kena *hijack* untuk curi data.
✅ **Elasticsearch & Kibana DoS** [CVE Feed] — Beberapa CVE baru (CVE-2026-94398 dll) boleh buatkan servis Elasticsearch/Kibana *crash* (Denial of Service).💡 **Kenapa Penting** — Boleh ganggu kestabilan *database* dan *monitoring* sistem Master.
# 💻 Tech, Dev & Gadgets
✅ **Apple & Qualcomm Renew License** [Amanz] — Dua gergasi ni sambung lagi perjanjian lesen paten sampai 2027.💡 **Kenapa Penting** — Modem 5G dalam iPhone akan terus stabil tanpa drama mahkamah.
✅ **Honor X9e Pro Masuk Malaysia** [Amanz] — Telefon tahan lasak dengan bateri raksasa 11,000 mAh, harga bermula RM1899.💡 **Kenapa Penting** — Sesuai kalau Master nak phone yang tak payah cas selalu dan tak pecah kalau terjatuh.
✅ **Microsoft Pause Update KB5002907** [BleepingComputer] — Update Office terbaru buatkan lesen Office 2016/2019 hilang tiba-tiba.💡 **Kenapa Penting** — Jangan *update* Office dulu kalau tak nak lesen *deactivate* sendiri.
# 🌍 Lain-lain
✅ **TikTok Bayar $100M Settlement** [TechCrunch] — TikTok setuju bayar denda di Alabama sebab didakwa buat budak-budak ketagih.💡 **Kenapa Penting** — Tekanan undang-undang terhadap *social media* makin kuat.
🔥 Top Picks
**GPT-5.5 Instant & Claude Opus 5.5** (AI makin bijak, Master kena *keep up*!)
**Oracle PeopleSoft & ShinyHunters** (Amaran keras untuk *security* infrastruktur).
**Honor X9e Pro** (Bateri 11,000 mAh tu memang gila, Master!)
> ls -la berita/
🧠 AI/ML
28Claude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer
Anthropic's Claude Opus 5.5 appears to be changing how it writes, with new analysis showing fewer obvious AI writing patterns, shorter sentences, and simpler wording compared with Opus 5. [...]
Three Mighty Alerts Supporting Hugging Face’s Production Infrastructure
Muse Diintegrasikan Ke Spotify Untuk Kawalan Audio Melalui Arahan Suara
Meta sebelum ini telah memperkenalkan Muse sebagai agen peribadi pintar. Melalui kemas kini terkini, Muse mula diintegrasikan ke dalam Spotify. Kehadiran Muse ini menjadikan kawalan audio lebih mudah kerana pengguna boleh memainkan lagu, mendengar po
Levoit’s new air purifier is for the pet odors that have taken over your apartment
This $189.99 air purifier is specifically designed to tackle pet odors, removing up to 70% in one hour.
SmolLM3: smol, multilingual, long-context reasoner
I created an interactive digital avatar of myself — and you can talk to it
After obtaining an interactive avatar and training it to discuss venture fraud, I have mixed feelings about making AI clones of ourselves.
New ways to buy ChatGPT ads
OpenAI expands ChatGPT ads with a beta self-serve Ads Manager, CPC bidding, and enhanced measurement tools—built to protect privacy and keep conversations separate from ads.
GPT-5.5 Instant System Card
New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions. The post New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining appeared first on SecurityWeek.
OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure
OpenAI’s CEO said there is an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation.” The post OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure appeare
AI-Assisted Genealogy: Using AI to Trace My Family Tree
I continue working on my tree, and I have deepened my understanding of the subject. In this post, I want to share again.
Unlocking large scale AI training networks with MRC (Multipath Reliable Connection)
OpenAI introduces MRC (Multipath Reliable Connection), a new supercomputer networking protocol released via OCP to improve resilience and performance in large-scale AI training clusters.
Sarvam AI Releases Saaras V4: A Speech-to-Text Model for All 22 Indian Languages and Global English
Sarvam AI's Saaras V4 is a speech-to-text model covering all 22 Indian languages plus global English. It pairs an audio encoder with a 3B hybrid state-space decoder. It adds keyterm prompting for up to 50 terms, 5 output modes from 1 model, and strea
Tencent Lancarkan TenPayGo Untuk Pelancong Gunakan Kad Bank dan Dompet Digital Tempatan Di China
Melancong ke China ialah seperti pergi ke Marikh kerana ia adalah negara nirtunai sepenuhnya sehingga pengemis mempunyai kod QR untuk menerima derma. Isu yang berlaku ialah sistem nirtunai di China tidak menyokong kad kredit, debit atau dompet digita
When Your Voice Agent Enters the Scene, Ft. GPT-Live
A starship docking game is where the user can collaborate with a AI agent using voice. The game examplifies how to build voice agents with GPT-Live.
Advancing youth safety and wellbeing in EMEA
Explore OpenAI’s European Youth Safety Blueprint and EMEA Youth & Wellbeing Grants, advancing safe, responsible AI for teens, families, and educators.
Zero Trust for AI Agents Starts With Fixing Zero Visibility
The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a str
Infinix Lancar Alat Kalawan GT NX Controller Dan Dok GT NX Station – Harga Bermula RM299
Infinix telah melancarkan siri aksesori GT NX yang terdiri daripada GT NX Controller dan GT NX Station. Kedua-dua perkakasan ini memfokuskan kepada memberikan alat kawalan terbaik dan juga menyelesaikan masalah... The post Infinix Lancar Alat Kalawan
GPT-5.5 Instant: smarter, clearer, and more personalized
GPT-5.5 Instant updates ChatGPT’s default model with smarter, more accurate answers, reduced hallucinations, and improved personalization controls.
Upskill your LLMs With Gradio MCP Servers
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which describ
Supersonic Labs Releases Julia 1: A 144.3M-Parameter Open Decision Model That Runs on a CPU
Supersonic Labs has released Julia 1, a 144.3M-parameter decision model built on mmBERT-small. It takes context, a question, and 2 to 20 options, then returns one choice with probabilities. The model runs on a CPU and ships under Apache 2.0. It beat
China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks
The US and China agreed to set up a communication mechanism for artificial intelligence-related incidents. The post China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks appeared first on SecurityWeek.
GitHub Actions re-enabled with Mini Shai-Hulud payload still active
Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code. [...]
OpenAI's AI agents accidentally uploaded user-provided images to third-party sites
OpenAI says its AI agents uploaded user-provided images to third-party image-hosting services while carrying out research and evaluation tasks. [...]
Insurers claim AI is already increasing healthcare costs
Blue Cross Blue Shield says hospital use of AI tools led to an additional $942M in healthcare spending over a two-year period.
Announcing NeurIPS 2025 E2LM Competition: Early Training Evaluation of Language Models
Microsoft Menamatkan Penjenamaan Copilot+ PC
Dua tahun lalu, penjenamaan Copilot+ PC diperkenalkan dengan ia menggantikan penjenamaan AI PC sebelumnya. Pada ketika itu, Copilot+ PC ialah penjenamaan yang digunakan pada komputer Windows 11 yang memenuhi keperluan minima kuasa memproses 45 TOPS u
⚡ Tech/Dev
7Qualcomm dan Apple Melanjutkan Perjanjian Lesen Paten
Qualcomm dan Apple telah memperbaharui perjanjian lesen paten global mereka, yang akan berkuat kuasa mulai 1 April 2027. Pengumuman ini dibuat oleh Qualcomm pagi ini dalam satu siaran media yang pendek. Qualcomm tidak mendedahkan butiran kewangan, te
Meta and YouTube say they will run ads for ‘Musk’ documentary after all
Two companies now say they will accept advertising for director Alex Gibney’s upcoming documentary about Elon Musk, following earlier reporting that a number of social media platforms had rejected the ads.
Microsoft pauses KB5002907 update after Office license deactivations
Microsoft has paused the rollout of the KB5002907 Microsoft 365 update after users report that it deactivated, or in some cases completely removed, perpetual Office 2016 and Office 2019 installations. [...]
When Does Working Software Actually Become Legacy Software?
Working software can still become legacy. Learn how security, maintenance, knowledge gaps, dependencies, and change costs reveal when software is aging.
End-to-End Multimodal Data Augmentation and Adversarial Robustness Benchmark with AugLy for Images, Text, Audio, and PyTorch
Discover how to build a comprehensive multimodal augmentation and adversarial robustness workflow using AugLy for images, text, audio, and PyTorch datasets. The post End-to-End Multimodal Data Augmentation and Adversarial Robustness Benchmark with Au
The Wanted Man Tiba Di Apple TV Januari 2027 – Hugh Laurie, Thandiwe Newton, Fionn Whitehead
Apple TV telah mengumumkan siri drama jenayah lapan episod terbaharu dengan judul The Wanted Man yang diterajui dan diterbitkan secara eksekutif oleh pelakon terkenal Hugh Laurie, bintang siri House dan... The post The Wanted Man Tiba Di Apple TV Jan
Exa Launches Agent Ultra: A Subagent Swarm Deep Research API Built for Exhaustive List Building
Exa has released Agent Ultra, the highest effort mode of its Exa Agent API. It coordinates subagents across thousands of sources for list building and entity enrichment. Exa reports it beats Opus 5.5, GPT-6 Astra, and Perplexity Agent on 4 benchmarks
🛡️ Cybersecurity
19SASE Converges Network & Security Into One Cloud Solution
Enterprise computing is moving to the edge. Keeping it secure requires tactics far beyond putting up firewalls. (Second in a three-part series.)
CVE-2026-97163 - Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
CVE ID :CVE-2026-97163 Published : Sept. 26, 2026, 3:16 p.m. | 8 hours, 21 minutes ago Description :Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 Severity: 10.0 | CRITICAL Vis
CVE-2026-82901 - Ultra Addons for Contact Form 7 <= 3.5.50 - Unauthenticated Arbitrary File Upload via Signature Form Field
CVE ID :CVE-2026-82901 Published : Sept. 26, 2026, 7:16 p.m. | 4 hours, 21 minutes ago Description :The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7
Why Your Rules Engine Deserves Its Own Kubernetes Node Pool
Dedicated Kubernetes node pools can isolate latency-sensitive rules engines, but the decision should be based on measured contention and resource needs.
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site. The cross-site reques
CVE-2026-97162 - Joomla Extension - lomart.fr - Various SQL injection vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
CVE ID :CVE-2026-97162 Published : Sept. 26, 2026, 3:16 p.m. | 8 hours, 21 minutes ago Description :Joomla Extension - lomart.fr - Various SQL injection vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 Severity: 8.3 | HIGH Visit the link for
CVE-2026-85984 - miniOrange OTP Login, Verification and SMS Notifications <= 5.5.5 - Unauthenticated Authentication Bypass via 'mo_wp_login_intent' Parameter
CVE ID :CVE-2026-85984 Published : Sept. 26, 2026, 6:16 p.m. | 5 hours, 21 minutes ago Description :The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent pa
Roundcube Webmail Vulnerability in Attackers’ Crosshairs
Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication. The post Roundcube Webmail Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek.
CVE-2026-94398 - Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service
CVE ID :CVE-2026-94398 Published : Sept. 26, 2026, 9:16 p.m. | 2 hours, 8 minutes ago Description :Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Severity: 6.5 | MEDIUM Vis
Deception by Design: CISA's Guide to Tricking Cybercriminals
The Cybersecurity and Infrastructure Security Agency (CISA) is going old school to help organizations with limited resources set traps for hackers.
CVE-2026-77203 - Groups <= 4.6.0 - Authenticated (Subscriber+) Privilege Escalation via 'groups_join' Shortcode
CVE ID :CVE-2026-77203 Published : Sept. 26, 2026, 6:16 p.m. | 5 hours, 21 minutes ago Description :The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.6.0. Th
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The
CVE-2026-94408 - Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service
CVE ID :CVE-2026-94408 Published : Sept. 26, 2026, 9:16 p.m. | 2 hours, 8 minutes ago Description :Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Severity: 4.9 | MEDIUM Vis
CVE-2026-100739 - mathurvishal CloudClassroom-PHP-Project viewresult.php sql injection
CVE ID :CVE-2026-100739 Published : Sept. 26, 2026, 10:16 p.m. | 1 hour, 9 minutes ago Description :A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown functi
CVE-2026-94399 - Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service
CVE ID :CVE-2026-94399 Published : Sept. 26, 2026, 9:16 p.m. | 2 hours, 8 minutes ago Description :Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Severity: 6.5 | MEDIUM Vis
CVE-2026-94400 - Uncontrolled Resource Consumption in Kibana Leading to denial of service
CVE ID :CVE-2026-94400 Published : Sept. 26, 2026, 9:16 p.m. | 2 hours, 8 minutes ago Description :Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130) Severity: 6.5 | MEDIUM Visit the
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable serve
‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
Three vulnerabilities in Salesforce Agentforce allowed hackers to hijack trusted agents, steal data, and launch phishing attacks. The post ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration appeared first on SecurityWeek
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score
🔬 Science/Research
2TikTok agrees to pay at least $100M in Alabama settlement
TikTok will pay Alabama at least $100 million in a settlement tied to allegations that the short-form video platform misled users about safety and was designed to addict children.
Uniqlo Hadir Dengan Tshirt Kolaborasi Disney x F1
Uniqlo telah mengumumkan penawaran koleksi Tshirt gabungan jenama Formula 1 dan Disney. Koleksi tersebut sudah mula ditawarkan pada 21 September 2026. Pelancaran ini sudah semestinya bersesuaian dengan F1 akan kembali... The post Uniqlo Hadir Dengan