⏐ Taklimat Pagi
Taklimat Pagi Saya
🔗 baca_penuh: pagi.hejes.my/2026/09/29
> ringkasan_ai
# 🤖 AI & Machine Learning
✅ **GPT-6 Astra & Ember-1** [OpenAI / MarkTechPost] — GPT-6 Astra kini 2x lebih laju buat kerja kompleks (tax workbook), manakala Ember-1 dari Fireworks AI boleh kurangkan penggunaan token sampai 40%.💡 **Kenapa Penting** — Efisiensi makin tinggi, kos token makin murah, kerja Master makin cepat siap.
✅ **Kebangkitan & Bahaya AI Agents** [Dark Reading / BleepingComputer / NVIDIA] — Ada kes *JadePuffer* guna AI agent untuk musnahkan resource Azure, dan *Carbonato Botnet* guna AI untuk curi API keys. NVIDIA respon dengan lancar *Open Agent Safety Platform* untuk 'kurung' (sandbox) agent ni.💡 **Kenapa Penting** — AI agent ada privilege tinggi; kalau tak ada audit/safety, dia boleh jadi *insider threat* paling teruk.
✅ **AMD Ambil Alih World Labs** [TechCrunch] — AMD beli syarikat Fei-Fei Li dengan harga $8.2 bilion untuk kuatkan lagi bahagian sains AI mereka.💡 **Kenapa Penting** — AMD tengah *all-out* nak lawan NVIDIA dalam hardware & software AI.
✅ **Gadget & Gaming** [Amanz / Aksiz] — Canon EOS R8 Mark II masuk Malaysia (RM6,999), Honor Magic9 Super Edition ada bateri raksasa 11,000mAh, dan Ace Combat 8 bakal launch kat Singapura Oktober ni.💡 **Kenapa Penting** — Saja nak update Master kalau Master rasa nak *shopping* atau *gaming* hujung minggu ni.
# 🛡️ Cybersecurity
✅ **Kebocoran Data Besar-Besaran** [BleepingComputer / SecurityWeek] — Times Car (6.6 juta akaun), DC Health Agency (400k rekod), dan 16,000 database Supabase terdedah sebab salah konfigurasi.💡 **Kenapa Penting** — Peringatan untuk kita check balik *permission* database supaya tak jadi mangsa seterusnya.
✅ **Serangan & Malware Baru** [Hacker News / Dark Reading] — Malware *RatHat* guna Gemini AI untuk cari mangsa 'high-value', dan *NeedyMantis* digunakan untuk maintain akses jangka panjang dalam network.💡 **Kenapa Penting** — Hacker sekarang dah guna AI untuk *target* mangsa dengan lebih tepat.
✅ **Update Security Apple & Google** [Hacker News / SecurityWeek] — Apple patch flaw CoreGraphics yang mungkin dah dieksploitasi, manakala Google beri amaran pasal kempen ShinyHunters target Oracle PeopleSoft.💡 **Kenapa Penting** — Master, tolong update semua OS dan software sekarang sebelum kena *hack*.
✅ **CVE Alert (Critical)** [CVE Feed] — Banyak vulnerability baru dikesan pada Nginx Proxy Manager, Ziroom ZHOME, dan ZoneMinder (buffer overflow/injection).💡 **Kenapa Penting** — Kalau Master ada guna tool ni, sila patch segera.
# 🌍 Lain-lain & Lokal
✅ **Dokumentari Palestin di Tonton** [Aksiz] — Filem *No Other Land* dan *The Voice of Hind Rajab* akan masuk platform Tonton 30 September ni.💡 **Kenapa Penting** — Naskhah penting untuk kesedaran isu kemanusiaan di Palestin.
✅ **Tiket Avengers: Doomsday Ditunda** [Aksiz] — GSC dan TGV tunda jualan awal tiket, tarikh baru belum tahu lagi.💡 **Kenapa Penting** — Jangan pergi cinema dulu, nanti hampa.
🔥 Top Picks
**AI Agent Safety (NVIDIA vs JadePuffer)** — Isu paling kritikal sebab melibatkan kawalan autonomi AI.
**AMD Acquisition of World Labs** — Perubahan besar dalam landskap hardware AI global.
**GPT-6 Astra** — Lonjakan prestasi yang ketara berbanding versi sebelumnya.
> ls -la berita/
🧠 AI/ML
37Canon EOS R8 Mark II Disenaraikan Di Malaysia Dengan Harga Bermula RM6999
Kamera baharu Canon EOS R8 Mark II kini mula tersenarai di laman web rasmi Canon Malaysia bersama harga jualan tempatan. Kamera ini ditawarkan pada harga bermula RM6,999 untuk badan sahaja. Canon turut menyediakan beberapa pakej lain termasuklah deng
Acara Pelancaran Rasmi Ace Combat 8: Wings of Theve Bakal Berlangsung Di Singapura Oktober Ini
Bandai Namco mengesahkan penganjuran acara pelancaran rasmi untuk ACE COMBAT 8: WINGS OF THEVE yang dibuka kepada orang awam di Orchard Central, Singapura dari 7 hingga 11 Oktober 2026. Penganjuran... The post Acara Pelancaran Rasmi Ace Combat 8: Win
When Is a Multi-Agent Code Judge Actually Grounded? Two Label-Free Measurements, and a Judge That Declines to Guess
arXiv:2609.30328v1 Announce Type: new Abstract: When one language model judges whether another's code is correct, it does not report the absence of evidence. It returns a confident verdict with reasoning attached, indistinguishable from a verdict it
IAM for AI agents: A Practical Enterprise Framework
What is IAM for AI agents? AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the identity-control architecture that governs those actors. This guide covers the limits of conventiona
Source: Inference provider Modal Labs closing in on $750M round at $15.75B valuation
The new financing is expected to more than triples the AI infrastructure startup's valuation from just four months ago.
Japan's Keio confirms ransomware attack disrupted business systems
Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. [...]
Our commitment to community safety
Learn how OpenAI protects community safety in ChatGPT through model safeguards, misuse detection, policy enforcement, and collaboration with safety experts.
Featherless AI on Hugging Face Inference Providers 🔥
DC Health Agency Exposes 400,000 Beneficiary Records
The Medicaid IDs and other information of Medicaid and DC Healthcare Alliance beneficiaries were exposed. The post DC Health Agency Exposes 400,000 Beneficiary Records appeared first on SecurityWeek.
Fireworks AI Releases Ember-1: A Post-Trained Kimi K3 That Uses About 40% Fewer Tokens
Fireworks AI has released Ember-1, a post-trained Kimi K3 that learns to produce shorter reasoning traces instead of lowering reasoning effort. Fireworks reports about 40% fewer tokens, with output tokens per task falling from 49.3K to 29.9K in a pro
Aurora CFO says 30,000 driverless trucks by 2030 isn’t as far-fetched as it sounds
Self-driving truck company Aurora laid out an audacious plan for 2030. Its CFO says its targets aren't aspirational.
JadePuffer agentic AI attacks target Azure, destroy cloud resources
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components. [...]
Autoheal Raises $7.9M From Innovation Endeavors to Make Enterprise Software Heal Itself
Autoheal raises $7.9M led by Innovation Endeavors for self-healing AI agents that fix incidents, patch security flaws and cut AI coding costs at Nomura.
Groq on Hugging Face Inference Providers 🔥
Musim Pertama Modern Warfare 4 Hadkan Fungsi Senjata Lama dan Perkenal Pilihan Sembunyi Kosmetik Dalam Call of Duty: Warzone
Pelancaran musim pertama Modern Warfare 4 bakal membawa perubahan terhadap sistem kandungan lama serta kawalan visual pemain dalam Call of Duty: Warzone. Menerusi kemaskini tersebut, pemain masih boleh menggunakan kandungan... The post Musim Pertama
Learn the Hugging Face Kernel Hub in 5 Minutes
20 Agentic Use Cases of TypeSafe AI’s Jev
TypeSafe AI's Jev skips text generation and returns typed decisions with calibrated probabilities. Input costs $0.042 per million tokens and output is free. We verified 20 agentic use cases, from model routing and tool-call gating to reranking and in
Google Research Introduces an AI Video Co-Director: 4 Agentic Frameworks for Coherent, Minutes-Long Video Generation
Google Research has introduced an AI video co-director for long-form video generation. The suite of 4 agentic frameworks turns short clips into coherent, minutes-long stories. It targets identity drift and cascading errors, the 2 failures that break
AI Agents Are Privileged Users; Who Is Auditing Their Access?
Enterprises regularly rigorously monitor human employees, while autonomous AI agents quietly operate with broad privileges that could turn them into the next generation of insider threats.
Modulate Raises $25 Million to Advance Deepfake Detection
The misuse and abuse of AI-generated voice is growing. Modulate’s intention is to allow real time detection and intervention. The post Modulate Raises $25 Million to Advance Deepfake Detection appeared first on SecurityWeek.
Basis completes a tax workbook 2x faster with GPT-6 Astra
GPT-6 Astra completed a 50-tab tax workbook twice as fast as GPT-5.6 Sol, and its stronger understanding of user intent gives Basis more confidence in real-world use.
Bringing AI to Autonomous Systems -- From Cognition to Collective Intelligence
arXiv:2609.30291v1 Announce Type: new Abstract: The purpose of this article is to highlight the central role of autonomous systems as the ultimate stage in the development of AI, to explain the underlying technical challenges that require a combinati
Watch the winning trailer from the Future Vision XPRIZE, The Gifted.
Watch the winning trailer from the Future Vision XPRIZE, The Gifted.
Sony Menarik Diri Daripada CES 2027
Sony Group mengumumkan mereka dan anak syarikat akan menarik diri daripada menyertai Consumer Electronics Show di Las Vegas pada tahun 2027. Ini ialah kali pertama sejak 1967 Sony tidak menyertai acara yang memaparkan teknologi terkini kepada umum. a
NVIDIA Launches Open Agent Safety Platform: OpenShell Sandboxes Agents on Vera CPUs While Sentry on BlueField-4 Quarantines Them in Milliseconds
NVIDIA has launched the Open Agent Safety Platform, an open reference design that enforces AI agent safety outside the agent itself. OpenShell, an Apache 2.0 runtime, sandboxes agents under YAML policies. Sentry, an out-of-band watchdog on BlueField-
Bridging LLM Agents and Data Spaces: An Architectural Mediation Approach using the Model Context Protocol
arXiv:2609.30341v1 Announce Type: new Abstract: Data Spaces enable sovereign and governed data sharing across organizational boundaries, but their integration with AI agents remains challenging due to mismatches between probabilistic language model i
Honor Magic9 Super Edition Diperkenalkan Dengan Bateri Besar 11,000mAh
Selain model standard Magic 9 dan Magic 9 Pro Max, siri ini turut memperkenalkan Magic 9 Super Edition. Versi ini hadir dengan bateri berkapasiti terbesar yang pernah digunakan dalam siri Magic. Namun begitu, penggunaan bateri sebesar ini bukanlah se
Meet Qodo: HackerNoon Company of the Week
Meet Qodo, HackerNoon’s Company of the Week, an AI code review and governance platform helping enterprise engineering teams maintain software quality.
OpenAI reportedly ditches model over safety concerns
A top executive at the AI lab told the Wall Street Journal that the model in question had displayed a poor aptitude for following orders.
The Lenfest Institute grows landmark program with expanded OpenAI support
OpenAI is expanding the Lenfest AI Collaborative and Fellowship Program with $5 million in funding and up to $5 million in software credits and engineering support.
How Long Prompts Block Other Requests - Optimizing LLM Performance
Ulasan Terbang
Karamjit Singh merupakan satu nama yang bagi saya cukup besar, walaupun bukan peminat lumba kereta terutama rali, masih ramai yang akan mengenali nama tersebut. Beliau juga terkenal dengan gelaran Flying... The post Ulasan Terbang first appeared on A
Shopify opens checkout to browser-based AI agents
Shopify is expanding WebMCP support to checkout, allowing browser-based AI agents to update order details and complete purchases with a buyer’s authorization.
BeONE Mobile Diperkenalkan Sebagai Perkhidmatan MVNO Terbaru Dikuasakan Rangkaian Maxis
Sebuah syarikat rangkaian telekomunikasi baru telah dibangunkan, dan ia adalah sebuah MVNO (Mobile Virtual Network Operator) baru yang bernama BeONE Mobile, yang membekalkan perkhidmatan rangkaian pra-bayar untuk pelbagai lapisan masyarakat dan perni
Email Marketing Knowledgebase: Platform Dependency And Resurrections [Part One]
A blocked Udemy course. A four-year-old abandoned GitHub repo. One dev's path from platform dependency to owning his own content stack.
Who’s liable when AI agents go rogue?
MIT Technology Review Explains: Let our writers untangle the complex, messy world of technology to help you understand what’s coming next. You can read more from the series here. Over the past few months, a cascade of cyberattacks by AI agents has st
When can we say AI made a scientific discovery?
This story originally appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here. Last Wednesday, Anthropic announced that earlier this year it had launched a molecular biology lab, where Claude
🛡️ Cybersecurity
26CVE-2026-101261 - Ziroom ZHOME A0101 firstSetup_wifi command injection
CVE ID :CVE-2026-101261 Published : Sept. 28, 2026, 10:30 p.m. | 56 minutes ago Description :A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown part of the file /api/ZRnetwork/firstSetup_wifi. Executing a manipulation of the
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impact
JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack
The "agentic threat actor" may have used exposed credentials to access resources and delete cloud-based storage, applications, and databases.
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273. The post Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign appeared first on SecurityWeek.
Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts
The botnet uses the open source Hermes Agent AI framework to execute commands via Telegram and steal AI API keys from exposed Docker hosts.
ScopeBench: Do Agents Preserve Engagement Boundaries Under Goal Pressure?
arXiv:2609.30325v1 Announce Type: new Abstract: Agents are increasingly deployed with real autonomy in web application and network penetration testing, where a single out-of-scope action can breach a client's engagement boundary. Existing offensive-s
Cybersecurity in the Intelligence Age
OpenAI outlines a five-part action plan for strengthening cybersecurity in the Intelligence Age, focused on democratizing AI-powered cyber defense and protecting critical systems.
CVE-2026-102334 - Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection
CVE ID :CVE-2026-102334 Published : Sept. 28, 2026, 10:21 p.m. | 1 hour, 5 minutes ago Description :Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password gues
Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at telecommunications
CVE-2024-42002 - Unsafe use of eval() method in ros2 topic hz tool
CVE ID :CVE-2024-42002 Published : Sept. 28, 2026, 10:17 p.m. | 1 hour, 32 minutes ago Description :A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distribu
Dutch police confirm arrest in ShinyHunters hacking investigation
Dutch police have confirmed that a 24-year-old Amsterdam man arrested earlier this month was detained as part of an investigation into the ShinyHunters hacking group. [...]
CVE-2026-102335 - Nginx Proxy Manager through 2.16.0 Improper Authorization via advanced_config
CVE ID :CVE-2026-102335 Published : Sept. 28, 2026, 10:21 p.m. | 1 hour, 5 minutes ago Description :Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to
CVE-2026-102296 - ZoneMinder before 1.38.4 Buffer Overflow via HTTP Camera Response
CVE ID :CVE-2026-102296 Published : Sept. 28, 2026, 10:17 p.m. | 1 hour, 32 minutes ago Description :ZoneMinder before 1.38.4 contains static buffer overflow vulnerabilities in RemoteCameraHttp::GetResponse() that allow malicious HTTP cameras or inte
One Packet Can Crash OT Servers in Industrial Sectors
A high-severity zero-day vulnerability affects the TDengine time-series database used across industrial, IoT, energy, and automotive environments.
Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M
The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level i
Call for Presentations Open for 2026 CISO Forum Virtual Summit
SecurityWeek seeks original, vendor-neutral presentations that help cybersecurity leaders navigate emerging threats, strengthen resilience, and address the strategic challenges facing today’s enterprise security programs. The post Call for Presentati
Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon
Cameron John Wagenius was sentenced to 70 months in prison for stealing information from the wireless carriers. The post Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon appeared first on SecurityWeek.
CVE-2026-101260 - Ziroom ZHOME A0101 firstLogin command injection
CVE ID :CVE-2026-101260 Published : Sept. 28, 2026, 11:17 p.m. | 33 minutes ago Description :A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. Affected by this issue is some unknown functionality of the file /api/ZRnetwork/firstLogin. Perfo
CVE-2026-102361 - mall4j through 4.0 Missing Authentication in Password Update Endpoint
CVE ID :CVE-2026-102361 Published : Sept. 28, 2026, 11:34 p.m. | 15 minutes ago Description :mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any sto
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malwa
CVE-2026-101262 - Ziroom ZHOME A0101 set_online_client command injection
CVE ID :CVE-2026-101262 Published : Sept. 28, 2026, 10:45 p.m. | 41 minutes ago Description :A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown code of the file /api/ZRQos/set_online_client. The manipulat
Times Car confirms data breach affecting 6.6 million user accounts
Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. [...]
Stealth Apart, Harm Together: Skill Cascading Attacks on Skill-Based Agent Systems
arXiv:2609.30383v1 Announce Type: new Abstract: A skill is a modular package of natural-language instructions, executable scripts, and reference resources that an agent can load at runtime to extend its capabilities for a specific task. Skill-based a
CVE-2026-101188 - Netcore POWER13 ubus routerd.passwd_set password recovery
CVE ID :CVE-2026-101188 Published : Sept. 28, 2026, 10:17 p.m. | 1 hour, 32 minutes ago Description :A security vulnerability has been detected in Netcore POWER13 2.0.240730.162638. This issue affects the function routerd.passwd_set of the file /ubus
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining Shiny
CVE-2026-102333 - httpdbg before 2.2.1 Stored Cross-Site Scripting via javascript URL
CVE ID :CVE-2026-102333 Published : Sept. 28, 2026, 10:21 p.m. | 1 hour, 5 minutes ago Description :httpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request URLs rendered as clickable links in the web interface. Attackers controlli
📌 Lain-lain
2Holo4: powering generalist computer-use agents
What If the World Had Only One Central Bank and One Global Currency?
Could one global currency simplify life or create a financial Big Brother? Discover why convenience might come at a hefty price.
🔬 Science/Research
2Over 16,000 Supabase databases expose PII, passwords, auth tokens
Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens. [...]
AMD will acquire Fei-Fei Li’s World Labs for $8.2 billion
The acquisition will see World Labs founder Fei-Fei Li join AMD as executive vice president and chief scientist.
🇲🇾 Malaysia/Lokal
1⚡ Tech/Dev
5Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions
A purported ad-blocker exfiltrates reams of sensitive information and benefits from having Google's stamp of approval despite researcher warnings.
Project SkySim, Part 1: The Case for a Drone Simulator That Runs in Your Browser
Every serious drone simulator asks you to install Linux, ROS, or a game engine before you can test a single line of your own code. So, I built my own one.
Are you a Codex Original?
We’re collecting real stories of builders, tinkerers, researchers, and creators who are using Codex to do incredible things. If you want to be a part of the next chapter of the Codex Originals program, tell us more about your story and project below.
Jualan Awal Tiket Avengers: Doomsday Ditunda
GSC dan TGV Cinema telah mengumumkan yang jualan awal tiket untuk Avengers: Doomsday yang sepatutnya bermula hari ini telah ditunda ke satu tarikh yang akan diumumkan kemudian. Penundaan ini adalah... The post Jualan Awal Tiket Avengers: Doomsday Dit
Mark Zuckerberg Memulakan Fokus Baharu Terhadap Arena Perusahaan Melalui Meta Enterprise Platform
Mark Zuckerberg hari ini mengumumkan pembentukkan bahagian perniagaan baharu dinamakan Meta Enterprise Platform. Seperti pada namanya, perkhidmatan ini disasarkan kepada perusahaan, dan akan membolehkan pelbagai perniagaan menggunakan kecerdasan buat