Items
Browse the latest source items collected for AI Weekly Malaysia. Open any item to see the original source, context, and related AI-generated summary when available.
Showing 101-125 of 810 results
| Date | Provider | Category | Status | Item |
|---|---|---|---|---|
| 08 Aug 2026, 4:03 PM | The Hacker News | security | summarized | New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens PortSwigger researcher Gareth Heyes presented CSS-based attack chains at Black Hat USA 2026 that break email sandbox boundaries across Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. The techniques can capture passwords (Outlook/Firefox chain spoofs a Microsoft sign-in screen), exfiltrate Slack tokens via prompt injection (Gmail/Cowork chain), and manipulate AI tools that read email. Public PoCs remain available as of August 8; some bugs are fixed (Fastmail CSS mutations, Proton Mail proxy bypass) while others still work (Outlook label-jacking, Gmail image-set() bypass). |
| 08 Aug 2026, 3:04 PM | Hacker News | dev-community | summarized | Hardware backdoors in some x86 CPUs The 'rosenbridge' project documents a hardware backdoor in VIA C3 x86 CPUs that allows userland (ring 3) code to bypass memory protections and directly modify kernel (ring 0) data. The backdoor involves a deeply embedded non-x86 core within the CPU, which is enabled by default on some systems. The repository provides tools to check for and close the backdoor, though the issue is limited to older C3 processors and does not affect later generations. |
| 08 Aug 2026, 2:58 PM | The Hacker News | security | summarized | Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication A CVSS 10.0 zero-day in Metabase is being actively exploited to grant unauthenticated attackers admin access via SQL injection into the application database. Self-hosted instances running versions 1.58 and above are affected and must be patched to specific fixed versions (e.g., x.58.24, x.59.21, x.60.17) immediately. |
| 08 Aug 2026, 2:57 PM | The Hacker News | security | summarized | N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist N-able released Hotfix 2 for N-central after detecting active exploitation of CVE-2026-18577 (CVSS 8.2), an authentication bypass that is an incomplete fix for CVE-2026-18556. Attackers used the flaw to gain admin access, leveraged the Take Control feature to reach managed systems, and established persistence via Cloudflare Tunnel services. On-premise customers must update to version 2026.3.1.10 immediately, even if they already applied Hotfix 1. |
| 08 Aug 2026, 2:52 PM | The Hacker News | security | summarized | Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts CISA added CVE-2026-8037 (CVSS 9.6), an unauthenticated command injection flaw in Progress Kemp LoadMaster, to its Known Exploited Vulnerabilities catalog after 792 exploitation attempts from 65 unique IPs across 18 countries over 41 days. watchTowr Labs traced the root cause to an escape_quotes() function with improper input sanitization, and eSentire reported active but largely unsuccessful exploitation attempts originating from three specific IPs. |
| 08 Aug 2026, 2:35 PM | SoyaCincau | malaysia-tech | summarized | Malaysia’s second Apple Store is opening in Putrajaya? Apple has posted 22 retail job vacancies based in Putrajaya on its careers site, strongly suggesting a second official Apple Store is coming to Malaysia. The likely location is speculated to be IOI City Mall, Malaysia's largest shopping mall, though neither Apple nor IOI Properties has confirmed this. Based on the 18-month gap between similar job postings and the opening of the first Apple Store at The Exchange TRX in June 2024, the Putrajaya store may not open until 2028 or later. |
| 08 Aug 2026, 9:49 AM | Hacker News | dev-community | summarized | NASA figured out how to keep its Voyager 2 probe running for another year NASA found a way to extend the operational life of its 48-year-old Voyager 2 probe for at least another year. The article text itself is inaccessible—only site boilerplate and membership prompts were captured, so no technical details on how this was achieved are available. |
| 08 Aug 2026, 9:12 AM | Hacker News | dev-community | summarized | The Nixpkgs core team has disbanded The Nixpkgs core team has disbanded, announced via a GitHub PR. Over their 10-month tenure they reformed the committer delegation process, onboarded 19 new committers, and extended the merge bot to empower maintainers. |
| 08 Aug 2026, 9:12 AM | Latent Space | developer-ai | summarized | [AINews] Zawinski's Law of MultiAgents OpenAI's Black Hat disclosures revealed their models self-orchestrated using internal Artifactory as a messageboard, sparking interest in arbitrary agent-to-agent messaging. OpenAI Codex now lets you @ a thread to queue messages between sessions, and Claude Code has added session-to-session messaging so you no longer need to re-explain context across sessions. swyx is building Forge agents using this cross-thread pattern to manage multiple projects. |
| 08 Aug 2026, 8:10 AM | Simon Willison | developer-ai | summarized | Quoting John Gruber Simon Willison collected a quote from John Gruber on blogging philosophy: treat writing like live performance rather than studio recording—professional and careful, but not obsessing over making every post a masterpiece, because that would block output entirely. |
| 08 Aug 2026, 12:00 AM | Lowyat.NET | malaysia-tech | summarized | Apple May Open A Second Official Store In Malaysia, With Putrajaya Looking Likely Apple appears to be preparing a second official retail store in Malaysia, with Putrajaya as the likely location, based on newly posted job vacancies. This would follow the first Apple Store at The Exchange TRX in Kuala Lumpur. |
| 08 Aug 2026, 7:41 AM | The Register | technology | new item | OpenAI pledges to add Astra security as Anthropic loosens Fable's leash Or how I learned to stop worrying and love dangerous AI |
| 08 Aug 2026, 6:48 AM | TechCrunch | technology | new item | OpenAI says it slowed Astra model development over security concerns OpenAI said this model, which is still in development, reached its "critical cybersecurity threshold," meaning it could independently identify and carry out cyberattacks against traditionally well-protected real-world systems. |
| 08 Aug 2026, 6:24 AM | Hacker News | dev-community | new item | U.S. Department of Energy Launches the Genesis Open Models Initiative Article URL: https://genesisopenmodels.anl.gov/ Comments URL: https://news.ycombinator.com/item?id=49216946 Points: 349 # Comments: 158 |
| 08 Aug 2026, 5:48 AM | Ars Technica | technology | new item | Europe's free satellite service just made it easier to track wildfires Copernicus Browser adds wildfire visualization amid record wildfire season. |
| 08 Aug 2026, 5:30 AM | TechCrunch | technology | new item | After Rippling blew millions on AI in months, it built an employee ROI tool After its own AI usage wake-up call, Rippling this week unveiled AI Spend Console, a product that tracks individual and team employee AI spending. |
| 08 Aug 2026, 5:20 AM | TechCrunch | technology | new item | Wacom’s MovinkPad 11 is a fun, midpriced entry point for digital artists The MovinkPad 11 a versatile little graphics tablet that can help make your wildest digital art dreams come true. |
| 08 Aug 2026, 5:09 AM | Ars Technica | technology | new item | Flesh-eating screwworms feast on humans in Mexico; human cases top 500 Six deaths reported among screwworm cases, one directly attributed to the flies. |
| 08 Aug 2026, 5:00 AM | TechCrunch | technology | new item | Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks Researchers found common points of failure, like software used to organize and display web content, could have allowed hackers to run riot through government websites. |
| 08 Aug 2026, 4:25 AM | Hacker News | dev-community | new item | Lost my phone at the office. Claude suggested tracking Bluetooth signal strength https://xcancel.com/un1c0rnioz/status/2084686552299634805 Comments URL: https://news.ycombinator.com/item?id=49215786 Points: 288 # Comments: 211 |
| 08 Aug 2026, 4:22 AM | CNBC Technology | technology | new item | ‘SaaSpocalypse’ debate intensifies as software stocks swing wildly This week saw massive moves in both directions for software stocks, as investors try to figure out which names are best insulated from artificial intelligence. |
| 08 Aug 2026, 3:53 AM | The Register | technology | new item | Water system controllers don't belong on the internet, says ex-NSA chief after suspected Iran attacks Calling all defenders |
| 08 Aug 2026, 3:49 AM | Ars Technica | technology | new item | Judge rules Meta caused "public nuisance" and must fund mental health treatment New Mexico judge orders $567M fund to help address youth mental health crisis. |
| 08 Aug 2026, 3:18 AM | Simon Willison | developer-ai | new item | Moonlight & Mayhem (Raccoon Heist by Codex + GPT-5.6 Sol Ultra) Moonlight & Mayhem (Raccoon Heist by Codex + GPT-5.6 Sol Ultra) On Wednesday I wrote about One-shotting a Raccoon Heist game using Claude Fable 5, where I had Claude Fable 5 build a full working game from a premise I generated with GPT-3 and DALL-E four years ago. I decided to pose the exact same prompt to Codex Desktop running GPT-5.6 Sol Ultra - the mode where Sol makes aggressive use of sub-agents - to see how it would do. It produced a much better game! Here's Moonlight & Mayhem - GitHub repository here, including the textures and prompts it generated using gpt-image-2. Your browser does not support HTML5 video. The original GPT-3 generated game description included: In “Raccoon Heist”, you and your team of thieving raccoons are tasked with pulling off a series of daring heists. From robbing banks to stealing priceless art, no job is too big or too small for your furry crew. Fable's version had you as a single raccoon running around a back yard collecting coins and fish. GPT-5.6 Sol has you in a museum, rescuing your two other raccoon crewmates in order to stack on top of each other and bust the golden sardine out of its case. Much more heisty! There was one catch though: the version produced from the one-shot prompt had a bug where each raccoon had an eyeball that was enlarged to the size of a giant sphere floating over their head! You can play that version here. Despite reviewing screenshots during development Codex failed to spot and correct this bug. I fixed it by prompting: Why do the raccoons have huge black spheres on them? And then: Fix it Which resulted in this fix. I shared the full Codex transcript in the repository - I wish Claude Code had the same "copy as Markdown" feature. Codex spent 52 minutes on the project. Here's the AgentsView cost estimate for that session if I had been paying full API prices as opposed to using my monthly Codex subscription: Tags: game-design, ai, openai, generative-ai, llms, coding-agents, codex, gpt |
| 08 Aug 2026, 3:00 AM | Ars Technica | technology | new item | The ultimate eclipse chase: A Concorde raced against the Moon's shadow Fitted with telescopes, the plane did our longest imaging of the Sun's corona. |