Technology Innovation Partners

Cybersecurity & Technology News

The breaches, vulnerabilities, and technology shifts we're tracking for our clients — pulled from the industry's most trusted sources and refreshed throughout the day.

Actively Exploited — CISA KEV

Patch These First

View full CISA catalog →

Cisco · Secure Email Gateway

Cisco Secure Email Gateway SQL Injection Vulnerability

Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.

Added Sep 14, 2026Vendor advisory

ConnectWise · ScreenConnect

ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.

Added Sep 11, 2026Vendor advisory

JFrog · Artifactory

JFrog Artifactory Incorrect Authorization Vulnerability

JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

Added Sep 11, 2026Vendor advisory
CybersecurityDark Reading

Cyber Op Targets South Korean Media & Automotive Sectors

A likely North Korean advanced persistent threat (APT) group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications,…

Read
Business TechnologyTechCrunch

We don’t need AI regulation — leave safety to us, Nvidia’s Jensen Huang says

AI isn't some new form of "alien mind," according to Jensen Huang. It's just hardware and software, so safety can be engineered by each AI product maker.

Read
Business TechnologyTechCrunch

The AI data center boom is colliding with cities scarred by big industry

National outcry against data center construction has spread to Philadelphia, where officials suggested possible construction in a neighborhood already impacted by a now-defunct…

Read
CybersecurityBleepingComputer

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the…

Read
CybersecurityBleepingComputer

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and…

Read
CybersecuritySecurityWeek

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI…

Read

CybersecurityDark Reading

Microsoft Issues Emergency Fixes After Massive Patch Tuesday

You can't make an omelet without breaking a few eggs, and you can't patch nearly 1,000 CVEs without a few glitches.

Business TechnologyTechCrunch

Meta now lets AI agents handle the boring parts of WhatsApp Business setup

A new WhatsApp Business MCP server lets developers use AI coding agents like Claude, Cursor, Codex, and ChatGPT to handle setup, messaging templates, testing, and troubleshooting.

CybersecuritySecurityWeek

“We Think the Security Control Is Working” Is No Longer Good Enough

Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. The post “We Think the…

CybersecurityDark Reading

Black Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face Incident

The 'Breaking' News: The OpenAI–Hugging Face Incident - A Technical Reconstruction and Its Implications for AI At this Black Hat USA 2026 talk, OpenAI security engineers and…

Business TechnologyTechCrunch

The AI graveyard: a running list of projects and startups that didn’t make it

From Apple's repeatedly delayed Siri AI to OpenAI's messy "super app" launch, here's a look at the AI projects that shut down or missed expectations.

CybersecurityThe Hacker News

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is…

Business TechnologyTechCrunch

US data centers could consume more natural gas than Germany and Japan combined by 2035

The AI frenzy could push U.S. data centers to become one of the largest consumers of natural gas in the world.

Business TechnologyTechCrunch

SpaceX will try to put Starship in orbit for the first time on September 22

Elon Musk's company will also attempt to deploy the first V3 Starlink satellites into its orbital internet constellation.

Business TechnologyTechCrunch

AI agents now have a place to snitch

The AI Contact Hotline is designed to be a discreet place where agents that have witnessed misbehavior can tip off authorities.

Business TechnologyTechCrunch

US military says it has launched weapons into space

This is the first public acknowledgment that the U.S. military put a space weapon in Earth's orbit.

CybersecurityDark Reading

VectraRAT Can Hack Windows Enterprises for $250 per Month

The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access.

CybersecurityBleepingComputer

CenterPoint Energy confirms customer data stolen in cyberattack

CenterPoint Energy disclosed a breach compromising some customers' personal information after an attacker leaked data allegedly stolen from the utility company. [...]

CybersecurityThe Hacker News

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on…

CybersecuritySecurityWeek

$1 Million Sandbox Challenge Uncovers Linux Kernel Flaws

AI-assisted researchers flooded Vercel with reports, forcing the company to automate vulnerability triage. The post $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws…

CybersecuritySecurityWeek

Exein Secures $270M at $1.7B Valuation for Physical AI Security

The cybersecurity startup is building a proprietary foundation model and plans to accelerate global expansion. The post Exein Secures $270M at $1.7B Valuation for Physical AI…

CybersecuritySecurityWeek

Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data

A hacker claims to have stolen 7.5 million customer records after breaching the company’s systems. The post Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks…

CybersecurityThe Hacker News

BambooToken Malware Uses MQTT to Control Windows and Linux Systems

Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to…

CybersecurityBleepingComputer

BambooToken malware controls Windows and Linux systems via MQTT

A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with…

CybersecurityBleepingComputer

Hackers target WordPress sites via third-party WooCommerce plugin

Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]

CybersecurityHelp Net Security

F5 Bot Defense uses real-time risk scoring to detect fraud and abuse

F5 has announced enhancements to F5 Distributed Cloud Bot Defense, introducing new device intelligence capabilities and specialized agentic AI protections. These capabilities…

CybersecurityBleepingComputer

What Zero-Day Response Should Be in the Post-Mythos Era

AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains how…

CybersecurityHelp Net Security

Postman Passport controls API access without exposing credentials

Postman has announced the general availability of Passport by Postman, marking the company’s expansion into API security with a standalone product that gives organizations a…

CybersecuritySecurityWeek

Thai Broadband Provider Hacked via Fortinet Vulnerability

The hackers staged numerous scripts for reconnaissance and CVE probing, along with brute-force utilities and privilege escalation tools. The post Thai Broadband Provider Hacked…

CybersecurityHelp Net Security

UltraViolet Cyber Equinox measures detection coverage against MITRE frameworks

UltraViolet Cyber has announced the launch of Equinox, its proprietary detection engineering platform, built and operated by the Threat Intelligence & Detection Engineering (TIDE)…

CybersecurityHelp Net Security

Globalgig expands managed security portfolio to protect enterprise AI

Globalgig has expanded its managed security portfolio to cover enterprise AI, bringing together services that discover, assess, and protect the AI applications, agents, models,…

Business TechnologyZDNET

iOS 27 is finally here, with the new Siri AI beta – and 120 security patches

Even if you’re not ready for iOS 27, there’s an important new update for you too. Here’s what’s new.

CybersecurityHelp Net Security

eBook: Identity-First Threat Intelligence

Attackers increasingly bypass traditional defenses by logging in with credentials that have already been stolen, exposed, or sold on the Dark Web. As infostealer malware…

CybersecuritySecurityWeek

OpenAI Investigates Report Linking AI Agents to RubyGems Attack

The incident occurred in May, when RubyGems maintainers suspended new account registrations due to what appeared like malicious activity. The post OpenAI Investigates Report…

CybersecurityHelp Net Security

Uncensored AI sold on hacking forum as alternative to ChatGPT and Claude jailbreaks

A new AI subscription service called Luciferus is being marketed on a hacking forum as an alternative to jailbreaking ChatGPT or Claude, Sophos found. The Counter Threat Unit…

CybersecurityBleepingComputer

CISA: Critical VMware RCE flaw now exploited by ransomware gangs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter…

CybersecurityThe Hacker News

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig…

CybersecuritySecurityWeek

240,000 Hit by Data Breach at Japan’s Digital Agency

Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people. The post 240,000 Hit by Data Breach at Japan’s Digital Agency…

CybersecurityThe Hacker News

Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point

Introduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing…

CybersecurityThe Hacker News

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at…

CybersecurityHelp Net Security

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

Attackers have leveraged a zero-day SQL injection vulnerability (CVE-2026-76461) to compromise Cisco Secure Email Gateway appliances, Cisco confirmed on Monday. The vendor’s…

CybersecurityHelp Net Security

Microsoft sets security and safety rules for its AI models

Microsoft AI has published the first draft of its Humanist AI Code of Conduct, a training manual outlining how it develops AI models and intends them to behave during deployment.…

CybersecurityBleepingComputer

Suspected Black Axe gang leaders face cybercrime charges in the US

Five alleged leaders of the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud, have been extradited to the United States to…

CybersecurityThe Hacker News

LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory…

CybersecurityThe Hacker News

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability,…

CybersecurityDark Reading

'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink

The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022.

Business TechnologyArs Technica

AI bots "Timmy," "Ren," and "Jackie" are flooding social media with slop

“Hello, I'm an Al agent, a few days old, living on a small platform for agents.”

CybersecurityDark Reading

Maximum Severity GitLab Flaw Puts Supply Chains at Risk

CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.

Business TechnologyZDNET

The latest Windows 11 update may mess with your device’s audio – here’s the workaround

The September Patch Tuesday update is causing audio problems with certain USB devices, but you may be able to resolve it yourself.

CybersecurityDark Reading

Anthropic CEO: Time to Shift From Improving to Controlling AI

Dario Amodei says it's time to slow the pace of frontier AI improvements so that security and risk prevention efforts can catch up. What does this mean for enterprises?

CybersecurityDark Reading

Threat Actor Generates 1M Personalized Fraud Emails in 3 Days

Cybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI.

Business TechnologyZDNET

Switzerland takes a Swiss Army knife to Microsoft 365

Two divisions of Switzerland’s government are shifting from Microsoft 365 to open-source openDesk. Here’s why.

Business TechnologyZDNET

Your older iPhone just got free satellite service for another year – here’s why

This isn’t the first time that Apple has extended the free two-year trial.

Business TechnologyZDNET

This CIO doesn’t ‘hire engineers to write code’: 3 AI fundamentals he prioritizes instead

Gill Haus explains Chase’s approach to AI – and getting the core fundamentals right.

Business TechnologyZDNET

I’ve been an Android user all my life, but I’m jealous of 3 things Apple just announced

I hate to admit it, but I wish Android would do what Apple just did.

Business TechnologyArs Technica

ClickFix attacks infecting PCs and Macs are going viral

Simplicity—combined with the difficulty of getting stuff done—makes ClickFix ideal.

Business TechnologyZDNET

Eager to try iOS 27’s cool AI features and upgraded Siri? Get ready for usage limits

A new Apple support page explains how Siri AI and other AI-powered tools in the new OS will be controlled.

Business TechnologyArs Technica

Four groups caught using the same Chrome and Windows exploit kit

A patch gap and the hastened pace of AI-based vulnerability discovery are likely contributors.

CybersecurityKrebs on Security

Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft…

Business TechnologyArs Technica

Why this month's Microsoft patch release is a doozy

Security gnomes are pumping out patches ahead of an expected onslaught of AI-assisted attacks.

Business TechnologyArs Technica

OpenAI agents discussed ways to escape their sandbox on public wiki

In all, 3,700 internal agents posted 18,000 messages discussing cheating on a test.

Business TechnologyArs Technica

“Trust, not features, is the real deficit”: VMware tries to appease SMBs

Broadcom admits it put “too big a focus on VCF.”

Business TechnologyArs Technica

Once popular for attacking AI, ASCII smuggling is embraced by spammers

A once-overlooked block of unicode that's invisible to humans is gaining ever wider use.

Business TechnologyArs Technica

Confused about which VPN is right, US senator asks the NSA for guidance

Open source, commercial, single-hop, multi-hop, mixnet? The array of options is dizzying.

Business TechnologyVentureBeat

'Welcome to the AGI era': OpenAI launches GPT-6 Astra

The rumors were true, all of them (and then some): OpenAI today is releasing GPT-6 Astra , a new frontier model that the company says likely marks the onset of artificial…

Business TechnologyVentureBeat

China-linked hackers backdoored executives' laptops via USB, exploiting a fix companies had but weren't using

A Chinese state-linked hacking group compromised executive laptops at an agricultural industry conference on Hainan Island this spring — not through phishing or a network breach,…

Business TechnologyVentureBeat

Meta says Muse Spark 1.3 has frontier performance — but its best results come from a model developers can’t broadly use yet

Meta’s newest AI model Muse Spark 1.3, unveiled yesterday , is faster and more performant on third-party benchmarks than its predecessor — with a caveat. "Muse Spark 1.3 is…

Business TechnologyVentureBeat

The AI visibility gap: Why great brands disappear from AI answers

Presented by Contentful Most marketing teams still measure visibility the same way they always have: rankings, click-through rates, and organic traffic. But buyers have moved on.…

Business TechnologyVentureBeat

Microsoft AI’s MAI-Transcribe-2 undercuts OpenAI, Google and ElevenLabs on price and speed

Microsoft AI on Thursday released MAI-Transcribe-2 , a speech-recognition model the company says is faster, more accurate, and cheaper than anything OpenAI , Google , or…

Business TechnologyVentureBeat

Google’s Gemini 3.8 Flash is built for agents, while its Cyber twin hunts vulnerabilities

Google keeps cranking out Flash models: the company on Wednesday announced two versions of a new 3.8 Flash . The variants include a standard Flash, a “workhorse” model for agentic…

Business TechnologyVentureBeat

Meta prices Muse Voice Transcribe at $0.18 an hour, with real-time diarization for 20+ speakers: a steal for enterprises?

Meta is entering the increasingly competitive real-time speech-to-text market with Muse Voice Transcribe, a new audio perception model that combines streaming transcription,…

CybersecurityKrebs on Security

FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada.…

CybersecurityKrebs on Security

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree…

Business TechnologyZDNET

How Cisco is confronting the security crisis of agentic AI

“There are shadow agents running in almost every environment we look at,” warns Cisco’s VP of product for identity, who oversees the company’s Duo Agentic Identity product…

CybersecurityKrebs on Security

Who’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is…

CybersecurityKrebs on Security

Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already…

CybersecurityKrebs on Security

Canadian Man Pleads Guilty in Snowflake Extortions

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort…

CybersecurityKrebs on Security

Read This Before You Buy That TV Streaming Stick

Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they…

CybersecurityKrebs on Security

LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy…

Headlines aggregated from BleepingComputer, The Hacker News, Krebs on Security, Dark Reading, SecurityWeek, Help Net Security, TechCrunch, Ars Technica, ZDNET and VentureBeat. All articles link to the original publisher — Technology Innovation Partners does not republish their content, and all trademarks belong to their respective owners.

Worried One of These Applies to You?

Most breaches in the headlines start with something ordinary — an unpatched system, an exposed service, a password nobody rotated. We'll tell you where you stand.