Technology Innovation Partners

Cybersecurity & Technology News

The breaches, vulnerabilities, and technology shifts we're tracking for our clients — pulled from the industry's most trusted sources and refreshed throughout the day.

Actively Exploited — CISA KEV

Patch These First

View full CISA catalog →

Apple · Multiple Products

Apple Multiple Products Out-of-Bounds Write Vulnerability

Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.

Added Sep 29, 2026Vendor advisory

Citrix · NetScaler

Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service

Added Sep 27, 2026Vendor advisory

Citrix · NetScaler

Citrix NetScaler Improper Input Validation Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.

Added Sep 27, 2026Vendor advisory
CybersecuritySecurityWeek

Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development

The accord opened the door to future regulation but focused on four voluntary steps for the companies to take. The post Trump Says Top Tech Firms Have Signed Accord to…

Read
CybersecurityBleepingComputer

Microsoft is rolling out Linux container support to WSL

Microsoft is taking Windows Subsystem for Linux beyond just running Linux distributions, as WSL Containers is now generally available. [...]

Read
Business TechnologyTechCrunch

America.gov gets really weird when you ask it about Minecraft, but it’s not a glitch

For the sake of national security, it's a relief to learn that America.gov is not hallucinating to the point that it's penning lengthy poetry.

Read
Business TechnologyTechCrunch

The internet is convinced Elon Musk’s xAI trolled OpenAI’s ‘Dots’ launch

Before OpenAI launched its new AI agent, Dots, on Tuesday, Elon Musk's xAI had already acquired the domain name "dot.com," which now redirects to the Grok chatbot download page.

Read
Business TechnologyTechCrunch

Your car and its mobile app are probably handing over all kinds of data to tech companies

Researchers at Northeastern University found vehicles and their companion apps regularly shared detailed data with some of the largest tech companies.

Read
Business TechnologyTechCrunch

a16z-backed EliseAI raises $350M, doubles valuation to $4B

EliseAI raises $350M, doubles valuation in a year.

Read

CybersecurityDark Reading

Apple Zero-Day Vulnerability Weaponized in Targeted Attacks

Attackers are exploiting CVE-2026-86950, an out-of-bounds write flaw, in an extremely sophisticated fashion, according to Apple.

CybersecurityBleepingComputer

Signal adds encypted local backup support to iOS, desktop apps

Signal, the secure messaging app, released version 8.30, completing the rollout of its secure backups feature across all supported operating systems (Android, iOS, Linux, macOS,…

Business TechnologyTechCrunch

Tesla secures $30B in new credit lines as it looks to scale Cybercab, Optimus

The company says it won't draw on the new debt facilities this year, as it has already planned at least $25 billion in capital expenditures.

CybersecurityDark Reading

Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution

A patched Unsloth Studio vulnerability allows malicious AI models to execute arbitrary Python code during inspection, via the trust_remote_code setting.

CybersecurityBleepingComputer

Custom ChatGPTs push ClickFix attacks to deploy RAT malware

Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. [...]

Business TechnologyTechCrunch

OpenAI’s latest features take direct aim at the app store model

OpenAI is building out the pieces of an alternative to the traditional app store model, turning ChatGPT into a place where software can be discovered and used by people and AI…

CybersecuritySecurityWeek

OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference

Altman made a slew of product announcements and updates, including the company’s new agents, called Dots. The post OpenAI CEO Announces New AI Agent and Avoids Mention of Security…

CybersecurityBleepingComputer

FBI tells ShinyHunters members to turn themselves in after recent arrest

The FBI is warning members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested a man the bureau described as one of the group's alleged leaders.…

Business TechnologyTechCrunch

OpenAI reportedly in talks to raise $30B round at $1.4T valuation

The new round is anticipated to be the company's last before its delayed 2027 public debut.

Business TechnologyZDNET

LLMjacking can run up your business’ AI bill fast – how to stop it

Google analysts warn that stolen AI credentials are being sold underground, and businesses are footing the bill.

Business TechnologyTechCrunch

More Ways to Disrupt: New 2026 Side Events from KOTRA, WayFounder, Enterprise Ireland, SafetyWing + Descope

Disrupt doesn’t end when you leave Moscone West. 👀 Founder dinners, investor meetups, happy hours, workshops, roundtables and more are taking over San Francisco during Disrupt…

CybersecurityBleepingComputer

Hackers exploit Citrix NetScaler zero-day to deploy web shells

Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials,…

CybersecurityBleepingComputer

Former US Air Force members sent to prison over BEC attacks

Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise…

Business TechnologyZDNET

Is ChatGPT your new Google Workspace alternative? Meet Space, Pages, and slides

OpenAI now lets teams create documents, build presentations, and work with AI agents inside ChatGPT

CybersecurityThe Hacker News

French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax…

CybersecurityBleepingComputer

Windows 11 2026 Update released, here's everything you need to know

Microsoft has started rolling out Windows 11 26H2 to everyone, and while it's this year's big annual feature update, you probably won't notice a massive difference after…

Business TechnologyZDNET

Get Kindle Unlimited free for 3 months with this early Prime Day deal

Amazon’s free Kindle Unlimited deal only comes around a couple times a year – and I highly recommend it.

CybersecuritySecurityWeek

DARPA Selects Xint to Use AI in Securing Military Messaging Apps

The AIxCC competition winner will analyze messaging app code and compiled binaries for vulnerabilities, with technology that could also help commercial customers secure their…

CybersecurityThe Hacker News

New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in…

CybersecurityThe Hacker News

Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft.…

CybersecurityBleepingComputer

New Spectre v2 attack variant leaks Linux root password hash in minutes

A new Branch Target Reuse (BTR) attack has been devised that can recover root password hashes on Intel computers running Linux in 3-5 minutes on average. [...]

CybersecurityDark Reading

Cloudflare Announces Public Certificate Authority for the Post-Quantum Web

Automated certificates for everyone, built for today, and hardened for the era of quantum computing.

CybersecuritySecurityWeek

New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks

Branch Target Reuse (BTR) is a new Spectre v2 attack targeting JIT compilers in web browsers, language runtimes, and the operating system kernel The post New Spectre v2 Variant…

CybersecurityDark Reading

'NeedyMantis' Provides Long-Term Access to Compromised Networks

Microsoft observed a China-based actor using a previously unidentified malware framework in targeted intrusions against telcos, universities, medical, and government-related…

CybersecurityHelp Net Security

NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)

The hacking of internet-exposed, vulnerable Citrix NetScaler ADC and Gateway deployments has escalated. What started as stealthy targeting via zero-day exploits has now become…

CybersecuritySecurityWeek

RemoteThreat Launches With $7 Million for Offensive Operations Platform

The company emerged from stealth mode with pre-seed funding from Osage University Partners and DataTribe. The post RemoteThreat Launches With $7 Million for Offensive Operations…

CybersecurityDark Reading

Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers

The critical vulnerabilities, which impact default configurations of NetScaler products, essentially give attackers a skeleton key to customers' networks.

CybersecurityThe Hacker News

Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown

Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled…

CybersecurityHelp Net Security

LastPass warns employees before they share sensitive data with AI tools

LastPass has announced an expansion of its Business Max offering to include AI Monitoring & Protect and Web Monitoring & Protect, new visibility and governance capabilities that…

CybersecurityThe Hacker News

101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. "The…

CybersecurityHelp Net Security

Postman adds security controls for AI agents, APIs, and MCP servers

Postman has announced the general availability of Fabric Gateway, a protocol-agnostic control plane for governing how AI agents, LLMs, and MCP servers discover and interact with…

CybersecuritySecurityWeek

Reco Raises $55 Million for Agentic Security

The company will use the funds to expand its sales, partnerships, channels, and customer support teams. The post Reco Raises $55 Million for Agentic Security appeared first on…

CybersecuritySecurityWeek

Hackers Use ChatGPT Custom GPTs in ClickFix Attacks

The personalized versions of ChatGPT were used to impersonate legitimate products and trick users into executing PowerShell commands. The post Hackers Use ChatGPT Custom GPTs in…

CybersecurityHelp Net Security

Webinar: Closing the accountability gap in AI-assisted delivery

Source control records who committed code. It does not record who made the decisions behind it, and that gap is widening as AI agents take on more of the delivery process. This…

CybersecurityHelp Net Security

Meta gives small businesses an AI agent that knows their work

Meta has introduced Muse for Small Business, adding skills and connectors to its personal AI agent to help business owners get work done using the tools they already use. Muse…

CybersecurityHelp Net Security

Vega II brings security-trained AI and lasting memory to the SOC

Vega has introduced Vega II, its biggest platform release since emerging from stealth. The update brings frontier AI trained for security operations into the SOC, gives teams a…

CybersecuritySecurityWeek

Pentagon Personnel Agency Data Breach Impacts 3 Million People

The data breach affects the Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense. The post Pentagon Personnel Agency Data Breach…

CybersecurityHelp Net Security

Deepfakes become a board priority once an executive falls for one

Nearly three-quarters of security leaders have encountered or suspect a deepfake attack in the past year, while just 10% say their organizations have purpose-built defenses,…

CybersecurityHelp Net Security

Malicious Custom GPT on chatgpt.com lures users into installing a RAT

Malware peddlers are using sponsored Google results to push a malicious ChatGPT Custom GPT named “Plus 5.6,” created to lead users to a fake Cloudflare CAPTCHA check and,…

CybersecurityThe Hacker News

Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation

Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. "It is true that this month a 24-year-old man from…

CybersecurityThe Hacker News

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's…

CybersecurityThe Hacker News

OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions

OpenAI on Monday shelved plans to release GPT-6.1 Astra, a next-generation artificial intelligence (AI) model that was planned for an October launch, after it failed internal…

CybersecurityDark Reading

Nvidia Launches AI Agent Safety Platform to Prevent Rogue Activities

The Open Agent Safety Platform relies on both hardware and software components to monitor agent activities and quarantine unruly agents before they cause harm.

CybersecurityDark Reading

One Packet Can Crash OT Servers in Industrial Sectors

A high-severity zero-day vulnerability affects the TDengine time-series database used across industrial, IoT, energy, and automotive environments.

Business TechnologyZDNET

iOS 27.0.1 released: Apple fixes annoying iPhone 18 Pro restart and freezing issues

The first update to iOS 27 squashes a bug in which the iPhone 18 Pro and Pro Max would freeze or restart when you try to use Face ID.

CybersecurityDark Reading

Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts

The botnet uses the open source Hermes Agent AI framework to execute commands via Telegram and steal AI API keys from exposed Docker hosts.

Business TechnologyZDNET

Bose’s new wired earbuds aim for the same great sound and ANC – no charging needed

The new wired USB-C earbuds mix old-school elements with modern audio features.

CybersecurityKrebs on Security

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters.…

Business TechnologyZDNET

Your Bose headphones are getting a major Bluetooth upgrade – what to expect

Key Bluetooth technologies and upgrades to USB-C audio are coming to the company’s flagship over-ears.

CybersecurityKrebs on Security

U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in…

Business TechnologyArs Technica

Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?

Ads appearing all over the Internet are trying to scam people.

Business TechnologyZDNET

This one WatchOS 27 feature just solved my biggest issue with Apple Watch

Sometimes less is more, and the most helpful software update is the simplest.

Business TechnologyZDNET

Your LG TV is constantly collecting your data – here’s how to stop it

Factory resetting your LG TV is the only way to remove certain data logs from its hardware.

Business TechnologyArs Technica

There's a new way to break RSA that's faster than anything we've seen before

Until now, cryptographers thought factoring was the only way to break RSA. Not anymore.

Business TechnologyArs Technica

Microsoft disrupts AI-assisted platform that compromised 12,000 accounts

EvilTokens provided an end-to-end platform that makes mass compromises faster and easier.

Business TechnologyArs Technica

IT mistake erases 11 years of viewing history for hospitals’ maternity records

The English hospitals recovered patient care data only.

Business TechnologyArs Technica

Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day

A simple ClickFix attack is only one way to completely hijack the new agent.

Business TechnologyArs Technica

An undercover Google analyst infiltrated a notorious supply-chain hacking gang

Google’s threat intelligence group said it had a mole inside TeamPCP's inner circle.

Business TechnologyArs Technica

LLMs respond differently to harmful prompts when AI watermarking is used

SynthID can cause models to follow harmful instructions they would otherwise refuse.

Business TechnologyArs Technica

Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack

Group plans to be largely out of commission for several weeks.

CybersecurityKrebs on Security

Data Broker Radaris Loses Domains in Privacy Fight

The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That…

CybersecurityKrebs on Security

Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft…

Business TechnologyVentureBeat

'Welcome to the AGI era': OpenAI launches GPT-6 Astra

The rumors were true, all of them (and then some): OpenAI today is releasing GPT-6 Astra , a new frontier model that the company says likely marks the onset of artificial…

Business TechnologyVentureBeat

China-linked hackers backdoored executives' laptops via USB, exploiting a fix companies had but weren't using

A Chinese state-linked hacking group compromised executive laptops at an agricultural industry conference on Hainan Island this spring — not through phishing or a network breach,…

Business TechnologyVentureBeat

Meta says Muse Spark 1.3 has frontier performance — but its best results come from a model developers can’t broadly use yet

Meta’s newest AI model Muse Spark 1.3, unveiled yesterday , is faster and more performant on third-party benchmarks than its predecessor — with a caveat. "Muse Spark 1.3 is…

Business TechnologyVentureBeat

The AI visibility gap: Why great brands disappear from AI answers

Presented by Contentful Most marketing teams still measure visibility the same way they always have: rankings, click-through rates, and organic traffic. But buyers have moved on.…

Business TechnologyVentureBeat

Microsoft AI’s MAI-Transcribe-2 undercuts OpenAI, Google and ElevenLabs on price and speed

Microsoft AI on Thursday released MAI-Transcribe-2 , a speech-recognition model the company says is faster, more accurate, and cheaper than anything OpenAI , Google , or…

Business TechnologyVentureBeat

Google’s Gemini 3.8 Flash is built for agents, while its Cyber twin hunts vulnerabilities

Google keeps cranking out Flash models: the company on Wednesday announced two versions of a new 3.8 Flash . The variants include a standard Flash, a “workhorse” model for agentic…

Business TechnologyVentureBeat

Meta prices Muse Voice Transcribe at $0.18 an hour, with real-time diarization for 20+ speakers: a steal for enterprises?

Meta is entering the increasingly competitive real-time speech-to-text market with Muse Voice Transcribe, a new audio perception model that combines streaming transcription,…

CybersecurityKrebs on Security

FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada.…

CybersecurityKrebs on Security

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree…

CybersecurityKrebs on Security

Who’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is…

CybersecurityKrebs on Security

Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already…

Headlines aggregated from BleepingComputer, The Hacker News, Krebs on Security, Dark Reading, SecurityWeek, Help Net Security, TechCrunch, Ars Technica, ZDNET and VentureBeat. All articles link to the original publisher — Technology Innovation Partners does not republish their content, and all trademarks belong to their respective owners.

Worried One of These Applies to You?

Most breaches in the headlines start with something ordinary — an unpatched system, an exposed service, a password nobody rotated. We'll tell you where you stand.