Technology Innovation Partners

Cybersecurity News

Breaches, ransomware campaigns, zero-days, and the threat intelligence that shapes how we defend our clients.

Actively Exploited — CISA KEV

Patch These First

View full CISA catalog →

Cisco · Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.

Added Aug 11, 2026Vendor advisory

Microsoft · Windows Ancillary Function Driver for WinSock

Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

Added Aug 11, 2026Vendor advisory

Metabase · Metabase

Metabase SQL Injection Vulnerability

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.

Added Aug 11, 2026Vendor advisory
CybersecurityBleepingComputer

New Evooo1Bot Linux botnet turns routers into traffic relay nodes

A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. [...]

Read
CybersecurityBleepingComputer

How Anthropic plans to watermark Claude's AI-generated text

It could soon become easier to identify AI-generated content, even if it's not the usual "It's Not X, it's Y" type of post you'd come across on LinkedIn and other socials. [...]

Read
CybersecurityDark Reading

Mission-Driven Security: Inside a Global Bank's Defense

In this video interview, Standard Chartered's group CISO shares insights on transitioning from technical roles to strategic leadership, the importance of business-savvy security…

Read
CybersecurityBleepingComputer

Hackers arrested over €30M bank fraud exploiting service provider flaw

Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to…

Read
CybersecurityDark Reading

Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI

Driven by AI-augmented research and scanning, vulnerability volumes continue to surge, driving the National Institute of Standards and Technology to ask whether AI could be the…

Read
CybersecurityDark Reading

Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office

One Caledonian government agency reported a breach, thanks to a third party that may have serviced other agencies as well.

Read

CybersecurityBleepingComputer

Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code…

CybersecurityBleepingComputer

The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI

Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security explains why…

CybersecurityDark Reading

What Boards Need to Know About Tech Risk

Why do so many boards underestimate technology risk until it becomes a crisis?

CybersecurityBleepingComputer

Max severity SAP Commerce Cloud flaw now targeted in attacks

A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company…

CybersecurityDark Reading

Cyera's Oasis Security Buy Is All About AI Agent Control

The $1 billion deal aims to converge data security and identity into a single control plane for agents, with privileged access redefined around business context rather than static…

CybersecuritySecurityWeek

In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities

Noteworthy stories that might have slipped under the radar: government AI platform deal sparks outrage, North Korean IT worker breaches federal agency, DEF CON attendee blamed for…

CybersecurityBleepingComputer

Shell investigates 'potential incident' after Clop data theft claims

Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. [...]

CybersecuritySecurityWeek

Trivy, Not LiteLLM Behind the 2,500 Org Compromise

Over 95% of the affected companies were exposed before the malicious LiteLLM packages were published. The post Trivy, Not LiteLLM Behind the 2,500 Org Compromise appeared first on…

CybersecurityKrebs on Security

Who’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is…

CybersecurityHelp Net Security

New Android malware relays bank cards to fraudsters while victims still hold them

Group-IB researchers discovered WindRelay, a new Android malware built to capture live payment card data over NFC (Near Field Communication) and relay it to attackers in real…

CybersecuritySecurityWeek

Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal

Google Cloud outlines its roadmap to full post-quantum cryptography readiness, with key milestones targeted for 2027 and 2028. The post Google Cloud Sets Out Post-Quantum Roadmap…

CybersecurityHelp Net Security

OpenAI’s GPT-5.6 Sol runs up to 14× faster with Ultrafast mode

OpenAI’s GPT-5.6 Sol on Ultrafast mode is available in limited preview to a select group of customers, launching first through the OpenAI API. The company says the service runs up…

CybersecurityBleepingComputer

RingCentral data breach exposed info of 1.6 million accounts

The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification…

CybersecuritySecurityWeek

1.6 Million Likely Impacted by RingCentral Data Breach

The hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers. The post 1.6 Million Likely Impacted by RingCentral Data…

CybersecuritySecurityWeek

Over 1,000 Charities Hit by Beacon CRM Data Breach

The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts. The post Over 1,000 Charities Hit…

CybersecurityBleepingComputer

Data analyst sent to prison for stealing data, extorting employer

A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme. [...]

CybersecurityHelp Net Security

AWS Certificate Manager sets 2027 end date for email-validated certificate renewals

AWS Certificate Manager (ACM) will phase out email validation for public certificates throughout 2027, ahead of the Certification Authority/Browser (CA/B) Forum’s March 15, 2028…

CybersecuritySecurityWeek

14,000 Trezor Customers Impacted by Data Breach at ShipMonk

Hackers stole the customers’ shipping information, including names, addresses, email addresses, and phone numbers. The post 14,000 Trezor Customers Impacted by Data Breach at…

CybersecurityHelp Net Security

Ukrainian police raid 94 fraudulent call centers, seize $2 million

Ukrainian police have disrupted 94 fraudulent call centers during a nationwide operation that involved more than 400 searches and the seizure of thousands of computers, phones,…

CybersecuritySecurityWeek

Hackers Exploiting Unpatched GeoServer Zero-Day

The security defect is described as an SQL injection that could allow attackers to achieve remote code execution. The post Hackers Exploiting Unpatched GeoServer Zero-Day appeared…

CybersecuritySecurityWeek

AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies. The post AmnesiaStealer macOS Malware Steals…

CybersecurityHelp Net Security

The hardest part of agentic AI may be rebuilding the business

Organizations expect AI agents to change how work gets done, driving productivity and growth while allowing employees to focus on higher-value tasks. Few, however, have the…

CybersecurityHelp Net Security

Weak IAM affects up to 98% of cloud environments

Misconfiguration remains one of the leading threats to cloud environments because a single configuration error can result in public network access, unrotated keys, missing…

CybersecurityHelp Net Security

17 draft Cyber Resilience Act standards are open for comment

A company selling a connected toy in Europe must show by the end of 2027 that the product meets the Cyber Resilience Act. The law states what manufacturers have to achieve and…

CybersecurityHelp Net Security

New infosec products of the week: August 14, 2026

Here’s a look at the most interesting products from the past week, featuring releases from A10 Networks, ScienceLogic, Searchlight Cyber, and SelectHub. ScienceLogic delivers…

CybersecurityBleepingComputer

Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks

You're not alone if you just received an "Apple Threat Notification" saying it detected a "mercenary spyware attack targeted at your iPhone." [...]

CybersecurityBleepingComputer

Ukraine shuts down 94 fraudulent call centers, seize millions in cash

Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts. [...]

CybersecurityBleepingComputer

Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. [...]

CybersecurityDark Reading

Global Threat Campaign Hits Critical VMware vCenter Flaw

Exploitation against CVE-2026–59310 began earlier this month, and patching the vulnerability may not be enough to fully mitigate the threat.

CybersecuritySecurityWeek

Cybersecurity M&A Roundup: 21 Deals Announced in July 2026

Significant cybersecurity M&A deals announced by Barracuda, CrowdStrike, Cyera, Okta, Palo Alto Networks, and Qualcomm. The post Cybersecurity M&A Roundup: 21 Deals Announced in…

CybersecurityHelp Net Security

White House authorizes private US companies to hack foreign criminal networks

President Trump signed a National Security Presidential Memorandum on August 12 allowing vetted private companies to run offensive cyber operations against foreign threat actors,…

CybersecuritySecurityWeek

Adobe Commerce Bug Targeted Immediately After Disclosure

The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches. The post Adobe Commerce Bug Targeted Immediately After Disclosure…

CybersecurityHelp Net Security

DataGrout helps enterprises control AI usage, governance and LLM costs

SelectHub has announced the launch of DataGrout, its specialized AI research lab introducing an LLM inference optimization platform and AI governance solution for enterprises.…

CybersecurityDark Reading

'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft

Researchers discovered hackers-for-hire performing cyber espionage and financially motivated heists from the same Web panel.

CybersecurityDark Reading

Belgium's eID Authentication Opens Citizen Accounts to RCE

The trust framework underlying Belgium's electronic ID system was fully compromised by severe vulnerabilities in a key browser extension, showcasing bigger problems with…

CybersecurityThe Hacker News

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is…

CybersecurityDark Reading

Long-running Data Theft Campaign Targeting Salesforce, ServiceNow

The "City-Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.

CybersecurityThe Hacker News

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a…

CybersecurityDark Reading

Walmart Takes a 'Trusted Agent' Approach to Purple Teaming

Walmart colocates red and blue teams to build trust and improve security through collaborative purple teaming exercises

CybersecurityThe Hacker News

737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser…

CybersecurityDark Reading

Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition

Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America.

CybersecurityDark Reading

Walmart Leaders Transform Security Operations Without Going Bananas

The big-box giant has scaled its defenses by encouraging trust and innovation. Good communications, transparency, and team spirit are key factors.

CybersecurityThe Hacker News

OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning

A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session…

CybersecurityThe Hacker News

Enterprise Defenses Recovered at the Edge and Collapsed Inside

Enterprise defenses are tuned to catch the attacks that make noise. This year's data shows attackers winning by making none. According to Picus Labs' new Blue Report 2026, which…

CybersecurityThe Hacker News

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result…

CybersecurityThe Hacker News

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in…

CybersecurityThe Hacker News

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database…

CybersecurityThe Hacker News

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. The vulnerability,…

CybersecurityThe Hacker News

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft…

CybersecurityThe Hacker News

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited…

CybersecurityKrebs on Security

Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already…

CybersecurityThe Hacker News

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that…

CybersecurityKrebs on Security

Canadian Man Pleads Guilty in Snowflake Extortions

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort…

CybersecurityKrebs on Security

Read This Before You Buy That TV Streaming Stick

Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they…

CybersecurityKrebs on Security

LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy…

CybersecurityKrebs on Security

Microsoft Patches a Record 570 Security Flaws

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of…

CybersecurityKrebs on Security

Lessons Learned from CISA’s Recent GitHub Leak

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including…

CybersecurityKrebs on Security

Felons, Fraudsters Flog Offensive Cybersecurity Startup

A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and…

CybersecurityKrebs on Security

FBI Seizes NetNut Proxy Platform, Popa Botnet

The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service…

CybersecurityKrebs on Security

Scattered Spider Hackers Plead Guilty on Day 1 of Trial

Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for…

Headlines aggregated from BleepingComputer, The Hacker News, Krebs on Security, Dark Reading, SecurityWeek and Help Net Security. All articles link to the original publisher — Technology Innovation Partners does not republish their content, and all trademarks belong to their respective owners.

Worried One of These Applies to You?

Most breaches in the headlines start with something ordinary — an unpatched system, an exposed service, a password nobody rotated. We'll tell you where you stand.