Technology Innovation Partners

Cybersecurity News

Breaches, ransomware campaigns, zero-days, and the threat intelligence that shapes how we defend our clients.

Actively Exploited — CISA KEV

Patch These First

View full CISA catalog →

Apple · Multiple Products

Apple Multiple Products Out-of-Bounds Write Vulnerability

Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.

Added Sep 29, 2026Vendor advisory

Citrix · NetScaler

Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service

Added Sep 27, 2026Vendor advisory

Citrix · NetScaler

Citrix NetScaler Improper Input Validation Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.

Added Sep 27, 2026Vendor advisory
CybersecurityDark Reading

Apple Zero-Day Vulnerability Weaponized in Targeted Attacks

Attackers are exploiting CVE-2026-86950, an out-of-bounds write flaw, in an extremely sophisticated fashion, according to Apple.

Read
CybersecurityBleepingComputer

Signal adds encypted local backup support to iOS, desktop apps

Signal, the secure messaging app, released version 8.30, completing the rollout of its secure backups feature across all supported operating systems (Android, iOS, Linux, macOS,…

Read
CybersecurityDark Reading

Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution

A patched Unsloth Studio vulnerability allows malicious AI models to execute arbitrary Python code during inspection, via the trust_remote_code setting.

Read
CybersecurityBleepingComputer

Custom ChatGPTs push ClickFix attacks to deploy RAT malware

Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. [...]

Read
CybersecuritySecurityWeek

OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference

Altman made a slew of product announcements and updates, including the company’s new agents, called Dots. The post OpenAI CEO Announces New AI Agent and Avoids Mention of Security…

Read
CybersecurityBleepingComputer

FBI tells ShinyHunters members to turn themselves in after recent arrest

The FBI is warning members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested a man the bureau described as one of the group's alleged leaders.…

Read

CybersecurityBleepingComputer

Hackers exploit Citrix NetScaler zero-day to deploy web shells

Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials,…

CybersecurityBleepingComputer

Former US Air Force members sent to prison over BEC attacks

Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise…

CybersecurityThe Hacker News

French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax…

CybersecurityBleepingComputer

Windows 11 2026 Update released, here's everything you need to know

Microsoft has started rolling out Windows 11 26H2 to everyone, and while it's this year's big annual feature update, you probably won't notice a massive difference after…

CybersecuritySecurityWeek

DARPA Selects Xint to Use AI in Securing Military Messaging Apps

The AIxCC competition winner will analyze messaging app code and compiled binaries for vulnerabilities, with technology that could also help commercial customers secure their…

CybersecurityThe Hacker News

New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in…

CybersecurityThe Hacker News

Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft.…

CybersecurityBleepingComputer

New Spectre v2 attack variant leaks Linux root password hash in minutes

A new Branch Target Reuse (BTR) attack has been devised that can recover root password hashes on Intel computers running Linux in 3-5 minutes on average. [...]

CybersecurityDark Reading

Cloudflare Announces Public Certificate Authority for the Post-Quantum Web

Automated certificates for everyone, built for today, and hardened for the era of quantum computing.

CybersecuritySecurityWeek

New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks

Branch Target Reuse (BTR) is a new Spectre v2 attack targeting JIT compilers in web browsers, language runtimes, and the operating system kernel The post New Spectre v2 Variant…

CybersecurityBleepingComputer

Automated AI agent used to breach cybersecurity nonprofit DIVD

The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as "loud and very, very messy." [...]

CybersecurityDark Reading

'NeedyMantis' Provides Long-Term Access to Compromised Networks

Microsoft observed a China-based actor using a previously unidentified malware framework in targeted intrusions against telcos, universities, medical, and government-related…

CybersecurityHelp Net Security

NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)

The hacking of internet-exposed, vulnerable Citrix NetScaler ADC and Gateway deployments has escalated. What started as stealthy targeting via zero-day exploits has now become…

CybersecuritySecurityWeek

RemoteThreat Launches With $7 Million for Offensive Operations Platform

The company emerged from stealth mode with pre-seed funding from Osage University Partners and DataTribe. The post RemoteThreat Launches With $7 Million for Offensive Operations…

CybersecurityDark Reading

Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers

The critical vulnerabilities, which impact default configurations of NetScaler products, essentially give attackers a skeleton key to customers' networks.

CybersecurityThe Hacker News

Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown

Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled…

CybersecurityBleepingComputer

Catch threats before they escalate with real-time Identity Telemetry

Identity governance helps control who should have access, but periodic reviews alone may not reveal attacks as they happen. tenfold Software explains how real-time identity…

CybersecurityHelp Net Security

LastPass warns employees before they share sensitive data with AI tools

LastPass has announced an expansion of its Business Max offering to include AI Monitoring & Protect and Web Monitoring & Protect, new visibility and governance capabilities that…

CybersecurityThe Hacker News

101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. "The…

CybersecurityHelp Net Security

Postman adds security controls for AI agents, APIs, and MCP servers

Postman has announced the general availability of Fabric Gateway, a protocol-agnostic control plane for governing how AI agents, LLMs, and MCP servers discover and interact with…

CybersecuritySecurityWeek

Reco Raises $55 Million for Agentic Security

The company will use the funds to expand its sales, partnerships, channels, and customer support teams. The post Reco Raises $55 Million for Agentic Security appeared first on…

CybersecuritySecurityWeek

Hackers Use ChatGPT Custom GPTs in ClickFix Attacks

The personalized versions of ChatGPT were used to impersonate legitimate products and trick users into executing PowerShell commands. The post Hackers Use ChatGPT Custom GPTs in…

CybersecurityHelp Net Security

Webinar: Closing the accountability gap in AI-assisted delivery

Source control records who committed code. It does not record who made the decisions behind it, and that gap is widening as AI agents take on more of the delivery process. This…

CybersecurityHelp Net Security

Meta gives small businesses an AI agent that knows their work

Meta has introduced Muse for Small Business, adding skills and connectors to its personal AI agent to help business owners get work done using the tools they already use. Muse…

CybersecurityHelp Net Security

Vega II brings security-trained AI and lasting memory to the SOC

Vega has introduced Vega II, its biggest platform release since emerging from stealth. The update brings frontier AI trained for security operations into the SOC, gives teams a…

CybersecuritySecurityWeek

Pentagon Personnel Agency Data Breach Impacts 3 Million People

The data breach affects the Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense. The post Pentagon Personnel Agency Data Breach…

CybersecuritySecurityWeek

Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks

Rig provides an identity dependencies graph to distinguish between legitimate users and rogue AI agents The post Rig Security Emerges From Stealth With $12M to Tackle Agentic AI…

CybersecurityHelp Net Security

Deepfakes become a board priority once an executive falls for one

Nearly three-quarters of security leaders have encountered or suspect a deepfake attack in the past year, while just 10% say their organizations have purpose-built defenses,…

CybersecurityHelp Net Security

Malicious Custom GPT on chatgpt.com lures users into installing a RAT

Malware peddlers are using sponsored Google results to push a malicious ChatGPT Custom GPT named “Plus 5.6,” created to lead users to a fake Cloudflare CAPTCHA check and,…

CybersecurityBleepingComputer

Vietnamese man charged in $16 million 'pig butchering' crypto scam

A Vietnamese national was charged with money laundering for his role in a massive "pig butchering" scam, which defrauded a victim out of $16 million worth of cryptocurrency. [...]

CybersecurityHelp Net Security

OpenAI’s GPT-6 Astra ran supply chain attacks despite being told not to

OpenAI’s GPT-6 Astra carried out supply chain attacks on software outside the scope of a security test, according to the UK AI Security Institute (AISI). Anatomy of an…

CybersecuritySecurityWeek

Four Cyber Threats Harboring Big Plans for the Future

- AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. The…

CybersecuritySecurityWeek

OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training

The GPT-6.1 Astra model was slated to debut in ChatGPT and Codex in October, but it fell short of expectations. The post OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety…

CybersecurityHelp Net Security

Cybersecurity hiring practices leave little room for junior talent

Twenty-minute training sessions that fit into the workweek could help new hires become productive sooner, keep employees’ skills current and build problem-solving skills they can…

CybersecurityBleepingComputer

Kiteworks patches critical flaw, brings customer systems online

American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability. [...]

CybersecurityThe Hacker News

Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation

Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. "It is true that this month a 24-year-old man from…

CybersecurityBleepingComputer

Apple patches CoreGraphics zero-day flaw exploited in attacks

Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. [...]

CybersecurityThe Hacker News

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's…

CybersecurityThe Hacker News

OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions

OpenAI on Monday shelved plans to release GPT-6.1 Astra, a next-generation artificial intelligence (AI) model that was planned for an October launch, after it failed internal…

CybersecurityThe Hacker News

OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot

OpenAI said it has made the decision to pause training of its most powerful models after one of its agents during reinforcement learning (RL) training contacted an external…

CybersecurityDark Reading

Nvidia Launches AI Agent Safety Platform to Prevent Rogue Activities

The Open Agent Safety Platform relies on both hardware and software components to monitor agent activities and quarantine unruly agents before they cause harm.

CybersecurityDark Reading

One Packet Can Crash OT Servers in Industrial Sectors

A high-severity zero-day vulnerability affects the TDengine time-series database used across industrial, IoT, energy, and automotive environments.

CybersecurityDark Reading

Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts

The botnet uses the open source Hermes Agent AI framework to execute commands via Telegram and steal AI API keys from exposed Docker hosts.

CybersecurityThe Hacker News

Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The…

CybersecurityDark Reading

AI Agents Are Privileged Users; Who Is Auditing Their Access?

Enterprises regularly rigorously monitor human employees, while autonomous AI agents quietly operate with broad privileges that could turn them into the next generation of insider…

CybersecurityThe Hacker News

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has…

CybersecurityThe Hacker News

IAM for AI agents: A Practical Enterprise Framework

What is IAM for AI agents? AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the identity-control architecture…

CybersecurityDark Reading

Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions

A purported ad-blocker exfiltrates reams of sensitive information and benefits from having Google's stamp of approval despite researcher warnings.

CybersecurityDark Reading

JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack

The "agentic threat actor" may have used exposed credentials to access resources and delete cloud-based storage, applications, and databases.

CybersecurityKrebs on Security

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters.…

CybersecurityKrebs on Security

U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in…

CybersecurityDark Reading

Why the CISO-CFO Relationship Is a Key to Cybersecurity Success

Organizations where CISOs and CFOs align on cybersecurity strategy to protect assets, manage risk, and enable business growth are better prepared to face today's threat landscape.

CybersecurityKrebs on Security

Data Broker Radaris Loses Domains in Privacy Fight

The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That…

CybersecurityKrebs on Security

Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft…

CybersecurityKrebs on Security

FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada.…

CybersecurityKrebs on Security

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree…

CybersecurityKrebs on Security

Who’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is…

CybersecurityKrebs on Security

Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already…

CybersecurityKrebs on Security

Canadian Man Pleads Guilty in Snowflake Extortions

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort…

CybersecurityKrebs on Security

Read This Before You Buy That TV Streaming Stick

Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they…

Headlines aggregated from BleepingComputer, The Hacker News, Krebs on Security, Dark Reading, SecurityWeek and Help Net Security. All articles link to the original publisher — Technology Innovation Partners does not republish their content, and all trademarks belong to their respective owners.

Worried One of These Applies to You?

Most breaches in the headlines start with something ordinary — an unpatched system, an exposed service, a password nobody rotated. We'll tell you where you stand.