Cybersecurity
The latest Cybersecurity coverage — news, analysis, and updates from the WindowsNews.AI desk.
Critical Vulnerability Alert: Schneider Electric's Easergy Studio Poses ICS Security Risk
A newly discovered critical vulnerability in Schneider Electric's Easergy Studio software has raised alarms across industrial control system (ICS) environments. Tracked as CVE-2023-XXXX (pending...
Critical EV Charger Flaw Lets Hackers Control Charging & Home Networks
A critical vulnerability (CVE-2024-8070) in Schneider Electric's EVlink Home smart electric vehicle chargers has raised significant cybersecurity concerns for smart home owners. This flaw could allow...
CISA Warns: Critical mySCADA Flaws Allow RCE; Patch to 8.26.0+ Now
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical advisory regarding multiple vulnerabilities in mySCADA systems, posing severe risks to industrial control systems...
CVE-2024-2617: Hitachi Energy RTU500 flaw enables remote code execution
A newly discovered vulnerability in Hitachi Energy's RTU500 series poses significant risks to industrial control systems worldwide. Tracked as CVE-2024-2617, this critical security flaw could allow...
WVU Sets Windows 11 Upgrade Deadline: What IT Admins and Users Need to Know
West Virginia University (WVU) has announced a firm deadline for upgrading all university-managed devices to Windows 11, marking a significant shift in campus IT policy. This move comes as Microsoft...
Microsoft 365 Admin MFA Mandate: Timeline, Prep & Enforcement Details
Microsoft is taking a significant step forward in securing enterprise environments by making Multi-Factor Authentication (MFA) mandatory for all Microsoft 365 Admin Center accounts. This critical...
Microsoft Partners with NCSC to Simplify Azure Compliance for New Zealand Government
Microsoft has announced a strategic partnership with New Zealand's National Cyber Security Centre (NCSC) to streamline Azure cloud compliance for government agencies. This collaboration marks a...
Ransomware Attacks on Microsoft 365 Surge 300%—Deploy Zero Trust Now
Microsoft 365 has become the latest battleground in the escalating war against ransomware, with cybercriminals increasingly targeting enterprise accounts through sophisticated phishing campaigns and...
Dynamics 365 Phases Out Unified Service Desk by October 2025
Microsoft has announced the deprecation of Unified Service Desk (USD) in Dynamics 365, marking a significant shift toward the modern Customer Service Workspace. This change reflects Microsoft's...
CISA and FBI Urge Immediate Patching of Ivanti Cloud Flaws
A critical cybersecurity alert has been issued regarding multiple vulnerabilities in Ivanti Cloud Service, which could allow attackers to execute remote code and compromise enterprise systems. The...
CISA and FBI Warn of Active Cyber Campaign Targeting Ivanti Cloud Service Appliances
The Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) have issued a joint advisory warning organizations about an active cyber campaign exploiting...
STAC5143 and STAC5777 exploit Microsoft 365 defaults to deploy ransomware via Teams and Quick Assist
Overview Ransomware attacks continue to evolve, and recent campaigns targeting Microsoft 365 and Microsoft Teams highlight a dangerous new frontier in cybercrime. Two distinct ransomware factions,...