Industrial Cybersecurity
The latest Industrial Cybersecurity coverage — news, analysis, and updates from the WindowsNews.AI desk.
CISA Warns Engineers: Proteus 9.1 SP4 Memory Bugs Expose Windows Workstations—Update Immediately
On July 7, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent advisory for Labcenter Electronics’ Proteus design software, revealing three high-severity...
Critical NGINX Heap Overflow in Hitachi Energy EMS Puts Grid Operators at Risk — What Windows Admins Need to Know
On July 7, 2026, Hitachi Energy and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a joint advisory detailing a critical vulnerability in the company’s e-mesh Energy...
CISA Issues Urgent Warning on Digi Serial Device Server Authentication Bypass — Patch Now
On July 7, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released an industrial control systems (ICS) advisory warning that several Digi International serial device servers...
USB Malware Can Cross Your Air Gap: Here’s How to Test Your OT System’s Resilience Before It’s Too Late
Operators of industrial control systems got a jolt this week after independent tests confirmed that a new breed of USB-borne malware can silently bridge the so-called air gaps that are supposed to...
CISA Flags XZ Utils Flaw CVE-2025-31115 Endangering B&R Industrial Terminals, Urges Immediate Patching
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has republished an ABB PSIRT advisory warning that CVE-2025-31115, a high-severity vulnerability in the XZ Utils data compression...
Mitsubishi MELSOFT Update Manager Flawed by 7-Zip Bugs, Industrial Systems Urged to Patch
Mitsubishi Electric’s MELSOFT Update Manager, a utility deployed across thousands of industrial control system (ICS) engineering workstations, shipped with a dangerously outdated version of 7-Zip...
Schneider PowerLogic P7 Patch Forces Reboot, Exposes OT to Real-World Risks
Schneider Electric has released a critical firmware update for its PowerLogic P7 protection and control platform, plugging three security holes that could let attackers remotely hijack or crash the...
ABB Freelance Security Lock Flaw Lets Attackers Hijack OT Consoles — Patch Now
ABB and the U.S. Cybersecurity and Infrastructure Security Agency issued a joint advisory in June 2026 warning that a high-severity vulnerability in the Freelance Security Lock component could let...
Siemens Patches Critical WinCC Certificate Manager Vulnerability CVE-2026-24349 with V21 Update 2
Siemens has released an urgent patch for a critical flaw in its WinCC Certificate Manager, tracked as CVE-2026-24349, that left industrial control systems open to man-in-the-middle attacks and...
CISA Sounds Alarm on Unpatched Mitsubishi Electric DoS Flaw in All FX5-ENET/IP Modules
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has republished an advisory for CVE-2026-8806, a high-severity denial-of-service vulnerability that affects every version of...
Mitsubishi Electric Patches Critical CVE-2026-8805 DoS Vulnerability in FX5-EIP EtherNet/IP Modules
Mitsubishi Electric, in coordination with the U.S. Cybersecurity and Infrastructure Security Agency (CISA), disclosed on June 18, 2026, that a remotely exploitable denial-of-service (DoS)...
CISA Alert: Schneider Electric OT Gear Vulnerable to Session Prediction Attacks (CVE-2026-4827)
CISA has urged critical infrastructure operators to immediately patch multiple Schneider Electric power automation products after discovering a session management vulnerability that could let...