Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
CISA Flags Three Medium-Severity Flaws in B&R Automation Runtime—Update to 6.4 to Fix XSS and CSV Injection
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on May 21, 2026, republished an advisory originally issued by ABB, warning of three medium-severity vulnerabilities in B&R...
ABB & CISA Warn: Patch B&R Automation Studio 6.5 SQLite Flaws Now
ABB’s B&R Automation Studio software versions earlier than 6.5, including version 6.5 itself, contain critical vulnerabilities tied to an outdated third-party SQLite database component. The...
Hitachi Energy GMS600 v1.3.2 fixes OpenSSL timing flaw CVE-2022-4304
Hitachi Energy has confirmed that two versions of its GMS600 grid monitoring system carry a dangerous OpenSSL vulnerability that could allow attackers to decrypt network traffic through timing...
CISA Warns ABB Terra AC Wallbox JP Users: Patch Memory Flaws with Firmware 1.8.36
The Cybersecurity and Infrastructure Security Agency (CISA) has republished an advisory from ABB on May 21, 2026, warning owners of the Terra AC wallbox JP charger about three medium‑severity...
CISA Flags 7 Actively Exploited Flaws: Old Windows Bugs & 2026 Defender Flaws
CISA’s Known Exploited Vulnerabilities (KEV) catalog grew by seven entries today, a mix of decades-old Windows and Adobe bugs alongside two brand-new Microsoft Defender flaws. The update, released...
Linux Kernel CVE-2026-43491: QRTR Memory Exhaustion DoS Patched
A newly published vulnerability in the Linux kernel, tracked as CVE-2026-43491, exposes systems to a denial-of-service attack through memory exhaustion in the Qualcomm IPC Router (QRTR) subsystem....
CVE-2026-43493: Linux Kernel pcrypt Async Bug Puts WSL Windows Users at Risk – What You Need to Know
A newly disclosed vulnerability in the Linux kernel’s cryptographic subsystem, tracked as CVE-2026-43493, has been added to the National Vulnerability Database (NVD) on May 19, 2026. The flaw...
CVE-2026-45585 BitLocker WinRE Bypass: How to Secure Your Device with the Offline BootExecute Fix
Microsoft has assigned CVE-2026-45585 to a newly disclosed security feature bypass vulnerability that affects BitLocker Drive Encryption when the Windows Recovery Environment (WinRE) is enabled. The...
CISA Warns ZKTeco CCTV Flaw CVE-2026-8598 Exposes Plain-Text Passwords
{ "title": "CISA Warns ZKTeco CCTV CVE-2026-8598: Unauthenticated Config Export Exposes Credentials", "content": "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent...
CISA Warns: ScadaBR 1.2.0 Bugs Enable Unauthenticated RCE on OT Systems
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a stark warning for industrial organizations worldwide: the open-source SCADA platform ScadaBR version 1.2.0 harbors four...
CVE-2025-3465: ABB CoreSense Path Traversal Flaw Exposes Localhost—Patch Now
ABB’s industrial control systems are facing a critical security alert after the Cybersecurity and Infrastructure Security Agency (CISA) republished the vendor’s advisory for CVE-2025-3465, a...
CVE-2026-0300 PAN-OS RCE Bug Threatens All Siemens RUGGEDCOM APE1808 Devices
Siemens industrial security appliances are facing a critical remote code execution risk after CISA warned that all versions of the RUGGEDCOM APE1808 are affected by a PAN-OS vulnerability tracked as...