Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
CISA Warns: Multiple Milesight Camera Flaws Enable RCE and DoS Attacks
A new CISA advisory has placed Milesight surveillance cameras squarely in the crosshairs of enterprise security teams. The advisory bundles five distinct CVE families affecting multiple camera...
CISA Warns of Yadea T5 E-Bike Vulnerability CVE-2025-70994 Allowing Key-Fob Signal Forging
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published an Industrial Control Systems (ICS) advisory detailing a critical vulnerability in Yadea's T5 electric bicycle. Tracked...
CVE-2025-65856: Unauthenticated Admin Access via ONVIF in Xiongmai XM530 Cameras
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory regarding a critical authentication-bypass vulnerability in Hangzhou Xiongmai Technology Co., Ltd XM530...
CISA Warns No Patch for Critical Auth Bypass in XM530 Cameras via ONVIF
CISA Issues Critical Advisory for Hangzhou XM530 IP Cameras The Cybersecurity and Infrastructure Security Agency (CISA) has released an ICS advisory detailing a severe authentication bypass...
CISA Warns of Critical 9.4-Rated Auth Bypass in Carlson VASCO-B GNSS Receiver
Critical infrastructure operators are being urged to patch Carlson Software’s VASCO-B GNSS Receiver after CISA published a new ICS advisory describing a high-severity authentication flaw that could...
CISA Warns: Critical Authentication Flaw in Carlson VASCO-B GNSS Receiver Could Enable Remote Takeover
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory regarding a critical authentication vulnerability in the Carlson Software VASCO-B GNSS Receiver. Tracked...
FIRESTARTER Backdoor Survives Reboots and Firmware Updates on Cisco ASA/Firepower
The cybersecurity community has been put on high alert following the disclosure of FIRESTARTER, a sophisticated backdoor targeting Cisco ASA and Firepower appliances. While patching known...
FIRESTARTER Malware on Cisco ASA/FTD Survives Patching, Forces Hardware Replacement
FIRESTARTER: A Persistent Threat to Cisco ASA/FTD Firepower Appliances CISA and the U.K.’s National Cyber Security Centre (NCSC) have jointly issued an urgent advisory detailing a sophisticated...
CISA, FBI Warn China Hackers Use SOHO Routers, IoT for Covert Proxy Networks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released a joint advisory detailing how China-nexus threat actors are systematically compromising small office/home office (SOHO)...
NCSC Warns: China-Nexus Hackers Now Weaponize Routers and Firewalls in Covert Botnets
The New Normal: Compromised Edge Devices as Covert Infrastructure For years, cybersecurity professionals have focused on protecting endpoints—servers, workstations, and mobile devices. But a new...
Critical brace-expansion npm bug lets attackers crash apps with a zero-step input
Critical Denial-of-Service Flaw Discovered in brace-expansion Package Microsoft has disclosed a high-severity denial-of-service vulnerability in the popular brace-expansion npm package, tracked as...
CVE-2026-33750 Brace Expansion Flaw Can Freeze Windows Systems
Understanding CVE-2026-33750 Microsoft has disclosed a denial-of-service vulnerability, CVE-2026-33750, that resides in the brace expansion feature of Windows command-line tools. The vulnerability...