Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft Account MFA Bypass Exploited: Critical CVE-2025-21396 Patched
A newly discovered critical vulnerability in Microsoft Account authentication (CVE-2025-21396) exposes millions of users to potential account takeovers. This elevation of privilege flaw, rated 9.8/10...
Azure AI Face flaw CVE-2025-21415 (CVSS 8.8) lets attackers hijack facial data access.
Microsoft has disclosed a critical elevation of privilege vulnerability (CVE-2025-21415) affecting its Azure AI Face service, potentially allowing attackers to gain unauthorized access to sensitive...
CVE-2025-24085: Critical Apple Vulnerability Discovered by CISA – Patch Immediately
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a newly discovered Apple vulnerability, CVE-2025-24085, which poses significant risks to users across...
CISA 2025 ICS Advisories: Critical OT Flaws Endanger Energy, Water, and Manufacturing
The Cybersecurity and Infrastructure Security Agency (CISA) has released its 2025 Industrial Control Systems (ICS) advisories, highlighting critical vulnerabilities affecting global infrastructure....
CISA Warns of Critical Rockwell FactoryTalk Flaws in Industrial Systems
Rockwell Automation's FactoryTalk software suite, widely used in industrial control systems (ICS), has been found to contain multiple critical vulnerabilities that could allow attackers to execute...
CVE-2020-11656 & CVE-2024-11932: Patch Rockwell DataMosaix v3.5–v4.2.1 for ICS RCE risks.
Industrial Control Systems (ICS) security faces new threats as researchers disclose critical vulnerabilities in Rockwell Automation's DataMosaix software. These flaws, tracked as CVE-2020-11656 and...
Schneider Electric PowerLogic Flaws Allow Remote Code Execution in OT Systems
Schneider Electric has issued urgent security advisories for multiple critical vulnerabilities affecting its Power Logic products, which could allow attackers to execute arbitrary code, cause...
CISA Urges Immediate Patching for Critical Rockwell FactoryTalk Flaws
Rockwell Automation has issued urgent security advisories regarding multiple critical vulnerabilities in its FactoryTalk software suite, which could allow attackers to execute remote code, escalate...
Schneider Electric patches critical CVE-2024-12703 auth bypass in RemoteConnect and SCADAPack
Critical Cybersecurity Advisory: Schneider Electric Vulnerability in ICS Software (CVE-2024-12703) Schneider Electric has issued a critical security advisory regarding a newly discovered...
Critical Security Alert: B&R Automation Runtime Vulnerability Exposes ICS Systems to Attacks
A newly discovered vulnerability in B&R Automation Runtime could allow attackers to bypass cryptographic protections in industrial control systems (ICS). The Cybersecurity and Infrastructure...
Google and Microsoft rush emergency patch for critical Chromium V8 zero-day under active exploit
CVE-2025-0612: Critical Vulnerability in Chromium's V8 Engine for Windows Users A newly discovered critical vulnerability (CVE-2025-0612) in Chromium's V8 JavaScript engine poses significant risks...
Emergency patch released for CVE-2025-0611 critical V8 flaw in Microsoft Edge.
Microsoft Edge users are facing a significant security threat following the discovery of CVE-2025-0611, a critical vulnerability in the Chromium V8 JavaScript engine that powers the browser. This...