Security
Stay ahead with our essential Windows security news: Patch Tuesday updates, threat analyses, and expert guidance to safeguard your Microsoft environment.
igloohome Smart Lock Flaw: What Windows Users Need to Know About the Android App Vulnerability
CISA disclosed CVE-2026-16581, a flaw in the igloohome Smart Lock Mobile App for Android that could have allowed unauthorized access to backend services. igloohome has tightened server-side authorization, and users should update their app. The advisory highlights how smart-lock security depends on the entire management chain, including Windows PCs often used for remote administration.
Legacy KNX Devices Left Vulnerable as ABB Confirms No Fix for Firmware Spoofing
ABB confirms that CVE-2026-12705, a firmware integrity flaw in its KNX Update Tool, cannot be fixed through a software patch because the affected classic KNX devices lack modern security features. The vulnerability requires physical access to the KNX bus, but it could allow attackers to brick devices or alter their behavior. Organizations must compensate with physical security, network segmentation, strict update procedures, and a phased migration to KNX Secure devices.
Siemens Desigo CC Hit by 9.8-Severity OpenSSL Bug, V7 Users Face Hard Choices
A critical OpenSSL stack buffer overflow (CVE-2025-15467, CVSS 9.8) in Siemens Desigo CC building-management software allows pre-authentication remote crashes and potential code execution. While V8 and V9 versions can be patched, V7 has no fix available, forcing facilities operators to immediately isolate affected systems and plan for version upgrades.
Critical 9.8-Rated Flaws Hit Siemens S7-1500 MFP Controllers, No Fix Available—Defense Steps You Must Take Now
Siemens has disclosed a collection of critical vulnerabilities (max CVSS 9.8) in the GNU/Linux subsystem of its SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP controllers running firmware V3.1.6 and later, with no patch currently available. Plant operators must immediately contain the risk by restricting network access, locking down shell accounts, controlling custom application deployments, and hardening connected Windows engineering workstations, while preparing for a future firmware fix.
CISA’s New OT Isolation Guide Tells Critical Infrastructure: Plan to Run Offline for Months
CISA, the FBI, and international partners released joint guidance on July 28, 2026, detailing how critical infrastructure operators should isolate vital OT systems and keep essential services running without external network connections. The document provides a step-by-step framework for identifying, mapping, and testing isolation capabilities, with special emphasis on Windows dependencies like Active Directory and DNS. It urges pre-planning and graduated isolation to maintain operations during extended cyber crises.
Siemens PLCSIM Advanced Flaw Exposes Industrial Simulation PCs to DoS Attacks, Mitigations Urged
Siemens disclosed CVE-2026-54429, a high-severity denial-of-service vulnerability in SIMATIC S7-PLCSIM Advanced that affects all versions. The bug allows an unauthenticated attacker on the same network segment to crash the application via multicast traffic, requiring manual restart. No patch is available, but Siemens recommends disabling the Virtual Switch binding, using Softbus mode, and restricting multicast as immediate mitigations.
CISA Flags MikroTik API Login Flaw: Disable Remote Access or Risk Compromise
MikroTik RouterOS and Cloud Hosted Router API services lack protection against brute-force password guessing, CISA warns. No patch exists, so admins must disable the API when not needed, enforce VPN access, restrict source IPs, and use strong, unique passwords to prevent full router compromise.
Mendix's Hidden Account Leak: How a Documentation Gap Created a 9.1-Severity Access Control Flaw
Siemens disclosed CVE-2026-7891, a critical 9.1-severity flaw in all Mendix Runtime versions caused by a documentation gap that led developers to apply overly permissive access rules to the System.User entity. The platform's built-in access rules for System.User override any XPath constraints on its specializations, potentially exposing all user records — especially dangerous when anonymous access is enabled. Remediation requires auditing role-management settings, not applying a patch, and moving user-data restrictions from XPath to App Security configuration.
Teams Vishing Attack Pushed Chaos Ransomware in Under 17 Hours, Sophos Finds
Sophos details a Teams vishing campaign (STAC4749) that used Quick Assist or RemSupp to gain remote access and drop Chaos ransomware in under 17 hours. The attackers impersonated IT support, tricking employees into granting control. The report highlights the need for strict Teams federation, helpdesk procedures, and endpoint monitoring to disrupt such social-engineering-driven attacks.
Syskit Governance Tools Land at Exponant to Tame Microsoft 365 Sprawl
Exponant now offers Syskit Point to centralize Microsoft 365 governance, reporting, and automation across Teams, SharePoint, OneDrive, and more. The partnership highlights that effective governance requires cross-department accountability, not just IT controls, and provides practical steps for organizations to improve their security and compliance posture.
Your Windows 11 Clipboard Is Saving More Than You Think—Here’s How to Take Control
Windows 11’s clipboard history, accessed via Windows key+V, stores up to 25 copied items—including pinned entries that survive reboots and manual clearing. This service-journalism analysis explains how the feature works, exposes the privacy risks of syncing across devices, and provides step-by-step guidance for users, admins, and developers to manage, clean, and secure their clipboard history.
New Essay: Microsoft Monoculture Risks a Single Bug Crippling All Federal Agencies
A Daily Wire analysis warns that the US government's deep reliance on a single vendor for productivity, cloud, and identity creates a national security risk, amplified by AI-driven vulnerability exploitation. The essay calls for contract reforms to ensure portability, independent audit logs, and supply-chain transparency.
LG Monitor App Delivered McAfee Pop-Ups Without Consent—Microsoft Just Changed That
After Windows users discovered that connecting an LG monitor silently installed a companion app that displayed McAfee ads, Microsoft intervened. LG agreed to disable the pop-up, but the auto-install mechanism remains. The incident exposes flaws in Windows' hardware-app delivery and, alongside a separate webOS proxy scandal, highlights LG's monetization impulses.