Live

Security

Stay ahead with our essential Windows security news: Patch Tuesday updates, threat analyses, and expert guidance to safeguard your Microsoft environment.

13 stories in view AI assisted desk updated 11:05 PM
Latest Most Read Breaking
Sort
Chrome 149 · CVE-2026-13030

Chrome 149 Patches Android GPU Flaw That Could Leak Browser Memory—Windows Update Included

Google’s Chrome 149 update fixes a high-severity GPU memory disclosure bug (CVE-2026-13030) that primarily threatens Android devices but also shipped as part of desktop security patches. Windows and Mac users aren’t explicitly identified as vulnerable, but the fix’s inclusion, combined with other bundled security updates, makes immediate patching essential for all platforms. We explain the real risks, the platform differences, and the simple steps users and admins must take.

Security

Android Users Must Update Chrome Now: CVE-2026-13037 Exploits WebView for Sandboxed Code Execution

Google has patched a high-severity use-after-free bug in Android's WebView engine that could let attackers execute code within the browser sandbox via a crafted HTML page. The fix, version 149.0.7827.197, requires updates to both Chrome and Android System WebView, and it demands immediate attention from users, IT admins, and app developers because WebView is embedded in countless Android apps.

Security Desk·30m ago ·5 min
Security

Chrome 149 Patches Critical WebGL Sandbox Escape — Here’s What Windows Users Need to Do

Google’s June 2026 Chrome 149 update silently patches a critical WebGL use-after-free vulnerability tracked as CVE-2026-13028. Although the CVE entry only mentions Android, the fix applies to Windows, macOS, and Linux, closing a hole that could allow sandbox escape via a malicious webpage. Windows users should immediately update Chrome to the latest version and restart the browser to ensure protection.

Security Desk·35m ago ·5 min
Security

Android Chrome Users Must Patch Now: Critical WebGL Flaw Could Let Attackers Escape Browser Sandbox

Google disclosed CVE-2026-13032, a critical use-after-free flaw in Chrome’s WebGL on Android that can escape the browser sandbox via a malicious webpage. Android users must update Chrome to version 149.0.7827.197 immediately. While Windows desktops are not directly affected, the related update fixes other high‑severity issues and should be applied.

Security Desk·35m ago ·5 min
Advertisement
Steam Deck · Raspberry Pi

A Spiked, Camera-Wielding Steam Deck Is the Funniest Anti-Family Deterrent—and a Cautionary Tale

A Reddit user built a spiked, camera-equipped security system for their Steam Deck to stop family from draining the battery. The satirical contraption worked but is impractical and risky. This article explores safer, simpler ways to protect a handheld PC using Steam’s built-in account tools, charging habits, and physical storage—without resorting to industrial theatrics.

SE Security Desk·50m ago
Kb5101650 · Secure Boot

Microsoft’s Secure Boot Certificate Rollout Marches On: What the July KB5101650 Update Means for Your PC

Microsoft’s July 2026 cumulative update KB5101650 assures Windows 11 users that missing the recent Secure Boot certificate expiration dates won’t brick their PCs. The rollout of the newer 2023 certificates continues automatically over the coming months, and a simple traffic-light status in Windows Security helps users understand what action—if any—they need to take.

SE Security Desk·2h ago
Android Security · Cisa Advisories

igloohome Smart Lock Flaw: What Windows Users Need to Know About the Android App Vulnerability

CISA disclosed CVE-2026-16581, a flaw in the igloohome Smart Lock Mobile App for Android that could have allowed unauthorized access to backend services. igloohome has tightened server-side authorization, and users should update their app. The advisory highlights how smart-lock security depends on the entire management chain, including Windows PCs often used for remote administration.

SE Security Desk·7h ago
ABB KNX · CVE-2026-12705

Legacy KNX Devices Left Vulnerable as ABB Confirms No Fix for Firmware Spoofing

ABB confirms that CVE-2026-12705, a firmware integrity flaw in its KNX Update Tool, cannot be fixed through a software patch because the affected classic KNX devices lack modern security features. The vulnerability requires physical access to the KNX bus, but it could allow attackers to brick devices or alter their behavior. Organizations must compensate with physical security, network segmentation, strict update procedures, and a phased migration to KNX Secure devices.

SE Security Desk·7h ago ·1 views
CVE-2025-15467 · OpenSSL

Siemens Desigo CC Hit by 9.8-Severity OpenSSL Bug, V7 Users Face Hard Choices

A critical OpenSSL stack buffer overflow (CVE-2025-15467, CVSS 9.8) in Siemens Desigo CC building-management software allows pre-authentication remote crashes and potential code execution. While V8 and V9 versions can be patched, V7 has no fix available, forcing facilities operators to immediately isolate affected systems and plan for version upgrades.

SE Security Desk·7h ago ·1 views
Industrial Cybersecurity · Ot Security

Critical 9.8-Rated Flaws Hit Siemens S7-1500 MFP Controllers, No Fix Available—Defense Steps You Must Take Now

Siemens has disclosed a collection of critical vulnerabilities (max CVSS 9.8) in the GNU/Linux subsystem of its SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP controllers running firmware V3.1.6 and later, with no patch currently available. Plant operators must immediately contain the risk by restricting network access, locking down shell accounts, controlling custom application deployments, and hardening connected Windows engineering workstations, while preparing for a future firmware fix.

SE Security Desk·7h ago ·1 views
Cisa Guidance · Critical Infrastructure

CISA’s New OT Isolation Guide Tells Critical Infrastructure: Plan to Run Offline for Months

CISA, the FBI, and international partners released joint guidance on July 28, 2026, detailing how critical infrastructure operators should isolate vital OT systems and keep essential services running without external network connections. The document provides a step-by-step framework for identifying, mapping, and testing isolation capabilities, with special emphasis on Windows dependencies like Active Directory and DNS. It urges pre-planning and graduated isolation to maintain operations during extended cyber crises.

SE Security Desk·7h ago ·2 views
CVE-2026-54429 · Siemens SIMATIC

Siemens PLCSIM Advanced Flaw Exposes Industrial Simulation PCs to DoS Attacks, Mitigations Urged

Siemens disclosed CVE-2026-54429, a high-severity denial-of-service vulnerability in SIMATIC S7-PLCSIM Advanced that affects all versions. The bug allows an unauthenticated attacker on the same network segment to crash the application via multicast traffic, requiring manual restart. No patch is available, but Siemens recommends disabling the Virtual Switch binding, using Softbus mode, and restricting multicast as immediate mitigations.

SE Security Desk·7h ago ·1 views
Mikrotik · Routeros

CISA Flags MikroTik API Login Flaw: Disable Remote Access or Risk Compromise

MikroTik RouterOS and Cloud Hosted Router API services lack protection against brute-force password guessing, CISA warns. No patch exists, so admins must disable the API when not needed, enforce VPN access, restrict source IPs, and use strong, unique passwords to prevent full router compromise.

SE Security Desk·7h ago ·3 views