Live
GMKtec’s New Mini PC Pairs AMD’s Ryzen AI 9 HX 470 With an OCuLink Port for Desktop Graphics·MSFT +2.1%AMD’s Next Ryzen Generation Appears in Linux Patches — Here’s What It Means for Your Windows PC·NVDA +0.2%Hackers Are Locking Water Plant Operators Out of Their Own PLCs—CISA Issues Urgent Disconnect Order·GOOGL +1.7%Critical File Upload Flaw in OpenBlue Employee Puts Facilities at Risk Despite Low Score·AMZN +1.1%Dell Gets First India-Made Memory Modules as Micron's $2.75B Plant Fires Up·MSFT +2.1%Bangladesh’s Semiconductor Summit Signals a Pragmatic First Step: Talent Before Factories·NVDA +0.2%Google Search Console Now Tracks Instagram, TikTok, and YouTube Performance—But Metadata Rules Remain Unclear·GOOGL +1.7%Microsoft Copilot Gets a Business Travel Booking Feature—and Admins Have Questions·AMZN +1.1%GMKtec’s New Mini PC Pairs AMD’s Ryzen AI 9 HX 470 With an OCuLink Port for Desktop Graphics·MSFT +2.1%AMD’s Next Ryzen Generation Appears in Linux Patches — Here’s What It Means for Your Windows PC·NVDA +0.2%Hackers Are Locking Water Plant Operators Out of Their Own PLCs—CISA Issues Urgent Disconnect Order·GOOGL +1.7%Critical File Upload Flaw in OpenBlue Employee Puts Facilities at Risk Despite Low Score·AMZN +1.1%Dell Gets First India-Made Memory Modules as Micron's $2.75B Plant Fires Up·MSFT +2.1%Bangladesh’s Semiconductor Summit Signals a Pragmatic First Step: Talent Before Factories·NVDA +0.2%Google Search Console Now Tracks Instagram, TikTok, and YouTube Performance—But Metadata Rules Remain Unclear·GOOGL +1.7%Microsoft Copilot Gets a Business Travel Booking Feature—and Admins Have Questions·AMZN +1.1%

Vulnerability Research

The latest Vulnerability Research coverage — news, analysis, and updates from the WindowsNews.AI desk.

13 stories in view AI assisted desk updated 10:34 PM
Latest Most Read Breaking
Sort
CISA · Johnson Controls

Critical File Upload Flaw in OpenBlue Employee Puts Facilities at Risk Despite Low Score

CISA's July 30 advisory details three vulnerabilities in Johnson Controls OpenBlue Employee, including an unrestricted file-upload bug that could let attackers compromise facility management systems. While the CVSS score is just 2.4, the software's presence in critical infrastructure makes immediate action essential. Windows administrators need to contact the vendor for updates and harden their deployments.

Security

Hackers Are Locking Water Plant Operators Out of Their Own PLCs—CISA Issues Urgent Disconnect Order

CISA issued an urgent alert on July 30, 2026, warning water utilities that threat actors are increasingly targeting internet-exposed programmable logic controllers, locking out operators and forcing boil-water notices. The agency calls for immediate disconnection of all exposed PLCs and provides guidance on securing remote access, password protection, and recovery.

Security Desk·1h ago ·5 min
Security

Microsoft Flags Azure Cosmos DB RCE Vulnerability; Here's What You Need to Do Now

On July 30, 2026, Microsoft published a security advisory for CVE-2026-66803, a remote code execution vulnerability in Azure Cosmos DB. The advisory lacks technical details, forcing organizations to take proactive defense measures while awaiting further guidance. This article explains the known facts, practical impacts for different users, and a step-by-step hardening checklist.

Security Desk·1h ago ·5 min
Security

What Windows 11's DNS Over HTTPS Setting Actually Does (and Doesn't Do) for Your Privacy

Windows 11 has included DNS over HTTPS for years, but a recent how-to guide has reignited interest. We explain exactly what the setting does, how to enable it, and why it isn't a substitute for a VPN. The feature encrypts domain name lookups, preventing ISPs from logging which sites you visit, but it does not hide your overall internet traffic. We cover step-by-step setup, browser conflicts, enterprise caveats, and the history of DNS encryption.

Security Desk·3h ago ·5 min
Advertisement
Apple · Android

Apple's Android Apps Every Windows User Should Know — Security, Switching, and Surprise

Apple maintains three little-known Android apps that fill specific needs: Tracker Detect for manual AirTag scanning, Move to iOS for switching phones, and Apple Music Classical for enhanced classical streaming. While Android now offers built-in tracker alerts, each app still has practical value for Windows users who use Android or plan to move to iPhone.

SE Security Desk·3h ago ·1 views
Samsung Galaxy · Galaxy S25 Ultra

Galaxy S25, S24 Ultra Owners Hit by Severe Battery Drain After July Security Patch

Samsung's July 2026 security patch for Galaxy S25 Ultra and S24 Ultra is causing severe battery drain, overheating, and slower charging for some users. The culprit may be a stuck WhatsApp backup process, but the root cause likely involves the firmware itself. Owners can troubleshoot by checking battery usage and updating apps, while Samsung has not yet acknowledged the issue.

SE Security Desk·4h ago ·1 views
Watchfire Controllers · CVE-2026-5846

Watchfire Firmware Patches Contain Plaintext RSA Keys, CISA Urges Immediate Updates

CISA has warned that Watchfire digital sign controllers shipped firmware patches containing plaintext RSA private keys and certificates. The high-severity flaw, CVE-2026-5846, allows authenticated attackers to push malicious firmware and seize control. Affected BC550, BC750, BC760, and BC760DC controllers must be updated to specific patch levels immediately.

SE Security Desk·4h ago ·1 views
Cisa Advisories · Network Segmentation

CISA Flags Root-Access Backdoor in Toptech Loading-Bay Controllers — Immediate Segmentation Required

CISA has issued a critical advisory for Toptech Systems RCU II+ and Multiload II+ industrial controllers, warning that an unauthenticated network service exposes a debug interface with full root access to the embedded Linux system. The vulnerability requires immediate network segmentation and remediation via Toptech’s removal tool or a firmware update. Windows administrators in OT environments are urged to verify that these controllers are isolated from corporate networks to prevent lateral movement.

SE Security Desk·4h ago ·1 views
Cisa · Cve-2026-13584

No Fix for CVE-2026-13584—Segment Your Mitsubishi CC-Link IE TSN Network Now

CISA published an advisory on July 30, 2026, flagging a high-severity protocol flaw (CVE-2026-13584) in Mitsubishi Electric’s CC-Link IE TSN that will not be patched. The vulnerability lets adjacent-network attackers tamper with control traffic, risking denial-of-service and incorrect equipment operation across a massive range of industrial devices. Network segmentation and physical security are the only mitigations.

SE Security Desk·4h ago
CVE-2026-14227 · MikroTik RouterOS

MikroTik RouterOS Flaw: Downgraded Accounts Retain API Access, Exposing WireGuard Keys

CISA's advisory for CVE-2026-14227 warns that downgrading a MikroTik RouterOS user's permissions does not immediately end existing API sessions, potentially allowing continued access to sensitive data such as WireGuard private keys. Administrators must manually log out users when their roles change and secure API interfaces until MikroTik provides a permanent fix.

SE Security Desk·4h ago
CVE-2026-18064 · NASA CFS

Flight Safety Apps at Risk: NASA cFS Flaw Forces Processor Resets — How to Mitigate Now

CISA warns that a high‑severity null pointer dereference (CVE‑2026‑18064) in NASA’s cFS Health and Safety app can trigger unplanned processor resets. There is no official release patch; the only remedy is to pull and build fix commit 828855f from the HS repository dev branch. Teams should immediately isolate affected systems and review command paths while preparing the source‑level update.

SE Security Desk·4h ago
Cybersecurity · Exposure Management

Stop Chasing CVEs: Microsoft Defender's New Dashboard Tells You What to Fix First

Microsoft has released a public preview of a new Exposure Resolution dashboard in the Defender portal that prioritizes security fixes based on internet exposure and business criticality. The dashboard organizes remediation into 'Resolve Now' and 'Monitor Exposure' workflows, helping Windows and cloud admins focus on the most dangerous vulnerabilities first.

SE Security Desk·5h ago ·1 views
Active Directory Recovery · Azure Security

Veeam v13.1 Hands Windows Admins an Automated Lifeline for Active Directory Disasters

Veeam Data Platform v13.1, released July 29, automates Active Directory forest recovery by capturing metadata during backups, expands threat detection to Azure, and adds a new cloud archive tier. The update simplifies identity disaster recovery for Windows admins and extends support to 14 hypervisors, with practical implications for security, compliance, and storage strategy.

SE Security Desk·6h ago