Live
CISA and NSA Rally 19 Nations Behind Unified SBOM Blueprint to Expose Hidden Code Risks·MSFT +0.1%CISA Exposes Critical Hard-Coded Credentials in SunPower Solar Gear, Plus Flaws in Delta, Fuji, Hitachi ICS Software·NVDA +3.0%Delta Electronics Patches XXE Bug in EIP Builder, CISA Warns Critical Manufacturing Operators to Upgrade Now·GOOGL +1.2%CISA Adds Actively Exploited TP-Link Extender and WhatsApp Zero-Click Flaws to KEV Catalog·AMZN +2.9%Critical Bluetooth Flaw in SunPower Inverters Grants Attackers Full Device Control·MSFT +0.1%Fuji Electric FRENIC-Loader 4 Flaw Opens Engineering Workstations to File-Based Code Execution Attacks·NVDA +3.0%FreePBX Zero-Day Exploited in Wild: CISA Orders Emergency Patching for CVSS 10 RCE·GOOGL +1.2%Mitsubishi Says No Fix Coming for MELSEC iQ-F Cleartext Credential Flaw (CVE-2025-7731)·AMZN +2.9%CISA and NSA Rally 19 Nations Behind Unified SBOM Blueprint to Expose Hidden Code Risks·MSFT +0.1%CISA Exposes Critical Hard-Coded Credentials in SunPower Solar Gear, Plus Flaws in Delta, Fuji, Hitachi ICS Software·NVDA +3.0%Delta Electronics Patches XXE Bug in EIP Builder, CISA Warns Critical Manufacturing Operators to Upgrade Now·GOOGL +1.2%CISA Adds Actively Exploited TP-Link Extender and WhatsApp Zero-Click Flaws to KEV Catalog·AMZN +2.9%Critical Bluetooth Flaw in SunPower Inverters Grants Attackers Full Device Control·MSFT +0.1%Fuji Electric FRENIC-Loader 4 Flaw Opens Engineering Workstations to File-Based Code Execution Attacks·NVDA +3.0%FreePBX Zero-Day Exploited in Wild: CISA Orders Emergency Patching for CVSS 10 RCE·GOOGL +1.2%Mitsubishi Says No Fix Coming for MELSEC iQ-F Cleartext Credential Flaw (CVE-2025-7731)·AMZN +2.9%

Cisa

The latest Cisa coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 7:58 AM
Latest Most Read Breaking
Sort
Automation · Ci/cd

CISA and NSA Rally 19 Nations Behind Unified SBOM Blueprint to Expose Hidden Code Risks

On September 3, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA), backed by 19 international partners, dropped a 22-page consensus document...

Advertisement
Adjacent Network · Bluetooth

Critical Bluetooth Flaw in SunPower Inverters Grants Attackers Full Device Control

A newly disclosed vulnerability in SunPower PVS6 solar inverters exposes critical energy infrastructure to takeovers by attackers who merely need to be within Bluetooth range. The U.S. Cybersecurity...

SE Security Desk·45w ago
Arbitrary Code · Cisa

Fuji Electric FRENIC-Loader 4 Flaw Opens Engineering Workstations to File-Based Code Execution Attacks

A critical deserialization vulnerability in Fuji Electric’s FRENIC-Loader 4 utility can give attackers full arbitrary code execution on industrial engineering workstations when a user opens a...

SE Security Desk·45w ago
Acp · Asterisk

FreePBX Zero-Day Exploited in Wild: CISA Orders Emergency Patching for CVSS 10 RCE

CISA on August 29, 2025, added a critical vulnerability in Sangoma’s FreePBX telephony platform to its Known Exploited Vulnerabilities (KEV) Catalog, warning that attackers have been exploiting the...

SE Security Desk·46w ago
Cisa · Cve-2025-7731

Mitsubishi Says No Fix Coming for MELSEC iQ-F Cleartext Credential Flaw (CVE-2025-7731)

A serious vulnerability in Mitsubishi Electric's MELSEC iQ-F series programmable logic controllers leaves credentials exposed in plaintext network traffic, and the vendor has declared it will not...

SE Security Desk·46w ago
Cisa · Cncsoft-g2

Unpatchable ICS Vulnerabilities: Mitsubishi, Schneider, Delta Among Vendors in CISA's Nine-Alert Batch

Nine industrial control system advisories released by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) on August 28, 2025, expose critical weaknesses in products from Mitsubishi...

SE Security Desk·46w ago
Asset Inventory · Cisa

No Firmware Fix for MELSEC iQ-F Modbus Flaw CVE-2025-7405 – Windows & OT Teams Must Isolate Now

Mitsubishi Electric has notified customers that it will not release firmware updates to address a critical authentication bypass vulnerability in its MELSEC iQ-F series programmable logic controllers...

SE Security Desk·46w ago
Cisa · Compensating Controls

Schneider Electric Patches Saitel DR RTU Flaw CVE-2025-8453 — DP RTU Fix Still Pending

Schneider Electric has shipped a firmware remedy for its Saitel DR Remote Terminal Units to plug a privilege management hole tracked as CVE-2025-8453, while a corresponding fix for the Saitel DP line...

SE Security Desk·46w ago
Cisa · Critical Infrastructure

US Cyber Agencies Sound Alarm on PRC Router Firmware Attacks Exposing Global Networks to Stealth Espionage

A joint cybersecurity advisory from CISA, the NSA, the FBI, and international partners has warned that state-sponsored Chinese APT actors are systematically compromising the backbone routers that...

SE Security Desk·46w ago