Cybersecurity
The latest Cybersecurity coverage — news, analysis, and updates from the WindowsNews.AI desk.
E-Waste Tsunami or Security Imperative? Windows 11’s TPM 2.0 Mandate Sparks Debate as 400M PCs Hang in Balance
On October 14, 2025, millions of perfectly functional PCs will officially become security risks. That’s the day Microsoft ends free support for Windows 10, and with it, an era of broad hardware...
Rockwell FactoryTalk ViewPoint Flaw Lets Attackers Hijack MSI Repairs for SYSTEM Access
A critical privilege escalation vulnerability in Rockwell Automation’s FactoryTalk ViewPoint HMI thin-client software allows a low-privileged local attacker to gain SYSTEM-level control of...
Physical Access Exploit Can Crash Siemens SIPROTEC 5 Relays via USB: Patch and Mitigation Guide for CVE-2025-40570
An attacker with physical access to a Siemens SIPROTEC 5 protection relay can halt its network communications within seconds by flooding the USB port with specially crafted packets. The...
CVE-2024-8894: Siemens COMOS Vulnerability – Patch ODA Drawing Flaw Before It's Exploited
{ "title": "CVE-2024-8894: Siemens COMOS Vulnerability – Patch ODA Drawing Flaw Before It's Exploited", "content": "A critical memory corruption flaw in a widely used third-party graphics...
Critical VNC Authentication Bypass in Siemens SINUMERIK CNC Systems—Patch Now, CISA Warns
Siemens has released emergency patches for a severe authentication bypass vulnerability in its SINUMERIK CNC platforms that could let an attacker on an adjacent network seize remote control of...
Rockwell Patches Critical DoS Flaws in 1756-EN4TR Modules, Urges Immediate Firmware Update to 7.001
Rockwell Automation has released a firmware fix for a pair of vulnerabilities in its 1756-EN4TR and 1756-EN4TRXT communication modules that could allow an attacker to crash the devices, causing a...
CISA Sounds Alarm on FactoryTalk Linx Flaw: A Single Env Variable Can Hand Over Full OT Driver Control
Industrial operators running Rockwell Automation’s FactoryTalk Linx have been handed a high‑priority patch order this week. A vulnerability resurfaced by CISA on August 14, 2025, allows any...
California Man Sues Microsoft to Halt Windows 10 Support Cutoff, Alleges Coercive AI Strategy
A Southern California resident has filed a state-court lawsuit seeking to force Microsoft to continue providing free security updates for Windows 10 beyond the company’s published end-of-support...
Discounted Keys, AI Subs, and Driver Updaters: One Power User's Blueprint for a Safer, Faster Windows 11 PC
A Windows power user has laid out a meticulously curated software stack that promises to eliminate daily PC friction, but the real story isn’t just about the apps—it’s the tangled web of...
San Diego Lawsuit: Microsoft Accused of Using Windows 10 Sunset to Force AI PC Upgrades
A lawsuit filed in San Diego Superior Court seeks an injunction that would force Microsoft to continue issuing free security updates for Windows 10 indefinitely, upending the company’s long-planned...
Windows 10 August Update Opens ESU Enrollment, Hardens Secure Boot Against Rollback
Microsoft’s cumulative update KB5063709, released on August 12, 2025, arrives at a critical juncture for Windows 10 users. With the end-of-support deadline looming on October 14, 2025, the patch...
Domain Controllers at Risk: Microsoft’s August Update Closes Kerberos dMSA Vulnerability Amid 100+ Fixes
Microsoft’s August 2025 Patch Tuesday release lands with an urgent fix for a Kerberos vulnerability that could allow attackers to escalate to domain administrator, alongside more than a dozen other...