Live
CISA Adds Actively Exploited Trend Micro Apex One Zero-Day to KEV, Mandates Rapid Patching·MSFT +2.1%Cisco Rushes Patch for Critical 10.0 Bug Exposing Firewall Managers to Pre-Auth Shell Attacks·NVDA +0.2%Chrome 139 Fixes High-Severity libaom AV1 Heap Overflow; Edge Patch to Follow·GOOGL +1.7%Siemens Patches Critical Simcenter Femap Bugs Allowing Code Execution from Malicious STP and BMP Files·AMZN +1.1%Siemens CROSSBOW SAC Emergency Patch: Critical SQLite Flaws Enable Remote Code Execution·MSFT +2.1%Rockwell Patch Plugs SYSTEM Takeover Hole in FactoryTalk ViewPoint via MSI Repair Hijack·NVDA +0.2%CVE-2025-7353 Exposes Rockwell ControlLogix Ethernet Modules to Remote Memory and Execution Control·GOOGL +1.7%Microsoft: CVE-2025-48807 Hyper V Exploit Demands Local Access, Yet Threatens Entire Host Infrastructures·AMZN +1.1%CISA Adds Actively Exploited Trend Micro Apex One Zero-Day to KEV, Mandates Rapid Patching·MSFT +2.1%Cisco Rushes Patch for Critical 10.0 Bug Exposing Firewall Managers to Pre-Auth Shell Attacks·NVDA +0.2%Chrome 139 Fixes High-Severity libaom AV1 Heap Overflow; Edge Patch to Follow·GOOGL +1.7%Siemens Patches Critical Simcenter Femap Bugs Allowing Code Execution from Malicious STP and BMP Files·AMZN +1.1%Siemens CROSSBOW SAC Emergency Patch: Critical SQLite Flaws Enable Remote Code Execution·MSFT +2.1%Rockwell Patch Plugs SYSTEM Takeover Hole in FactoryTalk ViewPoint via MSI Repair Hijack·NVDA +0.2%CVE-2025-7353 Exposes Rockwell ControlLogix Ethernet Modules to Remote Memory and Execution Control·GOOGL +1.7%Microsoft: CVE-2025-48807 Hyper V Exploit Demands Local Access, Yet Threatens Entire Host Infrastructures·AMZN +1.1%

Security Advisory

The latest Security Advisory coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 10:28 AM
Latest Most Read Breaking
Sort
Bod 22-01 · Cisa

CISA Adds Actively Exploited Trend Micro Apex One Zero-Day to KEV, Mandates Rapid Patching

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-54948, a critical command injection vulnerability in Trend Micro’s Apex One on-premises management console, to...

Advertisement
siemens_crossbow_sac_emergency.jpg
Cisa · Crossbow

Siemens CROSSBOW SAC Emergency Patch: Critical SQLite Flaws Enable Remote Code Execution

Siemens has released emergency patches for its RUGGEDCOM CROSSBOW Station Access Controller (SAC) after security researchers uncovered multiple critical vulnerabilities in the SQLite database engine...

SE Security Desk·48w ago
Applocker · Cisa Ics Advisory

Rockwell Patch Plugs SYSTEM Takeover Hole in FactoryTalk ViewPoint via MSI Repair Hijack

A high-severity local privilege-escalation vulnerability in Rockwell Automation’s FactoryTalk ViewPoint HMI software can hand an attacker full SYSTEM control of a Windows machine by exploiting a...

SE Security Desk·48w ago
1756 En Modules · Cip Protocol

CVE-2025-7353 Exposes Rockwell ControlLogix Ethernet Modules to Remote Memory and Execution Control

Rockwell Automation’s ControlLogix EtherNet/IP communication modules are vulnerable to a high-severity flaw that lets remote attackers dump and modify runtime memory, potentially hijacking device...

SE Security Desk·48w ago
Cve-2025-48807 · Endpoint Security

Microsoft: CVE-2025-48807 Hyper V Exploit Demands Local Access, Yet Threatens Entire Host Infrastructures

Despite a CVE title suggesting a remote code execution flaw, Microsoft confirmed this week that CVE‑2025‑48807—a vulnerability in Hyper‑V’s Virtualization Service Provider (VSP)...

SE Security Desk·48w ago
Air-gapped · Authentication

Microsoft's CVE-2025-53793 Advisory: Azure Stack Hub Authentication Flaw Exposes Sensitive Data

Microsoft has published an urgent security advisory for CVE-2025-53793, an improper authentication vulnerability in Azure Stack Hub that could allow unauthenticated attackers to access sensitive...

SE Security Desk·48w ago
Cve-2025-53783 · Cybersecurity

Microsoft Teams Flaw CVE-2025-53783: Unauthenticated RCE via Heap Overflow Sparks Urgent Patching

Microsoft has published a security advisory for CVE-2025-53783, a heap-based buffer overflow in Microsoft Teams that allows an unauthorized attacker to execute code remotely over a network. The...

SE Security Desk·48w ago
Cve-2025-53766 · Defense In Depth

Unverified GDI+ RCE Vulnerability CVE-2025-53766 Prompts Urgent Patch Verification Call

Microsoft’s Security Update Guide has quietly listed a new vulnerability tracked as CVE-2025-53766, describing a heap-based buffer overflow in the GDI+ graphics library that could allow remote code...

SE Security Desk·48w ago
Azure Local · Azure Stack Hub

CVE-2025-53765: Microsoft Warns of Azure Stack Hub Data Leak Through Authorized Local Access

Microsoft’s Security Response Center has published an advisory for CVE-2025-53765, an information disclosure vulnerability in Azure Stack Hub that permits an attacker with local authorization to...

SE Security Desk·48w ago