Live
Critical Chrome Update Seals High-Severity Site Isolation Bypass—Update to 149.0.7827.197 Now·MSFT +2.1%Chrome 149 Emergency Patch Closes Sandbox Escape Flaw in DevTools (CVE-2026-13025)·NVDA +0.2%Urgent Chrome Update: CVE-2026-13026 Use-After-Free Fixed in Version 149.0.7827.197 — Windows Teams Must Patch Immediately·GOOGL +1.7%Google Fixes High-Severity Use-After-Free Bug in Chrome’s FileSystem API·AMZN +1.1%Russian Intelligence Phishing Strikes Encrypted Messaging, CISA and FBI Warn Windows Users·MSFT +2.1%Linux Kernel IPVS Flaw CVE-2026-45850 Gets Microsoft Security Advisory — Here's What Windows Users Need to Know·NVDA +0.2%CISA Flags Critical Cisco and PTC Vulnerabilities as Actively Exploited: Immediate Patching Required·GOOGL +1.7%CISA Urges Healthcare Providers to Patch Critical File Write Flaw in pynetdicom Library·AMZN +1.1%Critical Chrome Update Seals High-Severity Site Isolation Bypass—Update to 149.0.7827.197 Now·MSFT +2.1%Chrome 149 Emergency Patch Closes Sandbox Escape Flaw in DevTools (CVE-2026-13025)·NVDA +0.2%Urgent Chrome Update: CVE-2026-13026 Use-After-Free Fixed in Version 149.0.7827.197 — Windows Teams Must Patch Immediately·GOOGL +1.7%Google Fixes High-Severity Use-After-Free Bug in Chrome’s FileSystem API·AMZN +1.1%Russian Intelligence Phishing Strikes Encrypted Messaging, CISA and FBI Warn Windows Users·MSFT +2.1%Linux Kernel IPVS Flaw CVE-2026-45850 Gets Microsoft Security Advisory — Here's What Windows Users Need to Know·NVDA +0.2%CISA Flags Critical Cisco and PTC Vulnerabilities as Actively Exploited: Immediate Patching Required·GOOGL +1.7%CISA Urges Healthcare Providers to Patch Critical File Write Flaw in pynetdicom Library·AMZN +1.1%

Security Alerts

The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 8:39 AM
Latest Most Read Breaking
Sort
Browser Security · Chrome Cve

Critical Chrome Update Seals High-Severity Site Isolation Bypass—Update to 149.0.7827.197 Now

A newly disclosed vulnerability in Google Chrome undermines one of the browser's most critical security defenses, Site Isolation, potentially allowing attackers who have already compromised the...

Advertisement
Cybersecurity · Encrypted Messaging

Russian Intelligence Phishing Strikes Encrypted Messaging, CISA and FBI Warn Windows Users

The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) jointly issued an alert this June 2026, warning that Russian intelligence-linked cyber actors...

SE Security Desk·4w ago
Cve 2026 45850 · Ipv6 Extension Headers

Linux Kernel IPVS Flaw CVE-2026-45850 Gets Microsoft Security Advisory — Here's What Windows Users Need to Know

On May 27, 2026, the Linux kernel security team disclosed a significant vulnerability in the IP Virtual Server (IPVS) subsystem that has now drawn a rare public advisory from Microsoft. Tracked as...

SE Security Desk·4w ago
Cisa Kev · Cisco Cucm

CISA Flags Critical Cisco and PTC Vulnerabilities as Actively Exploited: Immediate Patching Required

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on June 25, 2026. CVE-2026-20230 affects Cisco...

SE Security Desk·4w ago
Cisa Advisory · Ics And Healthcare

CISA Urges Healthcare Providers to Patch Critical File Write Flaw in pynetdicom Library

The Cybersecurity and Infrastructure Security Agency (CISA) published Industrial Control Systems Medical Advisory ICSMA-26-176-01 on June 25, 2026, warning of a high-impact path traversal...

SE Security Desk·4w ago
Cisa Advisory · Medical Imaging Security

CISA Flags High-Severity OHIF Token Leak—Immediate Patch Required to Protect Patient Data

A critical security flaw in the OHIF Viewer’s DICOM framework is leaving authenticated sessions wide open to token theft, prompting a rare CISA medical advisory and an urgent call to patch. The...

SE Security Desk·4w ago
Charging Station Management System · Cisa Advisory

CISA Flags EVoke Systems Flaw: Unauthenticated OCPP WebSockets Expose Chargers to Spoofing Attacks

A critical vulnerability in EVoke Systems’ Charging Station Management System (CSMS) could allow attackers to impersonate electric vehicle charging stations, manipulate charging data, and...

SE Security Desk·4w ago
Cve-2026-12897 · Horner Cscape

CISA Flags Horner Cscape Flaw Allowing Local Code Execution via Malicious CSP Files

A critical vulnerability in Horner Automation's Cscape programming software could allow an attacker with local access to execute arbitrary code on a Windows workstation, according to a fresh advisory...

SE Security Desk·4w ago
Cve-2026-11833 · Ics Patching

CISA Reissues Urgent Alert on Yokogawa FAST/TOOLS Information Disclosure Flaw

Industrial control systems are facing a renewed warning after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) republished Yokogawa’s security advisory for CVE-2026-11833 on June...

SE Security Desk·4w ago