- What: Siemens Desigo CC patch files falsely flagged as malware
- Impact: Patch files incorrectly identified by antivirus software
Patch/Configuration Management Siemens Desigo CC patch files falsely flagged as malware June 11, 2026 Share By SC Staff Siemens is alerting customers that patch files for its Desigo CC building management system are being incorrectly identified as malware by several cybersecurity solutions, as reported by Security Week. The issue affects patch files for Desigo CC versions 7 through 9. Siemens suspects the false positives stem from a PowerShell script compiled as an executable, which is part of the "patchHelper" utility. This script's operations, including file system modifications and execution with elevated privileges, are likely triggering security engines. Notably, the script has remained unchanged for months, making the sudden flagging by antivirus programs perplexing. Siemens has verified the integrity and digital signatures of the affected files, finding no malicious modifications. This incident follows a similar issue last year where Microsoft Defender Antivirus misidentified files for Siemens' Simatic PCS products. The false flagging could potentially disrupt the patching process for critical building management systems, impacting their security and operational stability. Source: Security Week SC Staff Related Patch/Configuration Management CISA directs federal agencies on prioritization of cyber vulnerabilities SC Staff June 10, 2026 The new directive, BOD 26-04, mandates that federal agencies focus on vulnerabilities that affect publicly exposed assets, can be fully automated by attackers, allow for complete system control, or show evidence of active exploitation. Patch/Configuration Management Windows 10 KB5094127 update fixes vulnerabilities, enhances Secure Boot monitoring SC Staff June 9, 2026 The KB5094127 update primarily focuses on security enhancements and bug fixes, as Microsoft is no longer introducing new features to Windows 10. Vulnerability Management CISA adds Check Point VPN bug to list of exploited vulnerabilities Steve Zurier June 9, 2026 CISA warns of an exploited Check Point VPN flaw that lets attackers bypass authentication. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds