Understanding stuxnet in relation to PLCs

How is stuxnet designed to attack industrial programmable Logic Controllers (PLCs)? What operating system is at the most risk? Can stuxnet be a threat to a corporation that strictly forbids the use of USB drive on its systems? How long can stuxnet stay in a system without causing any damage? Is there any variant of stuxnet?
