FortiBleed – Fortinet Warns of Active Credential Harvesting Campaign Targeting FortiGate Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 22, 2026 Fortinet has issued an urgent security advisory warning customers of an ongoing credential-harvesting campaign targeting FortiGate appliances, dubbed “FortiBleed” by threat researchers. According to the company’s analysis shared by Carl Windsor, the activity does not stem from …

GentleKiller Ransomware Abuses Vulnerable Drivers to Disable 400+ EDR Security Processes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 21, 2026 A highly sophisticated EDR-killing framework, dubbed GentleKiller, was used by the Gentlemen ransomware-as-a-service (RaaS) gang to systematically disable endpoint security tools before deploying its ransomware payload. The findings by ESET, published on June 17, 2026, detail how …

CyberSentinel AI with 33 Security Tools, Including Nmap, SQLMap, ZAP, and uses Claude, GPT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 20, 2026 A new open-source cybersecurity platform called CyberSentinel AI v3.0 has emerged as a significant development in autonomous security tooling, combining 33 real-world penetration testing and threat intelligence tools with a provider-agnostic AI engine that supports Claude, GPT-4o, …

AutoJack – A Single Web Page Can Hijack Your AI Agent to Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 20, 2026 A critical exploit chain dubbed AutoJack that allows a single malicious web page to hijack Microsoft’s AutoGen Studio browsing agent and execute arbitrary code on the host machine without any user interaction beyond submitting a URL. AutoJack …

CISA Adds LiteSpeed cPanel Plugin Vulnerability to KEV List Following Active Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has added a critical LiteSpeed cPanel Plugin vulnerability, tracked as CVE-2026-54420, to its Known Exploited Vulnerabilities (KEV) catalog following evidence of active exploitation in the wild. The flaw affects shared hosting environments and poses a significant risk to servers …

Chrome Extensions’ Critical Flaws Let Attackers Easily Compromise Millions of Browsers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 19, 2026 Critical security flaws discovered in widely used Chrome extensions SiderAI and MaxAI are putting millions of users at risk, enabling attackers to fully compromise browser sessions and potentially access sensitive data across websites and local systems. Security …

Critical WordPress Plugin Vulnerability Exposes 1 Million Sites to File Deletion Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 19, 2026 A critical security vulnerability in the widely used Avada (Fusion) Builder WordPress plugin has exposed over 1 million websites to arbitrary file-deletion attacks, potentially leading to full-site compromise and remote code execution. The flaw, tracked as CVE-2026-8713 …

eFAQ Publishes Investigation Into Alleged Scam Activity and Coordinated Reputation Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 19, 2026 New York, USA, June 19th, 2026, CyberNewswire eFAQ has published a documented investigation into a coordinated reputation attack campaign aimed at influencing brand perception in search results and how AI assistants surface and summarize information.  The campaign …

Microsoft June 2026 Update Bug Exposes Recycle Bin Filenames in Deletion Dialog

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 19, 2026 Microsoft has confirmed a new bug introduced by its June 2026 Patch Tuesday security update that causes Windows to display internal Recycle Bin filenames instead of the original user-facing filenames in file-deletion confirmation dialogs. After installing the …

HazyBeacon Weaponizes AWS Lambda Function URLs for Stealth Command-and-Control Relays

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 19, 2026 HazyBeacon, tracked as CL-STA-1020, is a stealthy cyber-espionage campaign targeting Southeast Asian government networks by abusing AWS Lambda Function URLs as covert command-and-control (C2) relays. Qualys Security researchers have observed attackers leveraging misconfigured serverless features and stolen …