AutoJack – A Single Web Page Can Hijack Your AI Agent to Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 20, 2026 A critical exploit chain dubbed AutoJack that allows a single malicious web page to hijack Microsoft’s AutoGen Studio browsing agent and execute arbitrary code on the host …

CISA Adds LiteSpeed cPanel Plugin Vulnerability to KEV List Following Active Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has added a critical LiteSpeed cPanel Plugin vulnerability, tracked as CVE-2026-54420, to its Known Exploited Vulnerabilities (KEV) catalog following evidence of active exploitation in the wild. The flaw affects …

Chrome Extensions’ Critical Flaws Let Attackers Easily Compromise Millions of Browsers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 19, 2026 Critical security flaws discovered in widely used Chrome extensions SiderAI and MaxAI are putting millions of users at risk, enabling attackers to fully compromise browser sessions and …

Critical WordPress Plugin Vulnerability Exposes 1 Million Sites to File Deletion Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 19, 2026 A critical security vulnerability in the widely used Avada (Fusion) Builder WordPress plugin has exposed over 1 million websites to arbitrary file-deletion attacks, potentially leading to full-site …

eFAQ Publishes Investigation Into Alleged Scam Activity and Coordinated Reputation Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 19, 2026 New York, USA, June 19th, 2026, CyberNewswire eFAQ has published a documented investigation into a coordinated reputation attack campaign aimed at influencing brand perception in search results …

HazyBeacon Weaponizes AWS Lambda Function URLs for Stealth Command-and-Control Relays

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 19, 2026 HazyBeacon, tracked as CL-STA-1020, is a stealthy cyber-espionage campaign targeting Southeast Asian government networks by abusing AWS Lambda Function URLs as covert command-and-control (C2) relays. Qualys Security …

Hackers Abuse Third-Party Okendo Reviews Script to Spread SmartApeSG Malware Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered supply chain attack has put thousands of e-commerce websites at risk after a popular third-party reviews widget was quietly turned into a malware delivery tool. Threat actors …

CISA Urges Hardening Fortinet Devices Following FortiBleed Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 19, 2026 CISA has issued an urgent advisory warning organizations to secure their Fortinet devices following reports of a large-scale credential exposure campaign known as “FortiBleed.” The alert comes …