Cristian Luțic

Cristian Luțic is a cybersecurity professional and Editor-in-Chief of iSec.News, with experience in security enablement, risk analysis, and vulnerability reporting. As Editor-in-Chief, he is responsible for editorial standards, source verification, and publication oversight at iSec News.
From professional sports to cybersecurity, his career path may have been unconventional, but it has been driven by the same core values: discipline, perseverance, and a passion for doing meaningful, impactful work.
iSec.News Motto: “Only news, only information security and privacy news. No fluff.”
-
Sniper Dz campaign used fake Facebook offers to target MENA users
Researchers said a fraud campaign targeted users in the Middle East and North Africa with fake Facebook offers, redirecting them through layered websites and browser tricks to push phishing, premium SMS, call scams and investment fraud.
-
Palo Alto says PAN-OS flaw is under active exploitation
Palo Alto Networks said it has seen active exploitation of a PAN-OS authentication bypass flaw, CVE-2026-0257, in limited attacks against GlobalProtect portals. The company published indicators and urged customers to review logs for signs of abuse.
-
FBI, Google disrupt large AI-powered phishing service tied to millions of scam URLs
The FBI, Google and Black Lotus Labs have disrupted an AI-powered phishing service called Outsider Enterprise that used more than a million fraudulent URLs and is believed to have helped steal millions of credit card records.
-
U.S. orders Anthropic to suspend foreign access to Fable 5 and Mythos 5 models
The U.S. government ordered Anthropic to suspend foreign access to its Fable 5 and Mythos 5 AI models, citing national security concerns. Anthropic disabled the models and disputed the need for the broad export controls.
-
Kyushu Electric says missing drive exposed data of 10.9 million customers
Kyushu Electric Power said a missing backup drive may have exposed customer data tied to up to 10.9 million accounts after staff found a server room cabinet unlocked and the device gone on May 26.
-
The Gentlemen ransomware linked to 478 claimed victims, new analysis says
A new analysis says The Gentlemen ransomware has claimed 478 victims since March 2025 and shifted in July to an independent model after using resources from other ransomware services.
-
Authorities dismantle AudiA6 crypto laundering service linked to ransomware proceeds
Authorities have dismantled the AudiA6 crypto laundering service, which investigators say moved more than $380 million for ransomware actors and other cybercriminals. The case led to arrests in Georgia and seizures across 11 countries.
-
South Korea fines Coupang record $409 million over data breach
South Korea’s privacy regulator fined Coupang a record 624.6 billion won, about $409 million, after a breach exposed data linked to more than 37 million customers and drew findings of weak security controls.
-
GitHub to disable npm install scripts by default in version 12
GitHub said npm version 12 will disable install scripts by default next month to curb supply chain abuse. The change will also restrict Git and remote dependencies unless users explicitly allow them.








