Cristian Luțic

Cristian Luțic is a cybersecurity professional and Editor-in-Chief of iSec.News, with experience in security enablement, risk analysis, and vulnerability reporting. As Editor-in-Chief, he is responsible for editorial standards, source verification, and publication oversight at iSec News.
From professional sports to cybersecurity, his career path may have been unconventional, but it has been driven by the same core values: discipline, perseverance, and a passion for doing meaningful, impactful work.
iSec.News Motto: “Only news, only information security and privacy news. No fluff.”
-
China-linked JDY botnet grows to more than 1,500 devices, researchers say
Researchers say the China-linked JDY botnet has grown to more than 1,500 compromised SOHO and IoT devices and is being used to scan exposed services and collect reconnaissance data for follow-on targeting.
-
Unpatched Langflow flaw under active exploitation, researchers say
An unpatched Langflow flaw tracked as CVE-2026-5027 is being actively exploited, researchers say. The bug can allow arbitrary file writes, and about 7,000 instances are exposed online.
-
Google patches Chrome zero-day CVE-2026-11645 after active exploitation
Google has patched 74 Chrome flaws, including CVE-2026-11645, a high-severity zero-day in the V8 engine that the company said was being exploited in the wild. Users are urged to update Chrome and other Chromium-based browsers.
-
Browser-based FROST attack can infer site visits from SSD timing
Researchers at Graz University of Technology say a browser-based attack called FROST can infer site visits and app launches from SSD timing, reaching 88.95% accuracy in one macOS test and working without native code or a permission prompt.
-
Six protobuf.js flaws can expose Node.js apps to code execution, denial of service
Six vulnerabilities in protobuf.js could enable remote code execution or denial of service in Node.js apps, according to a Cyera technical analysis. Patches are available for affected protobufjs and protobufjs-cli releases.
-
Microsoft removes 73 GitHub repositories during malware investigation
Microsoft removed 73 GitHub repositories on June 5 while investigating potential malicious content, briefly disrupting developer pipelines tied to Azure Functions. Researchers linked the incident to a broader Miasma and Shai-Hulud supply-chain campaign.
-
Veeam patches critical backup software flaw that could allow remote code execution
Veeam patched a critical flaw in Backup & Replication that could allow remote code execution on a backup server. The bug affects some 12.x releases and was fixed in version 12.3.2.4854.
-
Russia-Aligned Hackers Keep Exploiting WinRAR Flaw to Target Ukraine
Russia-aligned hacking groups have kept exploiting a patched WinRAR flaw against Ukrainian organizations, using crafted archives, hidden payloads and stolen browser data in campaigns that researchers said remained active into 2026.
-
Malicious PyPI packages tied to Hades attack wave, researchers say
Researchers said a new Hades supply chain campaign poisoned 37 wheel artifacts across 19 PyPI packages, using startup hooks to run Bun-based malware that sought cloud, repository and developer credentials.








