Cristian Luțic

Cristian Luțic is a cybersecurity professional and Editor-in-Chief of iSec.News, with experience in security enablement, risk analysis, and vulnerability reporting. As Editor-in-Chief, he is responsible for editorial standards, source verification, and publication oversight at iSec News.
From professional sports to cybersecurity, his career path may have been unconventional, but it has been driven by the same core values: discipline, perseverance, and a passion for doing meaningful, impactful work.
iSec.News Motto: “Only news, only information security and privacy news. No fluff.”
-
CISA flags LiteLLM flaw as exploited in the wild
CISA said a high-severity LiteLLM command injection flaw is being actively exploited. The bug can let authenticated users run commands on the host, and researchers warned it may be chained with a Starlette issue for unauthenticated access.
-
VS Code adds 2 hour delay for extension auto updates
Microsoft has added a two hour delay before Visual Studio Code auto updates most extensions, a move aimed at limiting supply chain risk. Trusted publishers are exempt, and users can still update manually.
-
Check Point warns of active exploitation of critical VPN flaw in IKEv1 setups
Check Point said attackers are exploiting a critical VPN flaw in older IKEv1 deployments, with activity dating back to May 7 and affecting a few dozen organizations globally. The bug can let an unauthenticated attacker bypass password checks and open a VPN session.
-
Oxford University says CareerConnect breach exposed user names, emails and passwords
Oxford University said a breach of its third-party CareerConnect platform exposed user names, email addresses and encrypted passwords on May 28. The university said its own systems were not compromised and warned of possible phishing attempts.
-
China-nexus group used BSD variant of BRICKSTORM in long-running intrusion, Volexity says
A China-nexus group used a BSD variant of BRICKSTORM, PLENET and AGENTPSD in a long-running intrusion against Linux systems, according to a Volexity technical analysis that traced activity through a victim, an MSP and a NAS device.
-
Hackers exploit critical Everest Forms Pro flaw to seize WordPress sites
Hackers are exploiting a critical flaw in Everest Forms Pro to take over WordPress sites. Wordfence said more than 29,300 attack attempts were blocked after the March patch, and some attacks created rogue administrator accounts.
-
Suspicious Polyfill login prompts appear on Toshiba and Muji sites
Toshiba and Muji warned that suspicious sign-in screens appeared on parts of their websites in Japan this week, with the prompts tied to polyfill.io. The companies said users who entered credentials should change passwords.






