Cristian Luțic

Cristian Luțic is a cybersecurity professional and Editor-in-Chief of iSec.News, with experience in security enablement, risk analysis, and vulnerability reporting. As Editor-in-Chief, he is responsible for editorial standards, source verification, and publication oversight at iSec News.
From professional sports to cybersecurity, his career path may have been unconventional, but it has been driven by the same core values: discipline, perseverance, and a passion for doing meaningful, impactful work.
iSec.News Motto: “Only news, only information security and privacy news. No fluff.”
-
New npm supply chain worms hit 50-plus packages, steal secrets
Two npm supply chain attacks spread a Rust information stealer and a worm across dozens of packages, targeting developer secrets, cloud credentials and AI tool configurations. Researchers said the malware used GitHub and npm features to keep propagating.
-
New Android spyware campaign targets Arabic-speaking users, ESET says
ESET says a new Android spyware campaign called Asin used fake utility, news and war map sites to target Arabic-speaking users. The operation remains unattributed, and its main objective has not been confirmed.
-
Researchers link new OP-512 cluster to IIS server espionage campaign
Researchers found a new China-linked threat cluster, OP-512, targeting Microsoft IIS servers with a custom web shell framework. The activity used timestomping, self-reporting shells and attempted privilege escalation on a legacy Windows Server 2016 host.
-
WFP says breach exposed data of about 600,000 Gaza households
The World Food Programme said a breach of its Gaza self-registration system exposed personal details of about 600,000 households. The agency suspended the platform, but said aid delivery and existing registrations would continue.
-
PCPJack hijacks 230 cloud servers for covert SMTP relay network
PCPJack hijacked 230 cloud servers tied to AWS, Google Cloud and Microsoft Azure to run a covert SMTP relay network, according to Hunt.io. The infrastructure used Sliver and Chisel tools and was still active when found.
-
DentaQuest says breach affected part of network, leak tied to 2.6 million accounts
DentaQuest said a security incident exposed data tied to 2.6 million accounts after a breach linked to ShinyHunters. The leaked records included names, contact details, government IDs and health insurance information.
-
iFood confirms data breach affecting 1.2 million users in Brazil
iFood said a December data breach exposed the personal details of 1.2 million users in Brazil, including CPF numbers, but not passwords or payment data. The company and hackers dispute the scale of the incident.
-
French, Spanish police shut fake ID marketplace used by migrant smugglers
French and Spanish authorities shut an online marketplace selling fake identity documents to migrant smuggling rings, arresting one suspect in Spain and seizing about 800 counterfeit IDs and production equipment.
-
China-linked TA4922 widens phishing attacks to Europe and South Africa
China-linked TA4922 has expanded phishing campaigns from East Asia to organizations in the U.K., Germany, Italy and South Africa, using malware such as Atlas RAT, RomulusLoader and SilentRunLoader, according to a Proofpoint technical analysis.
-
Researchers say macOS malvertising campaign is spreading FlutterShell backdoor
Researchers say a macOS malvertising campaign has been spreading a new backdoor called FlutterShell through trojanized desktop apps and ads, with activity seen as recently as March 2026.










