Cristian Luțic

Cristian Luțic is a cybersecurity professional and Editor-in-Chief of iSec.News, with experience in security enablement, risk analysis, and vulnerability reporting. As Editor-in-Chief, he is responsible for editorial standards, source verification, and publication oversight at iSec News.
From professional sports to cybersecurity, his career path may have been unconventional, but it has been driven by the same core values: discipline, perseverance, and a passion for doing meaningful, impactful work.
iSec.News Motto: “Only news, only information security and privacy news. No fluff.”
-
Redis patches two-year-old use-after-free flaw that enabled remote command execution
Redis patched CVE-2026-23479, a use-after-free flaw in blocking-client code that could lead to remote command execution. The bug affected versions 7.2.0 through 8.6.2 and had gone unnoticed for more than two years.
-
Fake open-source tool sites used to push malware through gated redirects
Researchers say fake sites impersonating open-source tools such as Ghidra and dnSpy are using gated redirects to push malware, including Remus Stealer, AnimateClipper and SessionGate, after users click download buttons.
-
Hackers spent months inside stock exchange executive’s Outlook inbox
Unknown attackers spent at least five months inside a senior stock exchange executive’s Outlook mailbox, copying messages in small batches and routing them through Dropbox and OneDrive in what researchers described as espionage.
-
CISA adds exploited Magento extension flaw to known vulnerabilities list
CISA added a critical Magento extension flaw to its exploited vulnerabilities catalog after reports of active abuse. The bug, CVE-2026-45247, can allow remote code execution and affects versions of Mirasvit Cache Warmer before 1.11.12.
-
Google patches Gemini flaw that could let poisoned notifications trigger Android actions
Google patched a Gemini on Android flaw that let a poisoned notification influence the assistant, potentially triggering actions from fake messages to smart home controls. SafeBreach said the bug was fixed server-side and no in-the-wild abuse was found.
-
Malspam campaign uses Google DoubleClick redirect chain to deliver DesckVB RAT
A malspam campaign is using Google DoubleClick redirects and personalized phishing pages to deliver DesckVB RAT, a .NET trojan. The attack chain uses HTML attachments, PowerShell, process hollowing, and anti-analysis checks.
-
CISA warns of cyberattacks targeting fuel tank monitoring systems
CISA warned on June 3 that cyberattacks are targeting fuel tank monitoring systems used in critical infrastructure. The report did not identify the attackers or say whether the activity caused outages or damage.
-
One-click VS Code attack can steal GitHub tokens from GitHub.dev
A technical analysis says a one-click attack against GitHub.dev in VS Code can steal a GitHub token with access to private repositories. Microsoft has acknowledged the issue and said it is working on a fix.
-
Unpatched Windows Search URI flaw could leak NTLMv2 hashes
Researchers said an unpatched Windows search: URI flaw could leak NTLMv2 hashes through a crafted link. Microsoft did not fix the issue after disclosure in April 2026, and the report advised SMB and NTLM mitigations.









