Cristian Luțic

Cristian Luțic is a cybersecurity professional and Editor-in-Chief of iSec.News, with experience in security enablement, risk analysis, and vulnerability reporting. As Editor-in-Chief, he is responsible for editorial standards, source verification, and publication oversight at iSec News.
From professional sports to cybersecurity, his career path may have been unconventional, but it has been driven by the same core values: discipline, perseverance, and a passion for doing meaningful, impactful work.
iSec.News Motto: “Only news, only information security and privacy news. No fluff.”
-
Fake IT support calls on Microsoft Teams push EtherRAT malware
Threat actors are using Microsoft Teams voice calls to impersonate IT support and push EtherRAT malware, according to a Unit 42 technical analysis. The campaign combines phishing emails, remote-access tools and a Node.js loader.
-
BeyondTrust patches critical flaws in Remote Support and Privileged Remote Access
BeyondTrust patched four vulnerabilities in its Remote Support and Privileged Remote Access products, including two critical authentication flaws that could allow unauthorized access under specific configurations. The company said the issues were found internally and has not reported active exploitation.
-
Spain arrests man suspected of aiding pro-Russian hacktivist groups
Spain arrested a man in Palencia who is suspected of aiding pro-Russian hacktivist groups CyberArmy of Russia Reborn and Z-Pentest. Police seized devices, froze crypto wallets and said the probe began with FBI information.
-
GitHub agentic workflow flaw could expose private repositories, researchers say
Researchers say a prompt injection flaw in GitHub Agentic Workflows could let attackers use a public issue to pull data from private repositories without stealing an account or exploiting software vulnerabilities.
-
Fake Netflix, Coca-Cola and FIFA job scams target marketing workers
A phishing campaign has impersonated Netflix, Coca-Cola, Adidas and FIFA to target marketing professionals for at least five months, using fake interview requests and built-in Google login pop-ups to steal accounts.
-
Iran-linked hackers use new Cavern C2 against Israeli targets
Iran-linked hackers used a new modular command and control framework called Cavern against Israeli organizations, according to Check Point Research. The activity relied on DLL side loading, service-provider trust chains and multiple post-exploitation modules.
-
Researchers link Microsoft device code phishing campaign to reusable DEBULL tooling
Researchers say a June and July Microsoft 365 device code phishing campaign used collaboration-themed lures, a compromised website and reusable DEBULL tooling to hijack accounts through Microsoft’s legitimate sign-in flow.
-
Linux KVM flaw lets guest VM corrupt host memory after 16 years undetected
A Linux KVM use-after-free flaw tracked as CVE-2026-53359 can let a guest VM crash the host, and a withheld exploit is said to reach host code execution on x86 systems with nested virtualization enabled.
-
Threat actors probe patched Gitea Docker flaw after public disclosure
Threat actors have started probing a patched Gitea Docker vulnerability, according to Sysdig. The flaw affects versions through 1.26.2 and can let a reachable container accept forged login headers.
-
Adobe ColdFusion flaw exploited within hours of disclosure, researcher says
Attackers are exploiting a maximum-severity Adobe ColdFusion flaw, CVE-2026-48282, within hours of disclosure, according to a researcher. The bug can enable remote code execution on unpatched systems, and officials have urged rapid patching.







