Cristian Luțic

Cristian Luțic is a cybersecurity professional and Editor-in-Chief of iSec.News, with experience in security enablement, risk analysis, and vulnerability reporting. As Editor-in-Chief, he is responsible for editorial standards, source verification, and publication oversight at iSec News.
From professional sports to cybersecurity, his career path may have been unconventional, but it has been driven by the same core values: discipline, perseverance, and a passion for doing meaningful, impactful work.
iSec.News Motto: “Only news, only information security and privacy news. No fluff.”
-
Hackers exploit Langflow flaw to push Monero miner in March-April campaign
Hackers exploited a critical Langflow remote code execution flaw over a 19-day period in March and April 2026 to deploy a Monero miner, disable security tools and spread to other hosts, according to a technical analysis from Trend Micro.
-
Malicious browser extension campaign steals crypto by swapping wallet addresses
McAfee Labs said a June campaign called Silent Swap uses malicious browser extensions to swap cryptocurrency wallet addresses in the clipboard, while a separate Socket disclosure found fake VPN extensions stealing sensitive data.
-
Japan military used infected USB drives linked to China-based hacking in nearly year-long breach
Japan’s Ground Self-Defense Force used counterfeit USB drives infected with malware on sensitive networks for nearly a year after they entered service during earthquake relief work, according to a Nikkei Asia investigation and leaked internal documents.
-
DHS revives critical infrastructure cyber information sharing with new ANCHOR-CI program
DHS is restoring a cyber information sharing forum for critical infrastructure with ANCHOR-CI, a CISA-run council that replaces CIPAC and will be exempt from federal advisory transparency rules.
-
Fake Perplexity Chrome extension tracked searches on Chrome Web Store
A malicious Chrome Web Store extension posing as Perplexity AI intercepted search traffic and collected browsing data, Microsoft said in a technical analysis. The company found no credential theft, but warned the permissions could enable broader abuse.
-
Exploitation attempts target Oracle Payments flaw patched in May
Exploitation attempts have surfaced against CVE-2026-46817 in Oracle Payments, part of Oracle E-Business Suite. The flaw was patched in May, but defenders are being told to check logs and restrict unpatched systems.
-
KDDI says breach may have exposed up to 14.2 million ISP email logins
KDDI said a breach in one of its email systems may have exposed up to 14.2 million customer email addresses and passwords across six Japanese internet service providers after attackers exploited third-party software.
-
Google details Turla’s STOCKSTAY backdoor used against Ukraine and European targets
Google said Turla used a previously undocumented .NET backdoor called STOCKSTAY against government and military targets in Ukraine and other European entities, with activity dating to December 2022 and delivery through phishing and archive-based lures.
-
Amazon Q Developer flaw let malicious repos run code and expose cloud credentials
Amazon Q Developer had a flaw that let a malicious repository run code and expose cloud credentials, according to Wiz Research. AWS says the issue is fixed, and customers are being urged to update affected plugins and language servers.
-
macOS flaw let standard users disable CrowdStrike and Kandji tools, researchers say
Researchers said a macOS flaw let standard user accounts disable major enterprise security tools, including CrowdStrike Falcon Sensor and Kandji, by abusing XPC communication. Vendors have patched the issue or are working on fixes.








