Cristian Luțic

Cristian Luțic is a cybersecurity professional and Editor-in-Chief of iSec.News, with experience in security enablement, risk analysis, and vulnerability reporting. As Editor-in-Chief, he is responsible for editorial standards, source verification, and publication oversight at iSec News.
From professional sports to cybersecurity, his career path may have been unconventional, but it has been driven by the same core values: discipline, perseverance, and a passion for doing meaningful, impactful work.
iSec.News Motto: “Only news, only information security and privacy news. No fluff.”
-
DeepLoad malware uses ClickFix lure and WMI to spread and steal credentials
A new DeepLoad malware campaign is using ClickFix lures, Windows tools and WMI to steal credentials, hide activity and reinfect cleaned hosts, according to a technical analysis from ReliaQuest.
-
European Commission says attackers breached public web infrastructure
The European Commission said attackers broke into cloud systems hosting its Europa websites on March 24 and may have taken data. The sites stayed online, but officials gave few details about what was exposed.
-
Russian-origin CTRL toolkit spread through malicious Windows shortcut files, researchers say
Researchers say a Russian-origin toolkit called CTRL was spread through malicious Windows shortcut files disguised as private key folders. The malware adds phishing, keylogging, RDP hijacking and reverse tunneling while limiting network traces.
-
Three China-linked clusters targeted Southeast Asian government, researchers say
Researchers said three China-linked clusters targeted a Southeast Asian government organization in 2025, using several malware families and techniques aimed at staying inside networks for long-term access.
-
Intellexa founder says he will appeal Greek spyware conviction
Intellexa founder Tal Dilian said he will appeal his Greek conviction over a mass-wiretapping case tied to Predator spyware, which was used to hack phones belonging to ministers, opposition leaders, military officials and journalists.
-
Startup Delve accused of supplying fake compliance evidence to customers
An anonymous Substack post accuses Delve of supplying fabricated compliance evidence to hundreds of customers, potentially exposing them to HIPAA criminal liability and GDPR fines. The company posted a blog response calling its product an automation platform.
-
China-linked group embeds stealthy kernel backdoors in telecom networks, Rapid7 says
Security firm Rapid7 reported that a China-linked threat cluster known as Red Menshen has embedded kernel-level implants and stealthy backdoors such as BPFDoor inside telecommunications networks to gather intelligence while evading conventional detection.
-
UK sanctions Xinbi marketplace linked to Southeast Asian scam centres
The U.K. has sanctioned Xinbi, a Chinese-language marketplace accused of selling stolen data and cryptocurrency services to scam centres in Southeast Asia, and targeted the operators of a large scam compound known as #8 Park, as part of efforts to disrupt crypto-based money laundering and large-scale investment fraud.








