Cristian Luțic

Cristian Luțic is a cybersecurity professional and Editor-in-Chief of iSec.News, with experience in security enablement, risk analysis, and vulnerability reporting. As Editor-in-Chief, he is responsible for editorial standards, source verification, and publication oversight at iSec News.
From professional sports to cybersecurity, his career path may have been unconventional, but it has been driven by the same core values: discipline, perseverance, and a passion for doing meaningful, impactful work.
iSec.News Motto: “Only news, only information security and privacy news. No fluff.”
-
Interlock ransomware exploited Cisco FMC zero-day CVE-2026-20131
Amazon Threat Intelligence links Interlock ransomware to exploitation of Cisco Secure FMC CVE-2026-20131. The flaw allowed unauthenticated root code execution and was used as a zero-day from January 26, 2026. Apply patches and assess systems.
-
Nine vulnerabilities in low-cost IP KVM devices can enable root access and arbitrary code execution
Nine vulnerabilities in low-cost IP KVM devices can allow unauthenticated attackers root access or arbitrary code execution. A technical analysis by Eclypsium highlights a CVSS 9.8 flaw and notes partial firmware fixes are available.
-
CVE-2026-3888 in Ubuntu Desktop allows local users to escalate to root
A high severity flaw in default Ubuntu Desktop installs of 24.04 and later allows a local unprivileged user to escalate to root. The issue is CVE-2026-3888 and patches for snapd are available for affected releases.
-
Critical pre-auth buffer overflow found in GNU InetUtils telnetd tracked as CVE-2026-32746
A pre-authentication buffer overflow in GNU InetUtils telnetd, tracked as CVE-2026-32746 and rated CVSS 9.8, can allow unauthenticated remote code execution as root. A fix is expected by April 1, 2026.
-
Big Tech provides $12.5m to help open source maintainers handle AI-generated bug reports
Six major tech firms have provided $12.5 million in grants to a foundation project and OpenSSF to help open source maintainers triage and remediate AI-generated bug and security reports. Details and timing remain unclear.
-
EU sanctions three firms and two individuals over cyberattacks
The EU Council sanctioned three firms and two individuals for cyberattacks on critical infrastructure and devices. One Chinese firm enabled hacking of over 65,000 devices across six EU states and an Iranian firm ran influence operations.
-
LeakNet adopts ClickFix via compromised websites and runs Deno in memory
ReliaQuest’s technical report says LeakNet now uses ClickFix fake CAPTCHA pages on compromised sites to trick users and a Deno-based in-memory loader. Post-compromise steps include DLL side-loading, PsExec lateral movement and S3 exfiltration.
-
DDoS attack disables Perm parking payments, drivers excused for March 10–13
A DDoS attack knocked Perm’s parking payment portal offline from March 10 to 13, leaving paid parking zones free and drivers excused for non-payment while systems were restored.
-
Konni uses compromised KakaoTalk desktops to spread EndRAT via spear-phishing
Konni used spear-phishing to install EndRAT and other RATs then abused compromised KakaoTalk desktops to send malicious ZIP attachments to selected contacts maintaining long-term persistence and stealing internal documents.
-
ForceMemo offshoot of GlassWorm force pushes malware into hundreds of Python repositories
A supply chain campaign called ForceMemo stole GitHub tokens and force-pushed obfuscated code into hundreds of Python repositories starting March 8, 2026. Compromised packages and pip installs may deliver remote payloads.








