Cristian Luțic

Cristian Luțic is a cybersecurity professional and Editor-in-Chief of iSec.News, with experience in security enablement, risk analysis, and vulnerability reporting. As Editor-in-Chief, he is responsible for editorial standards, source verification, and publication oversight at iSec News.
From professional sports to cybersecurity, his career path may have been unconventional, but it has been driven by the same core values: discipline, perseverance, and a passion for doing meaningful, impactful work.
iSec.News Motto: “Only news, only information security and privacy news. No fluff.”
-
Storm-2561 uses SEO poisoning to deliver trojan VPN clients that steal credentials
Microsoft disclosed a credential theft campaign that used SEO poisoning to deliver digitally signed trojan VPN clients that harvest credentials. The activity was observed in mid-January 2026 and is linked to Storm-2561.
-
European Parliament extends temporary CSAM detection exemption until August 2027
The European Parliament extended a temporary ePrivacy derogation allowing voluntary CSAM detection until 3 August 2027. Lawmakers imposed limits and exclusions for end-to-end encryption as they work to negotiate a permanent legal framework.
-
Google patches two Chrome zero-days exploited in the wild
Google released Chrome updates to fix two high severity zero-days exploited in the wild. Both are scored 8.8. Users should update Chrome to the listed versions on Windows macOS and Linux to reduce risk.
-
Nine CrackArmor Flaws in Linux AppArmor Could Enable Local Root Escalation
Qualys disclosed nine confused deputy vulnerabilities in the Linux kernel AppArmor module that can allow unprivileged users to bypass protections, escalate to root, and undermine container isolation. Vendors and administrators should prioritise kernel patches.
-
Starbucks says 889 Partner Central accounts were compromised in employee data breach
Attackers accessed 889 Starbucks Partner Central accounts used by employees. Exposed data includes names, Social Security numbers, dates of birth, and bank account information. Impacted partners are being offered two years of identity theft protection and credit monitoring.
-
Authorities dismantle SocksEscort proxy service built from infected residential routers
Court-authorized international law enforcement disrupted the SocksEscort proxy service in March 2026, dismantling a router-based botnet and freezing $3.5 million in cryptocurrency, the U.S. Department of Justice said.
-
Loblaw notifies customers after breach exposes names and contact details
Loblaw notified customers this week that a breach of a contained part of its IT network exposed names phone numbers and email addresses. The company logged customers out and there was no evidence that financial or health data were accessed.
-
Researchers identify suspected AI-assisted Slopoly backdoor used by Hive0163
Researchers identified a suspected AI-generated PowerShell backdoor called Slopoly used by the cybercrime group Hive0163 in early 2026. The backdoor established persistence and beaconed to a command server while analysts examined code patterns.
-
Authorities disrupt SocksEscort proxy network powered by AVRecon on Linux routers
Law enforcement disrupted the SocksEscort proxy network that used AVRecon to compromise Linux routers. Lumen’s Black Lotus Labs reported the network averaged about 20,000 infected devices weekly and authorities seized infrastructure and froze funds.
-
U.S. charges former DigitalMint negotiator in scheme linked to BlackCat ransomware
The Department of Justice charged Angelo Martino, a former DigitalMint ransomware negotiator, with one count of conspiracy to interfere with interstate commerce by extortion after his March 10 surrender. Allegations include sharing negotiation details with BlackCat.








