Cristian Luțic

Cristian Luțic is a cybersecurity professional and Editor-in-Chief of iSec.News, with experience in security enablement, risk analysis, and vulnerability reporting. As Editor-in-Chief, he is responsible for editorial standards, source verification, and publication oversight at iSec News.
From professional sports to cybersecurity, his career path may have been unconventional, but it has been driven by the same core values: discipline, perseverance, and a passion for doing meaningful, impactful work.
iSec.News Motto: “Only news, only information security and privacy news. No fluff.”
-
Amazon Q Developer flaw let malicious repos run code and expose cloud credentials
Amazon Q Developer had a flaw that let a malicious repository run code and expose cloud credentials, according to Wiz Research. AWS says the issue is fixed, and customers are being urged to update affected plugins and language servers.
-
macOS flaw let standard users disable CrowdStrike and Kandji tools, researchers say
Researchers said a macOS flaw let standard user accounts disable major enterprise security tools, including CrowdStrike Falcon Sensor and Kandji, by abusing XPC communication. Vendors have patched the issue or are working on fixes.
-
Mirage2FA phishing kit uses HTML smuggling to target Microsoft 365 users
Fortra identified Mirage2FA, a phishing kit that uses HTML smuggling and obfuscated JavaScript to mimic Microsoft 365 sign-in pages and steal credentials during MFA prompts in an email campaign tied to cheacker[.]store.
-
Microsoft flags photo ZIP phishing campaign targeting hotels in Europe and Asia
Microsoft said a phishing campaign has targeted hotels and other hospitality organizations in Europe and Asia since April 2026, using photo-themed ZIP files to install a Node.js implant and gain access to front-desk machines.
-
Xsolis says phishing attack exposed data of 1.4 million people
Xsolis said a targeted phishing attack exposed files tied to 1,396,519 people, including names, addresses, Social Security numbers and medical treatment information. The company has notified law enforcement and is offering assistance to affected individuals.
-
DraftKings hacker ‘Snoopy’ gets 18 months in prison
A Minnesota man known as Snoopy was sentenced to 18 months in prison for his role in a 2022 DraftKings account hacking scheme that prosecutors said compromised 60,000 accounts and stole $600,000.
-
Fake GTA 6 early access sites push crypto scam and malware, reports say
Fake websites are using interest in Grand Theft Auto VI to sell nonexistent early access for cryptocurrency, security researchers say. The scam can also install malware on PC and Android devices.
-
Malwarebytes warns of parcel mule job scams posing as remote work
Malwarebytes says scammers are using fake remote job offers, including “Parcel Expert” roles, to recruit parcel mules who receive and forward stolen goods from home. The company warns of fraud, identity theft and possible law enforcement contact.
-
China’s 360 says it has built tools to match Anthropic’s Mythos
Chinese cybersecurity firm 360 Security Technology said on Wednesday in Beijing that it has developed two AI security tools meant to answer Anthropic’s Mythos, including one that it said can automatically discover software vulnerabilities and had found 3,432 flaws. KEY FACTS Conference 360 founder Zhou Hongyi unveiled the tools at the ISC.AI 2026 cybersecurity conference…
-
Mistic backdoor tied to ransomware access broker in attacks on multiple sectors
A new backdoor called Mistic has been used since April in attacks on insurance, education, IT and professional services firms, with researchers linking it to a ransomware access broker that sells network access.








