Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Jason Haddix: Stop fearing AI pentesting

This post is based on Mackenzie's conversation with Jason Haddix on The Secure Disclosure podcast. Listen to the full episode or watch below. Jason Haddix has topped the Bugcrowd leaderboards, run security as CISO of Ubisoft, and wrote The Bug Hunter's Methodology, the playbook a lot of working pentesters learned from, so his read on the direction of the field is worth listening to. He believes that “90% of pen tests will be done by AI” in the near future.

Compromised Flutter package on pub.dev contains XCSSET malware

Today, pub.dev joins the list of package registries we have found malware on. We detected a variant of XCSSET hiding inside universal_file_viewer (version 0.1.5), a Flutter file preview package on pub.dev with around 500 downloads. This is the first compromised package we have detected on pub.dev, the official package repository for Dart and Flutter. Unlike the recent npm supply chain attacks you might be familiar with, this was not a case of someone deliberately targeting this package.

ThreatSpike Product Updates August 2026

Network management gets its most significant expansion yet this month with a complete topology map, path tracing, switch visualisation, syslog collection and more, all shipping together. Alongside it: a redesigned ticket status system, Credentials Manager updates, SQL Server metrics monitoring and more. Here’s everything that shipped.
Featured Post

Increasingly Dangerous Threats, Not More Alerts, Are the New SOC Challenge

For years, security operations centres have operated under the same constraints of more alerts than analysts, more investigations than hours in the day, and more pressure than most teams can sustainably absorb. That imbalance is becoming dangerous as frontier models rapidly improve at finding vulnerabilities and turning them into exploits, while defenders are left dealing with the consequences in real time.

Why Network Privacy is Becoming a Critical Layer of Modern Cybersecurity

In 2026, network privacy has become a critical layer of modern cybersecurity. With cyber threats becoming increasingly advanced and businesses embracing hybrid work, cloud platforms, and interconnected systems, network security can protect data moving across networks and reduce exposure to cybercrime. This article will explore why network security is so important in 2026, the risks associated with unsecured connections, and how businesses can strengthen their posture. Read on to find out more.

What Is MFA for Air-Gapped Networks? Closing the Last Security Gap in Isolated Systems

Air-gapped networks are supposed to be untouchable. No internet connection, no remote pathway, no way in for an attacker sitting halfway across the world. But ask any security team that has actually run one of these environments, and you'll hear a different story. Air gaps stop remote attacks cold. But they do almost nothing to stop a stolen password, a careless USB stick, or an insider with too much trust and too little oversight. That's the gap, and Multi-Factor Authentication (MFA) is here to fill it.