Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Compromised Flutter package on pub.dev contains XCSSET malware

Today, pub.dev joins the list of package registries we have found malware on. We detected a variant of XCSSET hiding inside universal_file_viewer (version 0.1.5), a Flutter file preview package on pub.dev with around 500 downloads. This is the first compromised package we have detected on pub.dev, the official package repository for Dart and Flutter. Unlike the recent npm supply chain attacks you might be familiar with, this was not a case of someone deliberately targeting this package.

ThreatSpike Product Updates August 2026

Network management gets its most significant expansion yet this month with a complete topology map, path tracing, switch visualisation, syslog collection and more, all shipping together. Alongside it: a redesigned ticket status system, Credentials Manager updates, SQL Server metrics monitoring and more. Here’s everything that shipped.
Featured Post

Increasingly Dangerous Threats, Not More Alerts, Are the New SOC Challenge

For years, security operations centres have operated under the same constraints of more alerts than analysts, more investigations than hours in the day, and more pressure than most teams can sustainably absorb. That imbalance is becoming dangerous as frontier models rapidly improve at finding vulnerabilities and turning them into exploits, while defenders are left dealing with the consequences in real time.

Why Network Privacy is Becoming a Critical Layer of Modern Cybersecurity

In 2026, network privacy has become a critical layer of modern cybersecurity. With cyber threats becoming increasingly advanced and businesses embracing hybrid work, cloud platforms, and interconnected systems, network security can protect data moving across networks and reduce exposure to cybercrime. This article will explore why network security is so important in 2026, the risks associated with unsecured connections, and how businesses can strengthen their posture. Read on to find out more.

Sophos To Bring OpenAI GPT Cyber Models Into Managed Risk Offering, Helping Defenders Validate Exploit Paths

The company is building a new Exploit Path Verification (EPV) capability that will tell security teams which vulnerabilities an attacker can reach in their environment, turning long exposure lists into evidence-backed priorities.

Session on AirGapped AI - Adopt AI Privately and Securely, AI Trends from Around the World at CyBe

In this session at CyBe AI Summit 2026, NIMHANS Convention Centre in Bengaluru, our Founder & CEO Mr. Anirban Mukherji discussed current AI trends, geopolitical and sovereignty risks tied to frontier LLMs, and practical implementations for India. He addressed how AI-driven automation like delivery robots and drones can disrupt jobs, why governments and defense agencies require air-gapped or on-prem solutions, and how cost and restricted access to frontier models create inequity in AI adoption.