Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

SparkKitty Malware: An Emerging Threat to Mobile Users

SparkKitty is a newly uncovered cross-platform information stealer, designed to exfiltrate sensitive data—particularly cryptocurrency wallet seed phrases—by leveraging advanced optical character recognition (OCR) techniques on both Android and iOS devices. The malware, discovered by Kaspersky in early 2024 and publicly detailed in June 2025, appears to be a direct evolution of a previous stealer known as SparkCat.
Featured Post

Recovery Defines Resilience

Most organisations now recognise that a serious cyber incident is likely, but the real question is whether they can keep running when it happens. A major incident can disrupt services, damage revenue, expose governance weaknesses and test customer trust as events unfold. The greatest risk often sits in the gap between recognising that reality and having a recovery plan that works under pressure. That is where financial loss, operational disruption and regulatory scrutiny can quickly escalate.

How to Test Your Website From Another Country (and Why Your Monitoring Says It's Fine)

The ticket says nobody in Brazil can log in. Your status page is green, every synthetic check passed in the last five minutes, and the last deploy went out three days ago. You run the check by hand. Still green. Then someone on the call opens the site on their phone, on mobile data, and gets a challenge page. I've watched that hour play out more than once. It's rarely a bug in the application. It's that the thing doing the checking and the person doing the complaining look like two completely different visitors to your own edge, and nothing in your stack is set up to notice.

Why Flipping Cyber Defense Backwards Works

Standard incident response is failing to keep pace with long-term threat campaigns. Adam Karcher from the FBI explains why the most effective security teams run their operations as an inverted offensive strategy, leveraging continuous adversary emulation to stop intrusions before they begin. Watch the full video on our channel.

How to Publish Multiple Policy Types in One Request: A Step-by-Step Guide

In this comprehensive guide, we will explain how to efficiently publish multiple policy types in a single request using the Fireblocks Policy Engine. This streamlined process allows you to update various policy types—such as transfer policies and typed message policies—simultaneously, ensuring that all changes are coordinated and compliant. Key Benefits of Multi-Type Policy Publishing.

How to Export Fireblocks Transaction Policies as CSV or JSON: A Step-by-Step Guide

In this comprehensive guide, learn how to export your Fireblocks transaction policies in both CSV and JSON formats. This video walks you through the process of selecting your policies, choosing the appropriate format, and securely downloading your data. Key Topics Covered: Exporting Policies: Understand how to access the active policy section from the Policy Overview screen. Choosing Formats: Discover the differences between CSV and JSON exports.

How to Use Policy Inspector to Diagnose Transaction Failures in Fireblocks

In this comprehensive guide, learn how to effectively use the Policy Inspector tool within Fireblocks to diagnose and resolve transaction failures. The Policy Inspector provides clear insights into which policy rules blocked a transaction and the reasons behind it, eliminating guesswork and streamlining communication with your security team. Key Features of Policy Inspector: Transaction Simulation: Test any transaction against your active policies directly in the console. Detailed Insights.

When the 'Attacker' Was an AI Agent: Lessons from the OpenAI-Hugging Face Breach

In this episode of Sophos Cyber Shorts, host Susie Evershed is joined by Ross McKerchar, Sophos CISO, to discuss the recent OpenAI and Hugging Face incident and what it reveals about the future of AI security. From containment failures and over-privileged AI workflows to faster AI-driven attacks, Ross shares practical advice for security leaders on how to strengthen resilience, response, and recovery.

The AI governance confidence gap: Why trust in AI is running ahead of the capacity to govern it

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.