Weekly #cybersecurity digest to your inbox

Subscribe for our weekly digest and get each Friday the most important cyber security news, list of upcoming free webinars and a summary of Cyberday development to your inbox.
Thanks! See you in your inbox on Fridays. :)
Unfortunately something went wrong. You can contact us at team@cyberdayai.

What is the NIS2 Law in Belgium? 🇧🇪 Introduction to requirements

Learn what the Belgian NIS2 Law is, Belgium’s national implementation of the EU NIS2 Directive. Understand key requirements, compliance timelines, sector coverage, and how Cyberday helps you meet them.

article

29.4.2025

What is CyberFundamentals? 🇧🇪 Belgium's cybersecurity framework

Learn what is CyberFundamentals, Belgium's cybersecurity framework for SMEs. Get an overview of requirements, benefits, and steps for compliance.

article

29.4.2025

10 things I wish I knew: Starting your ISO 27001 project on the right track

This post shares 10 key lessons learned from going through an ISO 27001 certification project - from the importance of setting clear goals and managing documentation to the realities of risk management and the value of using the right tools.

article

23.4.2025

Understanding NIS2: supervision and penalties of non-compliance

Let's now look into the NIS2 directive, it's supervision in EU member states and what is supervised. We'll also check out NIS2 penalties for noncompliance and how you can stay compliant (to avoid penalties).

article

15.4.2025

Comparing EU cybersecurity frameworks: NIS2, GDPR, DORA and more

A comparison of key cybersecurity frameworks in the EU, including NIS2, GDPR, DORA, CRA, and ISO 27001. Learn who they apply to and what they require.

article

10.4.2025

ISO 27001 compliance vs. certification: differences, benefits & which path to choose

Understanding when to pursue ISO 27001 compliance rather than going for certification—or vice versa—hinges on your organizational priorities, resources, and long-term security strategies. Check the differences and learn which path to choose.

article

1.4.2025

Framework recap, US security & and role management: Cyberday product and news summary 3/2025 🛡️

The March product and news update presents updates to role management and the new Trust Center, a review of the key frameworks for 2025 and US security.

article

28.3.2025

Understanding DORA compliance: Key steps to prepare your organization

Understand DORA compliance and get a clear DORA requirements summary with key compliance areas, practical steps, and essential guidelines to strengthen your organization's digital resilience.

article

18.3.2025

LockBit victims in the US alone paid over $90m in ransoms since 2020

⚠️ Seven nations (e.g. USA, UK, Germany) issued a joint security advisory about LockBit #ransomware gang. Advisory is a manual for identifying, stopping and reporting LockBit activity, which has cost > $90m for only US victims in 3 years.

Go to article at
16.6.2023

People Are Pirating GPT-4 By Scraping Exposed API Keys

💳 To use OpenAI's LLMs (eg GPT-4), you need an OpenAI account w/ credit card. Some authors have left API keys exposed in their publicly accessible code - and now access to accounts with upto 150k$ usage are offered online. #cybercrime

Go to article at
9.6.2023

New PowerDrop Malware Targeting U.S. Aerospace Industry

⚠️ Novel #malware found implanted in an unnamed domestic aerospace defense contractor last month. "PowerDrop uses advanced techniques to evade detection such as deception, encoding, and encryption" #cybersecurity #criticalinfra

Go to article at
9.6.2023

7 tips for spotting a fake mobile app

📱 Many apps are after your money or personal data. Remember when downloading apps: ✅ Check the developer’s pedigree 📵 Look out for excessive app permissions Other similar tips for #cybersecurity in the article >>

Go to article at
9.6.2023

Deepfake Cyber Attack Hits Russia: Fake Putin Message Broadcasted

📺 Hacker snuck in a fabricated message from Putin to russian radio and TV. Audio deepfakes are becoming very feasible with current tech. Convincing video deepfakes are more of a challenge, for now. #cybersecurity

Go to article at
9.6.2023

Volt Typhoon targets US critical infrastructure with living-off-the-land techniques

Volt Typhoon is a state-sponsored actor, active since mid-2021 that targets critical infrastructure in the US. ➡️ This blog from MS describes their tactics for achieving / maintaining unauthorized access to target networks. #cybersecurity

Go to article at
26.5.2023

OpenAI Leaders Call For Regulation To Prevent AI Destroying Humanity

ChatGPT founders call for a regulator to: ⚖️ place restrictions on AI 🔎 audit AI systems ✔️ test for compliance with safety standards in order to combat e.g. lock-in effects and becoming completely dependent on machines. #cybersecurity

Go to article at
26.5.2023

Shedding light on AceCryptor and its operation

AceCryptor has been around since 2016 and operates as the cryptor-as-a-service behind tens of #malware families ➡️ This blog by ESET researchers goes through some technical details about the prevalent cryptor.

Go to article at
26.5.2023

US Department of Transportation Suffered a Massive Security Breach Impacting 237,000 Federal Employees

⚠️ US Department of Transportation had a #cybersecurity breach exposing personal data of 114k current + 123k former employees. Breach hit staff administration systems (e.g. transit benefits), not the most critical transport safety systems.

Go to article at
26.5.2023