Weekly #cybersecurity digest to your inbox

Subscribe for our weekly digest and get each Friday the most important cyber security news, list of upcoming free webinars and a summary of Cyberday development to your inbox.
Thanks! See you in your inbox on Fridays. :)
Unfortunately something went wrong. You can contact us at team@cyberdayai.

Access control & MFA in NIS2: Build a solid foundation with ISO 27001 controls

What are the requirements for access control and MFA in NIS2 and ISO 27001 and how can they be implemented successfully? Learn more about the controls, requirements, best practices and how to overcome potential challenges in this blog post.

article

4.4.2024

Potential Struggles IT Companies might Encounter with Incident Identification and Reporting Today

The complexities of incident identification and reporting in IT, touching on coordination problems, tool inadequacies, and process deficiencies. It explores modern challenges like cyber threats and alert fatigue, as well as the cognitive gap.

article

28.3.2024

Information Security Risk Management: A Step-by-step Guide to a Clear Process

Get a step-by-step guide on managing information security risks, from asset identification to monitoring, essential for navigating growing cybersecurity threats.

article

21.3.2024

Ransomware, AI Act 101, NIST CSF 2.0: Cyberday product and news round up 3/2024 🛡️

In the March digest, development themes include new frameworks, risk management improvements and a new visual view for documentation cards. The news features Information Security Trailblazers, data breaches and AI Act 101.

article

21.3.2024

Empowering Employees: The Keystone in Incident Detection and Reporting

Employees are vital for detecting and reporting cyber threats and bolstering security. Proper training fosters a resilient culture, ensuring timely responses and safeguarding against breaches.

article

15.3.2024

Incident reporting in NIS2: Requirements and related ISO 27001 best practices

Understand NIS2 incident reporting requirements and how ISO 27001 best practices can help ensure compliance and enhance your organization's security posture.

article

8.3.2024

Top 7 information security standards, frameworks and laws explained

Many information security frameworks are available to help organizations build their own security plans. This article provides key information about some of the most popular information security frameworks.

article

4.3.2024

ISO 27001 and NIS2: Understanding their Connection

Learn how ISO 27001 and NIS2 relate, how they differ, and why organizations often address them together for stronger cybersecurity and compliance.

article

1.3.2024

100 people arrested in UK’s biggest fraud investigation

Over 200k victims were targeted via the iSpoof fraud website, which was taken down by Scotland Yard’s #cybercrime unit. 100 people arrested. Almost 20 people every minute were being contacted by scammers - stealing reported £50m.

Go to article at
25.11.2022

Bahamut cybermercenary group targets Android users with fake VPN apps

Active #malware campaign ongoing disquising as legitimate SecureVPN app. Main purpose of the app modifications is to extract sensitive user data and actively spy on victims’ messaging apps. Read a detailed analysis >>

Go to article at
25.11.2022

Ouch! Ransomware gang says it won’t attack AirAsia again due to the “chaotic organisation” and sloppy security of hacked airline’s network

⚠️ #Ransomware breach can also lead to gross public humiliation. Daixin gang said Air Asia, who lost data of 5M passengers and all employees, had so chaotic and poorly-secured IT infra that it refuses to repeat the attack.

Go to article at
25.11.2022

ICS cyberthreats in 2023 – what to expect

2023 #cybersecurity trends: More attacks on "real economy" - food 🌾 transport 🚢 energy ⚡ medical 💊 Rising number of political hacktivists 🦹 Ransomware towards critical infra 🏭 Rise of embedded phishing pages on legitimate sites 🎣

Go to article at
25.11.2022

Token tactics: How to prevent, detect, and respond to cloud token theft

⚠️ When we increase MFA coverage, threat actors need more sophisticated techniques to compromise resources. Recently there's been a significant increase in token theft. Read Microsoft's DART team's report on the #cybersecurity threat >>

Go to article at
18.11.2022

Google to Pay $391 Million Privacy Fine for Secretly Tracking Users' Location

391M$ fine: Google's #privacy actions deemed deceptive. ⚠️ "misled users to think they turned off location tracking, but continued to collecting data" Location is combined with behavioral data to create user profiles eg for ad targeting.

Go to article at
18.11.2022

Instagram Impersonators Target Thousands, Slipping by Microsoft's Cybersecurity

⚠️ #Phishing attack targets 22k students in the US with a "unusual login on Instagram" scam. To note: attack used a valid 41-month old domain with a good reputation, and was able to pass e.g. MS 365 and Exchange email protections.

Go to article at
18.11.2022

It’s time. Delete your Twitter DMs

Twitter is in quite a chaos. Security people are advising to e.g. delete DMs 💬 and stop using Twitter SSO 🔐. Recently quitted Twitter employees include: - CISO - Head of Trust & Safety - CPO (privacy) - CCO (compliance) #cybersecurity

Go to article at
18.11.2022

The Biggest Phishing Breaches of 2022 and How to Avoid them for 2023

#Phishing attacks were once primitive and full of typos, but nowadays even experts have trouble identifying them. Top types in 2022: 🅰️ Typosquatting 🌐 Lookalike domains 👔 Executive impersonation 🧑‍💼 High-level employee targeting

Go to article at
11.11.2022