Weekly #cybersecurity digest to your inbox

Subscribe for our weekly digest and get each Friday the most important cyber security news, list of upcoming free webinars and a summary of Cyberday development to your inbox.
Thanks! See you in your inbox on Fridays. :)
Unfortunately something went wrong. You can contact us at team@cyberdayai.

What is the NIS2 Law in Belgium? 🇧🇪 Introduction to requirements

Learn what the Belgian NIS2 Law is, Belgium’s national implementation of the EU NIS2 Directive. Understand key requirements, compliance timelines, sector coverage, and how Cyberday helps you meet them.

article

29.4.2025

What is CyberFundamentals? 🇧🇪 Belgium's cybersecurity framework

Learn what is CyberFundamentals, Belgium's cybersecurity framework for SMEs. Get an overview of requirements, benefits, and steps for compliance.

article

29.4.2025

10 things I wish I knew: Starting your ISO 27001 project on the right track

This post shares 10 key lessons learned from going through an ISO 27001 certification project - from the importance of setting clear goals and managing documentation to the realities of risk management and the value of using the right tools.

article

23.4.2025

Understanding NIS2: supervision and penalties of non-compliance

Let's now look into the NIS2 directive, it's supervision in EU member states and what is supervised. We'll also check out NIS2 penalties for noncompliance and how you can stay compliant (to avoid penalties).

article

15.4.2025

Comparing EU cybersecurity frameworks: NIS2, GDPR, DORA and more

A comparison of key cybersecurity frameworks in the EU, including NIS2, GDPR, DORA, CRA, and ISO 27001. Learn who they apply to and what they require.

article

10.4.2025

ISO 27001 compliance vs. certification: differences, benefits & which path to choose

Understanding when to pursue ISO 27001 compliance rather than going for certification—or vice versa—hinges on your organizational priorities, resources, and long-term security strategies. Check the differences and learn which path to choose.

article

1.4.2025

Framework recap, US security & and role management: Cyberday product and news summary 3/2025 🛡️

The March product and news update presents updates to role management and the new Trust Center, a review of the key frameworks for 2025 and US security.

article

28.3.2025

Understanding DORA compliance: Key steps to prepare your organization

Understand DORA compliance and get a clear DORA requirements summary with key compliance areas, practical steps, and essential guidelines to strengthen your organization's digital resilience.

article

18.3.2025

Meet Borat RAT, a New Unique Triple Threat

RAT #malware typically helps attacker gain control of a system, permitting access to network resources, files, and control mouse and keyboard. ☣️ Borat RAT goes beyond - deploying ransomware and DDoS attacks. Learn more from article >>

Go to article at
26.8.2022

Over 80,000 exploitable Hikvision cameras exposed online

Researchers discovered 80,000 Hikvision cameras w/ command injection #vulnerability - easily exploitable by sending specially crafted messages to server. ⚠️ Patch available for months, but thousands of organizations have not applied it.

Go to article at
26.8.2022

How a spoofed email passed the SPF check and landed in my inbox

📧 SPF lets you publish DNS records to define IPs allowed to use the domain for sending email. Article explains this must-have safeguard + examples where careless SPF records allowed bad actors to impersonate a corporation. #phishing

Go to article at
19.8.2022

Exploit out for critical Realtek flaw affecting many networking devices

⚠️ Exploit code released, zero-click #vulnerability (CVSS 9.8/10) affecting millions of devices with Realtek’s RTL819x SoC. Attacker can compromise e.g. routers from many brands. Patch available - check if your equipment is vulnerable.

Go to article at
19.8.2022

RubyGems now requires multi-factor auth for top package maintainers

Software package registry RubyGems requires top admins to secure accounts w/ MFA. Registries like PyPI and npm are doing the same. ⚠️ This relates to growing trend, where criminals steal accounts to publish rogue software. #cybersecurity

Go to article at
19.8.2022

U.K. Water Supplier Hit With Clop Ransomware Attack

⚠️ U.K. water supplier hit by Clop #ransomware. Attack didn't stop water supply. As ransom wasn't paid, breached data (incl. passports, data system screenshots) was published. Trend continues: critical infra a top target for cybercrime.

Go to article at
19.8.2022

Ransomware, email compromise are top security threats, but deepfakes increase

#Cybersecurity threat reports (2021-2022) from VMware and Palo Alto Unit 42: ☢️ Most common threats: Ransomware, business email compromise (BEC) 📈 Increasing rapidly: Deepfakes, zero-day vulnerability exploits, API hacks

Go to article at
12.8.2022

The Security Pros and Cons of Using Email Aliases

📧 Some users tame their inbox with +app email aliases. Using these can make you the first to know about a breach or leak, if u start receiving mail to an app's alias! Downside is the format might not work on all services. #cybersecurity

Go to article at
12.8.2022

10 Credential Stealing Python Libraries Found on PyPI Repository

⚠️ Growing #cybersecurity threat - bad actors publish rogue software on popular public repositories. Now 10 modules removed from Python Package Index (PyPI) that harvest critical data (e.g. passwords, API tokens). Details in article >>

Go to article at
12.8.2022