Weekly #cybersecurity digest to your inbox

Subscribe for our weekly digest and get each Friday the most important cyber security news, list of upcoming free webinars and a summary of Cyberday development to your inbox.
Thanks! See you in your inbox on Fridays. :)
Unfortunately something went wrong. You can contact us at team@cyberdayai.

Encryption, RaaS, supply chain attacks: Monthly Cyberday product and news roundup 12/2023 🛡️

In December's summary, development themes include UI updates and information security statements. On the news side talk about encryption, RaaS and supply chain attacks.

article

15.12.2023

How do you benefit from ISO 27001 certification?

Why do organizations choose to go for ISO 27001 certification? In this blog article, we will give you our top 5 reasons to get certified. Certification will certainly benefit your security directly, but there are other kind of benefits available too.

article

25.10.2023

Working towards NIS2 compliance with Cyberday

✈️ You want to lift your cyber security management to a new level & get NIS2 compliant with a smart tool like Cyberday? In this post you'll learn how your organization can achieve NIS2 compliance in a smart way by building an own agile ISMS.

article

23.8.2023

Who does NIS2 apply to? Scope and required security measures explained.

In this post you'll learn about what industries are affected by NIS2, security requirements the directive sets, and the available enforcement methods if an organization is not compliant.

article

23.8.2023

What is NIS2 directive? Know EU's new cyber security legislation

Learn what is the new EU NIS2 directive, why the original NIS was not enough and how it affects your company's compliance requirements.

article

1.8.2023

SOC 2: Working towards compliance

With the help of SOC 2, organisations can provide proof of effectively implemented controls and the use of best practices to protect the data to their customers and stakeholders, which may help to build trust.

article

31.7.2023

Personnel information security training and guidelines in Cyberday

Most data breaches start with human error. Still, investments in technical information security are often made more eagerly. We tell you why staff information security training and guidelines are important and how to implement then efficiently.

article

13.6.2023

Information security risk management in Cyberday: Identifying risks, evaluation, treatment and closure

Every cyber security framework highlights risk management in its own way. We summarize in this post, what's essential in information security risk management and what kind of an approach Cyberday offers for it.

article

13.6.2023

Threat Trends: Vulnerabilities

📈 We have another record year in CVE disclosure, already 18000+ disclosed. Still most CVEs never get exploited. How should you prioritize #vulnerability's for treatment? Which are severe, which just get media attention? Article has tips ->

Go to article at
30.9.2022

IT admin admits sabotaging ex-employer’s network in bid for higher salary

⚠️ In a bid to get re-hired w/ a larger salary, ex IT employee admitted to sabotage. Mr Umetsu used his old (!) creds to edit DNS records to misdirect web and email traffic. Now he faces upto 10y in prison. #cybersecurity

Go to article at
30.9.2022

Capital One Phish Showcases Growing Bank-Brand Targeting Trend

Phishers watch the news. 📨 6000 #phishing emails going out daily in a scam targeting identities. Campaign exploits Capital One's new partnership with Authentify, tricking bank's customers into uploading images of ID cards.

Go to article at
30.9.2022

Critical WhatsApp Bugs Could Have Let Attackers Hack Devices Remotely

💊 WhatsApp patches two severe flaws that could lead to RCE attacks. One of them (CVE-2022-36934, CVSS score: 9.8) is an integer overflow #vulnerability that can be exploited through establishing a video call.

Go to article at
30.9.2022

Can your iPhone be hacked? What to know about iOS security

Device's #cybersecurity largely depends on your usage. Examples of things that can compromise an iPhone: 💣 sideloaded apps 📱 malicious apps from App Store 📅 calendar invite scams 🛠️ configuration profiles installed through phishing

Go to article at
23.9.2022

Spell-Checking in Google Chrome, Microsoft Edge Browsers Leaks Passwords

Researchers found an "unintended interaction" with #cybersecurity worries: 🔓 When Chrome's Enhanced Spellcheck or Edge's MS Editor is enabled on your browser, the passwords you type on websites leak to Google and Microsoft.

Go to article at
23.9.2022

$35 Million Fine For Morgan Stanley After Unencrypted, Unwiped Harddrives Are Auctioned

💸 $35 million penalty for Morgan Stanley SEC’s enforcement division: "Improper disposal of thousands of hard drives since 2016 was an 'extensive failure' to safeguard customers’ data (as required by federal regulations)". #cybersecurity

Go to article at
23.9.2022

Malwarebytes blocks Google, YouTube as malware

An amusing #malware protection blunder: 📣 "Malwarebytes is aware of a temporary issue with the web filtering component of our product that may be blocking certain domains, including google.com"

Go to article at
23.9.2022

US government software suppliers must attest their solutions are secure

US gov agencies need to start gathering more evidence from software suppliers: ✅ self-attestation needed from suppliers before using the software ❌ if NIST requirements not followed, more explanation / assessments needed #cybersecurity

Go to article at
16.9.2022