Weekly #cybersecurity digest to your inbox

Subscribe for our weekly digest and get each Friday the most important cyber security news, list of upcoming free webinars and a summary of Cyberday development to your inbox.
Thanks! See you in your inbox on Fridays. :)
Unfortunately something went wrong. You can contact us at team@cyberdayai.

ISO 27001 and ISO 9001: Differences, how they work together and benefits of combining

Learn about the synergy between ISO 27001 and ISO 9001. Learn how integrating these standards enhances information security, quality management, and overall operational efficiency, using case examples and actionable insights.

article

6.6.2024

NIS2 Compliance: Top 5 Reasons for the Manufacturing Sector

The article highlights the critical importance for manufacturers to comply with NIS2 regulations to safeguard their operations and infrastructure from cyber threats.

article

31.5.2024

Cannes Hospital data breach, the impact of AI and NIS2 evolution: the Cyberday product and news round-up 5/2024 🛡️

May's Product and News Update presents the new monthly ISMS reports as well as the Metrics page. Other topics include Cyberday's new framework DORA and recent news around the world.

article

17.5.2024

6 ways to assess security work effectiveness

Evaluating the effectiveness of your cybersecurity involves examining the adequacy of your existing security measures. This process helps you identify your current security status and determine the necessary actions to enhance and fortify.

article

3.5.2024

System acquisition and development in NIS2: Suggested best practices

Get tips on securely acquiring and developing systems with a focus on ISO 27001, helping meet NIS2 requirements. Post explains key aspects like secure coding, acquiring secure applications and testing or publishing changes in a controlled manner.

article

16.4.2024

Continuity management in NIS2: Benchmark measures for business continuity and backups with ISO 27001

This post offers insight on complying with NIS2's continuity and backup requirements using ISO 27001's best practices. It guides you through continuity planning, backup processes, challenges, and achieving compliance effectively.

article

12.4.2024

HR security in NIS2: Best practices for compliance

Discover how the crucial role of HR in information security not only shapes the corporate security culture, but also steers the organization towards ISO 27001 and NIS2 compliance, ensuring secure handling of information assets and much more.

article

5.4.2024

Access control & MFA in NIS2: Build a solid foundation with ISO 27001 controls

What are the requirements for access control and MFA in NIS2 and ISO 27001 and how can they be implemented successfully? Learn more about the controls, requirements, best practices and how to overcome potential challenges in this blog post.

article

4.4.2024

Popular YouTube Channel Caught Distributing Malicious Tor Browser Installer

HK based popular YouTube channel used as a means for distributing malicious Tor-version. Browser's own website is blocked in China. ⚠️ #Malware campaigns using hacked channels and video description links are getting more and more popular.

Go to article at
7.10.2022

8 strange ways employees can (accidently) expose data

Article has interesting "warning examples" for sensitive data exposure, incl.: 📣 LinkedIn career updates 🖨️ discarded office printers 🖼️ social media pics 📧 emails sent to personal accounts 👓 even eyeglass reflections #cybersecurity

Go to article at
7.10.2022

Steam Gaming Phish Showcases Browser-in-Browser Threat

⚠️ Browser-in-the-browser is a novel #phishing tactic that should be on security radars. An authentic-looking fake browser window (e.g. a login form) is deployed to steal credentials and take over accounts. Steam users are now targeted >>

Go to article at
7.10.2022

Former Uber CSO convicted for covering up massive 2016 data theft

Former Uber CSO and DoJ #cybercrime prosecutor guilty of hiding Uber data theft. In 2016 crooks stole 57M customer records from Uber systems. Crooks were paid a ransom to cover up the incident, though law requires disclosing breaches.

Go to article at
7.10.2022

Lazarus hackers abuse Dell driver bug using new FudModule rootkit

☢️ North Korean hacking group spotted exploiting Dell driver CVE in its spear #phishing attacks. Attack disguises as a "job offer" to spy and steal data from carefully selected targets (e.g. aerospace experts, political journalists).

Go to article at
7.10.2022

Threat Trends: Vulnerabilities

📈 We have another record year in CVE disclosure, already 18000+ disclosed. Still most CVEs never get exploited. How should you prioritize #vulnerability's for treatment? Which are severe, which just get media attention? Article has tips ->

Go to article at
30.9.2022

IT admin admits sabotaging ex-employer’s network in bid for higher salary

⚠️ In a bid to get re-hired w/ a larger salary, ex IT employee admitted to sabotage. Mr Umetsu used his old (!) creds to edit DNS records to misdirect web and email traffic. Now he faces upto 10y in prison. #cybersecurity

Go to article at
30.9.2022

Capital One Phish Showcases Growing Bank-Brand Targeting Trend

Phishers watch the news. 📨 6000 #phishing emails going out daily in a scam targeting identities. Campaign exploits Capital One's new partnership with Authentify, tricking bank's customers into uploading images of ID cards.

Go to article at
30.9.2022

Critical WhatsApp Bugs Could Have Let Attackers Hack Devices Remotely

💊 WhatsApp patches two severe flaws that could lead to RCE attacks. One of them (CVE-2022-36934, CVSS score: 9.8) is an integer overflow #vulnerability that can be exploited through establishing a video call.

Go to article at
30.9.2022