Weekly #cybersecurity digest to your inbox

Subscribe for our weekly digest and get each Friday the most important cyber security news, list of upcoming free webinars and a summary of Cyberday development to your inbox.
Thanks! See you in your inbox on Fridays. :)
Unfortunately something went wrong. You can contact us at team@cyberdayai.

Build your NIS2 measures for Business Continuity and Backups with ISO 27001

This post offers insight on complying with NIS2's continuity and backup requirements using ISO 27001's best practices. It guides you through continuity planning, backup processes, challenges, and achieving compliance effectively.

article

12.4.2024

Understanding HR Security Basics for ISO 27001 & NIS2 Compliance

Discover how the crucial role of HR in information security not only shapes the corporate security culture, but also steers the organization towards ISO 27001 and NIS2 compliance, ensuring secure handling of information assets and much more.

article

5.4.2024

Access Control & MFA (NIS2 21.2): Build A Solid Foundation with ISO 27001 Best Practices

What are the requirements for access control and MFA in NIS2 and ISO 27001 and how can they be implemented successfully? Learn more about the controls, requirements, best practices and how to overcome potential challenges in this blog post.

article

4.4.2024

Potential Struggles IT Companies might Encounter with Incident Identification and Reporting Today

The complexities of incident identification and reporting in IT, touching on coordination problems, tool inadequacies, and process deficiencies. It explores modern challenges like cyber threats and alert fatigue, as well as the cognitive gap.

article

28.3.2024

Information Security Risk Management: A Step-by-step Guide to a Clear Process

This post offers a comprehensive guide on managing information security risks, from pre-steps like asset identification to evaluation, treatment and monitoring. A crucial aspect given the surge of cyber vulnerabilities amid increasing tech advances.

article

21.3.2024

Ransomware, AI Act 101, NIST CSF 2.0: Cyberday product and news round up 3/2024 🛡️

In the March digest, development themes include new frameworks, risk management improvements and a new visual view for documentation cards. The news features Information Security Trailblazers, data breaches and AI Act 101.

article

21.3.2024

Empowering Employees: The Keystone in Incident Detection and Reporting

Employees are vital for detecting and reporting cyber threats and bolstering security. Proper training fosters a resilient culture, ensuring timely responses and safeguarding against breaches.

article

15.3.2024

NIS2 Incident Reporting Requirements and related ISO 27001 Best Practices

This post outlines NIS2 incident reporting and further describes ISO 27001 best practices, and their application in crafting successful incident reporting processes for your organization.

article

8.3.2024

Turning on stealth mode: 5 simple strategies for staying under the radar online

Want to be safe and private online? These can help you: 📨 Disposable email addresses 📱 Cheap prepaid SIMs 💳 Single-use, virtual bank cards More tips in the article >> #privacy

Go to article at
12.5.2023

Hackers Are Using ChatGPT-Themed Lures to Spread Sophisticated Malware on Meta

⚠️ Meta: Hackers exploiting interest in AI chatbots to trick people into installing #malware and take over accounts This is a common trend, bad actors exploiting high-engagement topics for their benefit. Details >>

Go to article at
12.5.2023

San Bernardino County Sheriff’s Department paid a $1.1M ransom

👮 #Ransomware forced police to shut down its main systems (e.g. email, in-car computers and law enforcement DBs). 💰 Despite authorities always saying "do not pay", they chose to pay 1.1M$ ransom to recover the encrypted systems and data.

Go to article at
12.5.2023

Security Risks of AI

📃 Stanford and Georgetown published a report with 11 clear recommendations on the #cybersecurity risks of AI. "The understanding of how to secure AI systems lags far behind their widespread adoption." Link to full version >>

Go to article at
28.4.2023

Fake Flipper Zero sellers are after your money

Flipper Zero is a portable multi-tool for pentesters and hardware geeks - often out of stock due to its popularity. ⚠️ Bad actors are noticing this and creating bogus sites claiming to sell Flipper Zero. Case example >> #cybersecurity

Go to article at
28.4.2023

How we fought bad apps and bad actors in 2022

Google's 2022 #cybersecurity numbers - 1.43M policy-violating apps blocked from Google Play - 173K bad accounts banned - $2000M in fraudulent transactions prevented - 500K apps stopped from unnecessarily accessing sensitive permissions

Go to article at
28.4.2023

Google leaking 2FA secrets – researchers advise against new “account sync” feature for now

G Authenticator launched an “account sync” so users can backup 2FA data to cloud and later restore to a new device. ⛔ Researchers though have found some #cybersecurity worries in the feature (especially with encryption). Details >>

Go to article at
28.4.2023

Microsoft: Windows 10 22H2 is the final version of Windows 10

⚠️ The current version (22H2) will be the final version of Windows 10 - work versions supported until May 2025. MS encourages transitioning to Windows 11. 22H2 won't get any Windows 10 feature updates, but #cybersecurity updates continue.

Go to article at
28.4.2023

Popular Fitness Apps Leak Location Data Even When Users Set Privacy Zones

🚩 Students discovered: when a user starts fitness activity from home, an attacker can use app's API metadata to pinpoint their home location, even if they've set up an "endpoint privacy zone" (EPZ) for that area. #privacy

Go to article at
21.4.2023