Weekly #cybersecurity digest to your inbox

Subscribe for our weekly digest and get each Friday the most important cyber security news, list of upcoming free webinars and a summary of Cyberday development to your inbox.
Thanks! See you in your inbox on Fridays. :)
Unfortunately something went wrong. You can contact us at team@cyberdayai.

Best Practices and Common Challenges of ISMS Implementation

No matter if you are an IT professional, a cyber security expert, or in a management role, this post will provide you with valuable insights into the best practices for a successful ISMS implementation and how to navigate common challenges.

article

14.2.2024

ISMS Guide: Top 10 ISMS Implementation Benefits

What is an ISMS and why does your organization benefit from its implementation in the long run? This blog post will give you a short guide about all the basics you need to know about an ISMS and its top 10 benefits.

article

9.2.2024

Intro to Incident Management: Definitions, benefits and best practices

Learn how an incident management process improves communication, documentation, and continuous improvement for IT organisations.

article

6.2.2024

5 Efficient Ways for Involving People in Your Security Work

Discover how teamwork, education, reporting, and risk assessments empower ISMS. Explore 5 ways to engage people for a secure, collaborative digital space.

article

1.2.2024

AI Act, cyber risks and breaches: Cyberday product and news roundup 1/2024 🛡️

In January's summary, development themes include reporting updates, improved report sharing and upgraded Academy. On the news side talk about AI Act, cyber risks and breaches.

article

30.1.2024

10 most important tasks for a CISO and tips for being successful

This article provides an insight into the main responsibilities of a CISO, from implementing security principles to fostering collaboration. It also presents valuable tips for successful performance, emphasizing constant learning as a key ingredient.

article

24.1.2024

The Human Firewall Effect: Tips for Securing Your Organization from Within

This blog post emphasizes the critical role employees play in bolstering an organization's cyber security. It discusses developing clear guidelines, employee training, and monitoring progress to create a strong human firewall.

article

19.1.2024

Encryption, RaaS, supply chain attacks: Monthly Cyberday product and news roundup 12/2023 🛡️

In December's summary, development themes include UI updates and information security statements. On the news side talk about encryption, RaaS and supply chain attacks.

article

15.12.2023

Malware and malicious insiders account for most government cybercrime costs

They have also resulted in a large growth in cybersecurity expenditure across the Australian government and other organisations.While this trend is not unique to this nation and cyber-based acts on government agencies across the globe are on the rise, Australia’s reliance on technology for the provision of government services means the effects of cybercrime on citizens have the potential to be incredibly far reaching.A recent study by Accenture and the Ponemon Institute found that cybercrime is increasing in numbers and in scope. The study, which surveyed 2647 security and IT executives across 355 global organisations, found that then average number of security breaches per government agency was 190 in 2018, well ahead of the 14 experienced, on average, by private sector companies.The study also found that for public sector organisations, the average cost of security breach rose 17 per cent in 2018 to an average of US$10.28 million per incident, up from US$9.38 million in 2017.

Go to article at
15.5.2020
Insider Attacks

Quick look at a couple of current online scam campaigns, (Tue, Feb 25th)

Since I was exposed to three different online scam campaigns in the last three weeks, without having to go out and search for them, I thought that today might be a good time to take a look at how some of the current online scams work.

Go to article at
15.5.2020
Phishing

Attackers Deliver Malware via Fake Website Certificate Errors

Cybercriminals are distributing malware using fake security certificate update requests displayed on previously compromised websites, attempting to infect potential victims with backdoors and Trojans using a malicious installer. [...]

Go to article at
15.5.2020
Malware

University of Utah Health notifies patients of phishing attacks that began in January

The University of Utah Health is notifying patients whose protected health information was in some employees’ email...

Go to article at
15.5.2020
Phishing

Pabbly Email Marketing Exposes 51.2 Million Records Online

Jeremiah Fowler reports: Email marketing is big business and many companies rely on emails to keep in contact with their...

Go to article at
15.5.2020
Illegal Personal Data Processing

Beware of Amazon Prime Support Scams in Google Search Ads

A malicious ad campaign is underway in Google Search results that lead users to fake Amazon support sites and tech support scams. A security researcher reached out to BleepingComputer today about search keywords such as "amazon prime" and "amazon prime customer support" that leads to ads pretending to be Amazon Prime support. For example, in the image below simply searching for "amazon prime" resulted in a fake and shady-looking support ad hosted on sites.google.com. In addition to Amazon support scams, other ads discovered by the researcher were for the search keywords "my account" and "login" that lead to a variety of different tech support scams like the one below. Tech Support Scam ads in Google Search Clicking on these ads lead to tech support scams located on sites such as  sites.google.com, Azure, and other providers. Tech Support Scam via Google Ads Now many of you may look at these ads and wonder how anyone could fall for them.

Go to article at
15.5.2020
Phishing

Hackers Are Breaking Directly Into Telecom Companies to Take Over Customer Phone Numbers

Hackers are now getting telecom employees to run software that lets the hackers directly reach into the internal systems of U.S. telecom companies to take over customer cell phone numbers, Motherboard has learned. Previously, these hackers have bribed telecom employees to perform SIM swaps or tricked workers to do so by impersonating legitimate customers over the phone or in person. But instead of targeting consumers, they're tricking telecom employees to install or activate RDP software, and then remotely reaching into the company's systems to SIM swap individuals. Once RDP is enabled, "They RDP into the store or call center [computer] [...] and mess around on the employees' computers including using tools," said Nicholas Ceraolo, an independent security researcher who first flagged the issue to Motherboard. Certain employees inside telecom companies have access to tools with the capability to 'port' someone's phone number from one SIM to another.

Go to article at
15.5.2020
Malware

Why the Latest Marriott Breach Should Make Us "Stop and Think" About Security Behaviors

Marriott International has experienced their second data breach

Go to article at
15.5.2020
Illegal Personal Data Processing

Microsoft’s case study: Emotet took down an entire network in just 8 days

Microsoft shared details of the Emotet attack suffered by an organization named Fabrikam in the Microsoft’s DART Case Report 002, where Fabrikam is a fake name the IT giant gave the victim.

Go to article at
15.5.2020
Malware