Weekly #cybersecurity digest to your inbox

Subscribe for our weekly digest and get each Friday the most important cyber security news, list of upcoming free webinars and a summary of Cyberday development to your inbox.
Thanks! See you in your inbox on Fridays. :)
Unfortunately something went wrong. You can contact us at team@cyberdayai.

NIS2: Who's in the scope and what security measures are required? (part 2/3)

In this post you'll learn about what industries are affected by NIS2, security requirements the directive sets, and the available enforcement methods if an organization is not compliant.

article

23.8.2023

NIS2: Working towards compliance with Cyberday (3/3)

✈️ You want to lift your cyber security management to a new level & get NIS2 compliant with a smart tool like Cyberday? In this post you'll learn how your organization can achieve NIS2 compliance in a smart way by building an own agile ISMS.

article

23.8.2023

NIS2: Get familiar with the EU's new cyber security directive (part 1/3)

Learn about the background and reasons behind the EU's new Network and Information Security 2 (NIS2) Directive. How does it affect your company and how should you react to be compliant?

article

1.8.2023

SOC 2: Working towards compliance (1/2)

With the help of SOC 2, organisations can provide proof of effectively implemented controls and the use of best practices to protect the data to their customers and stakeholders, which may help to build trust.

article

31.7.2023

Personnel information security training and guidelines in Cyberday

Most data breaches start with human error. Still, investments in technical information security are often made more eagerly. We tell you why staff information security training and guidelines are important and how to implement then efficiently.

article

13.6.2023

Information security risk management in Cyberday: Identifying risks, evaluation, treatment and closure

Every cyber security framework highlights risk management in its own way. We summarize in this post, what's essential in information security risk management and what kind of an approach Cyberday offers for it.

article

13.6.2023

Become a Cyberday partner: Features, benefits and best practices

A good and efficient tool such as Cyberday is a great way to work on the organization's cyber secuirty. However, for some organizations that is not enough and the expertise and support of a consultant is needed. Our partner program offers both!

article

6.6.2023

Cyberday Community has been launched!

We just launched a new Community section inside Cyberday. Our goal is to make collaboration with your peers and with us easier and thus help you improve your information security even further!

article

24.3.2023

Employees Are Entering Sensitive Business Data Into ChatGPT

Content input to ChatGPT is used by OpenAI to train the AI. ⛔ Data shows 4.9% of users have at least once pasted company data into ChatGPT. Firms like JP Morgan and Verizon have blocked access to ChatGPT over such concerns. #privacy

Go to article at
17.3.2023

Business on the dark web: deals and regulatory mechanisms

🦹 Hundreds of deals get made on the dark web daily: selling data, dealing illegal services, hiring crooks - with big money on the table.  Article gives insight into dark web transactions and escrow services >> #cybersecurity

Go to article at
17.3.2023

Microsoft Warns of Large-Scale Use of Phishing Kits to Send Millions of Emails Daily

⚠️ New AiTM #phishing kit (sold for 300$/mo) is growing fast in cybercrime world. AiTM phishing involves intercepting password and session cookies by deploying a proxy server between the user and the website - and can thus go around MFA.

Go to article at
17.3.2023

Exfiltration malware takes center stage in cybersecurity concerns

📈 Spike in #malware designed to exfiltrate data directly from devices and browsers. Infostealers let cybercriminals to work at scale - stealing credentials, cookies, and auto-fill data to use in targeted attacks or sell on the darknet.

Go to article at
17.3.2023

LockBit Claims it Stole SpaceX Schematics From Parts Supplier, Threatens to Leak Them

⚠️ #Ransomware gang boasts breaking into Maximum Industries, SpaceX supplier, and stealing 3,000 "certified rocket part drawings". LockBit's other recent alleged victims include e.g. ION and Royal Mail.

Go to article at
17.3.2023

Fortinet warns of new critical unauthenticated RCE vulnerability

"Critical" buffer underflow #vulnerability (CVSS 9.3) impacting FortiOS and FortiProxy disclosed. Allows unauthenticated attacker to execute arbitrary code or perform DoS on vulnerable devices. Updates and workarounds in article >>

Go to article at
10.3.2023

Ransomware review: March 2023

Recent #ransomware numbers: ☢️ LockBit alone leaked data of 126 victim organizations on its leak site during February 2023 🏭 Services, logistics and tech top industries 🦹 Medusa a new active gang

Go to article at
10.3.2023

Fifth of Government Workers Don't Care if Employer is Hacked

Survey 800 public sector workers found "not my job” -attitude exposing governments to risk 👤 34% of workers recognize their actions impact organization’s security ⚠️ 21% said they don’t care if organization is hacked #cybersecurity

Go to article at
10.3.2023

GitHub begins 2FA rollout for code contributors

Developer accounts are popular targets for #phishing and account takeover. Protecting them is a critical step toward securing the software supply chain. 🔑 GitHub developers and admings now have 45 days to configure 2FA on their accounts.

Go to article at
10.3.2023