Weekly #cybersecurity digest to your inbox

Subscribe for our weekly digest and get each Friday the most important cyber security news, list of upcoming free webinars and a summary of Cyberday development to your inbox.
Thanks! See you in your inbox on Fridays. :)
Unfortunately something went wrong. You can contact us at team@cyberdayai.

Navigating the Cybersecurity Maze: Master NIS2 with the help of ISO 27001

Learn how to master NIS2 with ISO 27001 and grab our free NIS2 e-book! This blog post was originally written for the Cyber Security Nordic 2024 event where Cyderday is presented as Strategic partner.

article

3.10.2024

Corporate Security Alert: Identifying Dangerous Apps on Employee Phones

This article uncovers hidden security risks of popular apps on work devices, covering social media, messaging, cloud storage, gaming, utility, health, VPN, and shopping apps, with recommendations to safeguard corporate data.

article

20.9.2024

NIS2 national legistation, ransomware and a new development forum: Cyberday product and news round-up 9/2024 🛡️

This is the September news and product review from Cyberday. Read news about ransomware, new phishing techniques and local NIS2-legistations.

article

20.9.2024

IT and OT Cyber Security: Different Environments, Different Priorities

This blog post outlines the key differences between IT and OT cyber security, focusing on their distinct areas, objectives, environments, threat landscapes, and compliance requirements.

article

4.9.2024

Cyber Security in Supply Chain Risk Management

Businesses should prioritize supply chain security by adopting best cyber security practices, fostering resilience, and promoting collaboration to protect against evolving cyber threats. Learn more about this topic in this blog post.

article

22.8.2024

Spreadsheet vs. ISMS tool - top 10 reasons why a tool is better than the traditional way

Discover the top 10 reasons why agile tools outperform traditional spreadsheets in managing cyber security compliance, from centralized management to continuous improvement.

article

22.8.2024

ISMS Essentials: Mastering a Data System Inventory for Your Organization

This post provides essential insights for maintaining a data system inventory within your organization's ISMS, detailing key processes, asset types, and tackling common challenges.

article

15.8.2024

Incident Detection: Building, Nurturing, and Continuously Improving a Proactive Environment

Shift from reactive to proactive incident detection. Use advanced tools, continuous learning, and customised strategies to anticipate and prevent issues. Focus on constant improvement and innovation to boost security and resilience.

article

15.8.2024

Tietosuojavaltuutetun toimisto tehostaa ETA-maiden ulkopuolelle tehtävien henkilötietojen siirtojen valvontaa

As guidance is fined down, Finnish DPA is increasing control of data transfers. ⚠️ Before transferring data outside the EEA, you must be aware of the basis for the transfer and ensure an adequate level of #dataprotection is quaranteed.

Go to article at
24.8.2021

How attackers could exploit breached T-Mobile user data

T-Mobile suffered a data breach that affected about 50 million people. Danger to victims includes: ⚠️ SMS phishing (impersonating the operator) and malware ⚠️ SIM swapping attacks Read the article for protection tips #cybersecurity

Go to article at
24.8.2021

Education giant Pearson fined $1M for downplaying data breach

2018 data breach led to the compromise of 13 000 student / admin login credentials. The breach was disclosed only after media inquiries and its effects were downplated. This resulted in now decided $1M additional fine. #cybersecurity

Go to article at
19.8.2021

XSS Bug in SEOPress WordPress Plugin Allows Full Site Takeover

Cross-site scripting (XSS) vulnerability in a popular WordPress plugin allows attackers to inject arbitrary web scripts into sites, as one API endpoint was insecurely implemented. Plugin is installed on 100,000 websites. #cybersecurity

Go to article at
19.8.2021

Phishing Costs Nearly Quadrupled Over 6 Years

“Until organizations deploy a people-centric approach to cybersecurity that includes security awareness training and integrated threat protection to stop and remediate threats, phishing attacks will continue.” #cybersecurity

Go to article at
17.8.2021

65 vendors affected by severe vulnerabilities in Realtek chips

Researchers found a vulnerability on Realtek chips, informed them and Realtek promptly provided an appropriate patch. To prevent risky devices, manufacturers need to check their hardware and provide patches to their users. #cybersecurity

Go to article at
17.8.2021

Most organizations experienced at least one ransomware attack, multiple attacks very common

Worrying #ransomware statistics: ⚠️ 37% of organisations experienced a successful attack in previous 12 months ⚠️ only 13% of attacked organisations reported NOT paying the ransom 📈 avg. ransom 250k$ #cybersecurity

Go to article at
17.8.2021

How hackers can use message mirroring apps to see all your SMS texts — and bypass 2FA security

Major vendors (e.g. Microsoft) have urged users to abandon 2FA solutions that leverage one-time codes sent via SMS. 2FA w/ SMS is open to multiple attacks, like SIM swapping, request smuggling and notification mirroring. #cybersecurity

Go to article at
17.8.2021

Microsoft Warns of Another Unpatched Windows Print Spooler RCE Vulnerability

Only a day after releasing Patch Tuesday updates, Microsoft acknowledged that it's working to remediate yet another remote code execution vulnerability in the Windows Print Spooler component. #PrintNightmare continues. #cybersecurity

Go to article at
12.8.2021