Weekly #cybersecurity digest to your inbox

Subscribe for our weekly digest and get each Friday the most important cyber security news, list of upcoming free webinars and a summary of Cyberday development to your inbox.
Thanks! See you in your inbox on Fridays. :)
Unfortunately something went wrong. You can contact us at team@cyberdayai.

Meet Borat RAT, a New Unique Triple Threat

RAT #malware typically helps attacker gain control of a system, permitting access to network resources, files, and control mouse and keyboard. ☣️ Borat RAT goes beyond - deploying ransomware and DDoS attacks. Learn more from article >>

Go to article at
26.8.2022

Over 80,000 exploitable Hikvision cameras exposed online

Researchers discovered 80,000 Hikvision cameras w/ command injection #vulnerability - easily exploitable by sending specially crafted messages to server. ⚠️ Patch available for months, but thousands of organizations have not applied it.

Go to article at
26.8.2022

How a spoofed email passed the SPF check and landed in my inbox

📧 SPF lets you publish DNS records to define IPs allowed to use the domain for sending email. Article explains this must-have safeguard + examples where careless SPF records allowed bad actors to impersonate a corporation. #phishing

Go to article at
19.8.2022

Exploit out for critical Realtek flaw affecting many networking devices

⚠️ Exploit code released, zero-click #vulnerability (CVSS 9.8/10) affecting millions of devices with Realtek’s RTL819x SoC. Attacker can compromise e.g. routers from many brands. Patch available - check if your equipment is vulnerable.

Go to article at
19.8.2022

RubyGems now requires multi-factor auth for top package maintainers

Software package registry RubyGems requires top admins to secure accounts w/ MFA. Registries like PyPI and npm are doing the same. ⚠️ This relates to growing trend, where criminals steal accounts to publish rogue software. #cybersecurity

Go to article at
19.8.2022

U.K. Water Supplier Hit With Clop Ransomware Attack

⚠️ U.K. water supplier hit by Clop #ransomware. Attack didn't stop water supply. As ransom wasn't paid, breached data (incl. passports, data system screenshots) was published. Trend continues: critical infra a top target for cybercrime.

Go to article at
19.8.2022

Ransomware, email compromise are top security threats, but deepfakes increase

#Cybersecurity threat reports (2021-2022) from VMware and Palo Alto Unit 42: ☢️ Most common threats: Ransomware, business email compromise (BEC) 📈 Increasing rapidly: Deepfakes, zero-day vulnerability exploits, API hacks

Go to article at
12.8.2022

The Security Pros and Cons of Using Email Aliases

📧 Some users tame their inbox with +app email aliases. Using these can make you the first to know about a breach or leak, if u start receiving mail to an app's alias! Downside is the format might not work on all services. #cybersecurity

Go to article at
12.8.2022

10 Credential Stealing Python Libraries Found on PyPI Repository

⚠️ Growing #cybersecurity threat - bad actors publish rogue software on popular public repositories. Now 10 modules removed from Python Package Index (PyPI) that harvest critical data (e.g. passwords, API tokens). Details in article >>

Go to article at
12.8.2022