IT Security Awareness News Roundup for July 2026

Added at 07/01/2026, last update at 07/24/2026

What matters most in IT security and awareness, and what should guide the attention of CIOs, CISOs, and CEOs? (regularly updated)

IT Security Awareness Failures

Russian Hackers Combine Phishing With Zimbra Zero-Click Exploit

CISA warns that a Russian state-sponsored group is combining phishing emails with a patched zero-click vulnerability in Zimbra Collaboration servers. The campaign targets organizations to steal email data while increasing the effectiveness of phishing attacks. (07/24/2026)

The incident demonstrates that phishing can be significantly more dangerous when combined with software vulnerabilities, reinforcing the need for timely patching and user awareness. → Basic Security Awareness Training.

The Trust Trap: How Phishers Cloaked Malware in a Fake LastPass Compliance Update

Cybercriminals launched a highly sophisticated phishing campaign this week using the lookalike domains lastpassnewsletter[.]com and lastpasscompliance[.]com to trick users into updating their security policies. Instead of a standard login page, the fraudulent site presented a fake DocuSign interface designed to push malicious downloads for Windows and macOS alongside a spoofed live-support chat. To bypass traditional spam filters, the attackers successfully routed their emails through legitimate Amazon SES and Google Cloud infrastructure before security teams intervened and blacklisted the domains. (07/16/2026)

General Human Risk Management Tip: Allow for IT Security Awareness Training.

Fake Job Offers Used to Steal Google Accounts

Cybercriminals are impersonating well-known global brands to lure marketing professionals with fake job opportunities and redirect them to fraudulent Google sign-in pages. The campaign uses sophisticated techniques, including browser-in-the-browser attacks and multiple redirects, to make phishing sites appear legitimate. (07/10/2026)

Awareness Training Takeaway: This incident highlights the importance of verifying unexpected offers and always confirming the authenticity of login pages before entering credentials in general - IT Security Awareness Training.

Advanced Phishing Campaigns Now Adapt to Victims' Devices Automatically

Security researchers at Cofense have identified a new wave of phishing campaigns that automatically tailor their attacks based on a victim's device, operating system, and browser information. After a user clicks a malicious link, attackers collect device details to deliver platform-specific malware or highly convincing fake login pages, significantly increasing the likelihood of a successful compromise. This demonstrates how phishing attacks are becoming more sophisticated and personalized, making them harder to detect. (07/04/2026)

Awareness Training Takeaway: In this case of "phishing", a single click may already lead to system compromise. Beyond fake login pages, attackers increasingly use device-aware techniques that can deliver malicious payloads after the user interacts with the link. Organizations should continue to emphasize user awareness, encourage employees to verify unexpected requests, and report suspicious emails or login pages immediately: IT Security Awareness Training for Employees.

Secure Programming / Coding Failures

Critical WordPress SQL Injection & REST API Vulnerabilities

Researchers disclosed two critical WordPress core vulnerabilities, including CVE-2026-60137 (SQL Injection), which can be chained with another flaw to achieve remote code execution. Exploitation began within hours after patches were released, highlighting how quickly attackers weaponize newly disclosed vulnerabilities. (07/24/2026)

We're repeating ourselves here: Oddly enough, SQL Injection remains a top threat! → Train your developers and TPMs with Secure Programming of Web Applications. Developers and technical teams should prioritize parameterized queries, secure input validation, and rapid patch management to reduce exposure!

Critical SQL Injection Vulnerability Discovered in Ubiquiti UniFi Talk

Ubiquiti disclosed a critical authenticated SQL injection vulnerability (CVE-2026-50747) affecting UniFi Talk as part of a broader set of security advisories. An authenticated attacker could exploit the flaw to escalate privileges, highlighting the risks of insufficient input validation in backend applications. Organizations should apply vendor patches immediately. (07/16/2026)

Even with decades of documentation, SQL Injection remains a top threat! → Train your developers and TPMs with Secure Programming of Web Applications

A quick update from us

Security Awareness Training for Your LMS - Thank you for the amazing feedback!

Our Security Awareness Courses have now been completed on Udemy alone by more than 30,000 learners in 165 countries. Our courses are also available in SCORM format for Enterprise Learning Management Systems - with no subscriptions and a pay once, own forever licensing model... (07/06/2026)

General IT Security Awareness Content

Awareness Microlearning for your Team

Do you check links before clicking? Do you use mouseover/hover events in your browser and mail client? But what do you do on your mobile device? Understand what HTTPS does - and does not(!) - mean:
Phishing vs HTTPS Security

Quishing Attacks Background:
IT Security Awareness - Quishing Info Comic

How is your team's security awareness? For real and for audits!?

Phishing simulations. Microlearning. SCORM modules. There are a lot of options out there. But what actually changes employee behavior?

IT Security Awareness - Think before you click

Continuous reminders, motivation, and bite-sized learning content are key to maintaining effective security awareness:

IT Security Awareness - The Seatbelt Ignorer Analogy