IT Security Awareness News Roundup for August 2026

Added at 08/01/2026, last update at 08/23/2026

What matters most this month in IT security and awareness, and what should guide the attention of CIOs, CISOs, and CEOs? (regularly updated)

IT Security Awareness Failures

Fake Download Sites Exploit Trust in Familiar Links

Malwarebytes identified a network of deceptive websites impersonating popular games and Windows software, all ultimately pushing users to download a special installer. The sites are particularly deceptive because even when users hover over a download button, the browser can display a genuine destination such as Steam or VideoLAN, while JavaScript redirects the actual click elsewhere. (08/20/2026)

HissenIT Tip: A legitimate-looking link or even a valid digital signature does not guarantee that you downloaded the software you intended! → Our course, IT Security Awareness for Employees, makes users aware of such evergreen and time-tested tricks!
Fake Download Sites Exploit Trust in Familiar Links

ClickFix Social Engineering Campaign targeting macOS

A novel cyberattack campaign targeting macOS users relies on fake CAPTCHAs and misleading browser error prompts to deceive victims. Employees are instructed to copy and execute a command directly inside their system terminal under the guise of solving a verification issue. Once executed, the malicious code silently installs AmnesiaStealer to harvest sensitive credentials, session cookies, and digital wallet keys. (08/18/2026)

HissenIT Tip: That is why basic Cybersecurity Awareness for Employees is so important - including managers!
ClickFix Social Engineering Campaign News

Financial Sector Targeted in Sophisticated IT Helpdesk Vishing Wave

Attackers are directly contacting employees at financial institutions and law firms while posing as internal IT helpdesk personnel. Under the pretense of urgent technical maintenance, the fraudsters persuade victims to log into fake corporate authentication portals. Utilizing an Adversary-in-the-Middle (AiTM) setup, the adversaries successfully intercept both login credentials and multi-factor authentication (MFA) tokens to compromise enterprise accounts. (08/18/2026)

General Human Risk Management Tip: Allow for IT Security Awareness Training.
Financial Sector Targeted News

Study: AI-Powered Personalization Makes Phishing Significantly More Effective

A large-scale study involving more than 7,700 participants found that LLM-generated, personalized phishing e-mails nearly tripled click rates, increasing them from 3.9% for generic phishing to 10.0%. Attackers can automatically collect publicly available information about individuals and use it to create highly convincing, tailored phishing messages at a cost of only around $0.03 per e-mail.

The study shows that traditional warning signs such as poor language or generic content are becoming less reliable. (08/12/2026)

For security awareness, organizations should train employees to recognize personalized social-engineering attempts, verify unexpected requests independently, and be mindful of how much personal information is publicly available: IT Security Awareness Training for Employees.
Security Awareness - Learn how Hackers think

Exploiting Outlook Web Access Zero-Day: New 'Half-Click' Attack Deploys OWAReaper Malware

A Russia-aligned threat actor, is exploiting CVE-2026-42897, a cross-site scripting flaw in Outlook Web Access, in a "half-click" campaign where merely opening or previewing an e-mail triggers infection. The exploit deploys a novel browser-based implant called OWAReaper, which harvests credentials and OAuth tokens, grants itself persistent server-side mailbox access, and survives password resets and even full device re-imaging. Targeting government, telecom, finance, hospitality, and aerospace organizations across the US and Europe with intentionally bland lure e-mails. This may have exploited the vulnerability as a zero-day months before Microsoft's patch. (08/01/2026)

Teach e-mail security to your team, why disabling the Outlook reading/preview pane might be important: IT Security Awareness Training for Employees.
Security Awareness - Outlook Zeroday vs E-Mail Security

Secure Programming / Coding Failures

Stored XSS in 'directory-serve' Node.js Package

A Stored Cross-Site Scripting (XSS) vulnerability was identified in the 'directory-serve' Node.js package (up to version 1.3.7) due to unsanitized input in its 'lib/helper/html.js' component. The flaw allows remote attackers to upload or create files with maliciously crafted filenames containing HTML or JavaScript code. When users or administrators view the directory listings via the web UI, the injected scripts execute automatically in their browser context, enabling session hijacking and unauthorized data access. (08/18/2026)

Cross-Site Scripting mitigation: Teach your TPMs and developers - Secure Programming of Web Applications for Developers and TPMs.
Stored XSS in 'directory-serve'

XSS2Shell: WordPress XSS Vulnerability Can Lead to Remote Code Execution

Security researchers at Pwn.ai disclosed CVE-2026-64638, a pre-authentication XSS vulnerability affecting WordPress versions under active maintenance before 7.0.3. The flaw exploits differences between WordPress's HTML sanitizers and can ultimately allow an attacker to execute JavaScript in the WordPress origin without requiring an account. When combined with an authenticated administrator session, the attack chain can be escalated to full remote code execution on the server. WordPress released an emergency security update, version 7.0.3, on August 6, making prompt patching essential. (08/12/2026)

XSS is a well-known, well documented, old coding error: Teach your TPMs and developers - Secure Programming of Web Applications for Developers and TPMs.
WordPress XSS Vulnerability

General IT Security Awareness Content

Security Awareness Training - for real and for ISO audits?

Are you on a platform or are you owning your awareness program? Make sure you can easily report the status of your employee awareness education:
Security Awareness Training Reporting for ISO 27001 + 27002

How do you measure whether your security awareness training is actually working? Completion rates? Click rates? Incident reports?
Security Awareness Training vs Driver Training

Importance of Backups!

Do you backup your important files? Are you sure, have you ever simulated a full restore? What about your organizations' servers? How (fast) do you recover from an IT disaster?
Security Awareness and Importance of Backups

A quick update from us

Cybersecurity Awareness Training Costs

Compare LMS-based Awareness training and onsite training costs: Comparing Cybersecurity Training Costs 2026

Security Awareness: Internet Hops vs Encryption

Throwback: 8 years ago, we shared this post on an issue that is still highly relevant today and always will be: Security Awareness: Internet Hops vs Encryption