IT Security Awareness News Roundup for August 2026

Added at 08/01/2026, last update at 08/31/2026

What matters most this month in IT security and awareness, and what should guide the attention of CIOs, CISOs, and CEOs?

IT Security Awareness Failures

When "Apple Support" Calls: AI-Powered Vishing Targets Stolen Devices

Cybercriminals are using AI-powered voice agents to impersonate Apple Support and trick victims into revealing their Apple Account credentials, device passcodes, and two-factor authentication codes. The attackers target people whose devices have been stolen, using convincing calls to bypass security protections such as Activation Lock. The campaign highlights how AI is making social engineering more convincing - and why employees should never share passwords, passcodes, or MFA codes during unsolicited support calls. (08/30/2026)

HissenIT Tip: Ensure basic understand of threats through Cybersecurity Awareness for Employees.
AI-Powered Vishing Targets Stolen Devices

Fake Download Sites Exploit Trust in Familiar Links

Malwarebytes identified a network of deceptive websites impersonating popular games and Windows software, all ultimately pushing users to download a special installer. The sites are particularly deceptive because even when users hover over a download button, the browser can display a genuine destination such as Steam or VideoLAN, while JavaScript redirects the actual click elsewhere. (08/20/2026)

HissenIT Tip: A legitimate-looking link or even a valid digital signature does not guarantee that you downloaded the software you intended! → Our course, IT Security Awareness for Employees, makes users aware of such evergreen and time-tested tricks!
Fake Download Sites Exploit Trust in Familiar Links

ClickFix Social Engineering Campaign targeting macOS

A novel cyberattack campaign targeting macOS users relies on fake CAPTCHAs and misleading browser error prompts to deceive victims. Employees are instructed to copy and execute a command directly inside their system terminal under the guise of solving a verification issue. Once executed, the malicious code silently installs AmnesiaStealer to harvest sensitive credentials, session cookies, and digital wallet keys. (08/18/2026)

HissenIT Tip: That is why basic Cybersecurity Awareness for Employees is so important - including managers!
ClickFix Social Engineering Campaign News

Financial Sector Targeted in Sophisticated IT Helpdesk Vishing Wave

Attackers are directly contacting employees at financial institutions and law firms while posing as internal IT helpdesk personnel. Under the pretense of urgent technical maintenance, the fraudsters persuade victims to log into fake corporate authentication portals. Utilizing an Adversary-in-the-Middle (AiTM) setup, the adversaries successfully intercept both login credentials and multi-factor authentication (MFA) tokens to compromise enterprise accounts. (08/18/2026)

General Human Risk Management Tip: Allow for IT Security Awareness Training.
Financial Sector Targeted News

Study: AI-Powered Personalization Makes Phishing Significantly More Effective

A large-scale study involving more than 7,700 participants found that LLM-generated, personalized phishing e-mails nearly tripled click rates, increasing them from 3.9% for generic phishing to 10.0%. Attackers can automatically collect publicly available information about individuals and use it to create highly convincing, tailored phishing messages at a cost of only around $0.03 per e-mail.

The study shows that traditional warning signs such as poor language or generic content are becoming less reliable. (08/12/2026)

For security awareness, organizations should train employees to recognize personalized social-engineering attempts, verify unexpected requests independently, and be mindful of how much personal information is publicly available: IT Security Awareness Training for Employees.
Security Awareness - Learn how Hackers think

Exploiting Outlook Web Access Zero-Day: New 'Half-Click' Attack Deploys OWAReaper Malware

A Russia-aligned threat actor, is exploiting CVE-2026-42897, a cross-site scripting flaw in Outlook Web Access, in a "half-click" campaign where merely opening or previewing an e-mail triggers infection. The exploit deploys a novel browser-based implant called OWAReaper, which harvests credentials and OAuth tokens, grants itself persistent server-side mailbox access, and survives password resets and even full device re-imaging. Targeting government, telecom, finance, hospitality, and aerospace organizations across the US and Europe with intentionally bland lure e-mails. This may have exploited the vulnerability as a zero-day months before Microsoft's patch. (08/01/2026)

Teach e-mail security to your team, why disabling the Outlook reading/preview pane might be important: IT Security Awareness Training for Employees.
Security Awareness - Outlook Zeroday vs E-Mail Security

Secure Programming / Coding Failures

How do you train your technical project managers or developers?

Whether you develop in-house or work with external development partners, custom software comes with security responsibilities. Build security into your development process from day one. Train developers in OWASP, secure coding and common application security risks. Equip TPMs and Project Managers to recognize security risks throughout the project lifecycle. Security is not just an IT responsibility - it is a team responsibility:

Secure Code Training - SQL Injection Mitigation Poster

Stored XSS in 'directory-serve' Node.js Package

A Stored Cross-Site Scripting (XSS) vulnerability was identified in the 'directory-serve' Node.js package (up to version 1.3.7) due to unsanitized input in its 'lib/helper/html.js' component. The flaw allows remote attackers to upload or create files with maliciously crafted filenames containing HTML or JavaScript code. When users or administrators view the directory listings via the web UI, the injected scripts execute automatically in their browser context, enabling session hijacking and unauthorized data access. (08/18/2026)

Cross-Site Scripting mitigation: Teach your TPMs and developers - Secure Programming of Web Applications for Developers and TPMs.
Stored XSS in 'directory-serve'

XSS2Shell: WordPress XSS Vulnerability Can Lead to Remote Code Execution

Security researchers at Pwn.ai disclosed CVE-2026-64638, a pre-authentication XSS vulnerability affecting WordPress versions under active maintenance before 7.0.3. The flaw exploits differences between WordPress's HTML sanitizers and can ultimately allow an attacker to execute JavaScript in the WordPress origin without requiring an account. When combined with an authenticated administrator session, the attack chain can be escalated to full remote code execution on the server. WordPress released an emergency security update, version 7.0.3, on August 6, making prompt patching essential. (08/12/2026)

XSS is a well-known, well documented, old coding error: Teach your TPMs and developers - Secure Programming of Web Applications for Developers and TPMs.
WordPress XSS Vulnerability

General IT Security Awareness Content

Security Awareness Training - for real and for ISO audits?

Are you on a platform or are you owning your awareness program? Make sure you can easily report the status of your employee awareness education:
Security Awareness Training Reporting for ISO 27001 + 27002

How do you measure whether your security awareness training is actually working? Completion rates? Click rates? Incident reports?
Security Awareness Training vs Driver Training

Importance of Backups!

Do you backup your important files? Are you sure, have you ever simulated a full restore? What about your organizations' servers? How (fast) do you recover from an IT disaster?
Security Awareness and Importance of Backups

A quick update from us

Cybersecurity Awareness Training Costs

Compare LMS-based Awareness training and onsite training costs: Comparing Cybersecurity Training Costs 2026

Security Awareness: Internet Hops vs Encryption

Throwback: 8 years ago, we shared this post on an issue that is still highly relevant today and always will be: Security Awareness: Internet Hops vs Encryption