IT Security Awareness News Roundup for August 2026
Added at 08/01/2026, last update at 08/23/2026
What matters most this month in IT security and awareness, and what should guide the attention of CIOs, CISOs, and CEOs? (regularly updated)
IT Security Awareness Failures
Fake Download Sites Exploit Trust in Familiar Links
Malwarebytes identified a network of deceptive websites impersonating popular games and Windows software, all ultimately pushing users to download a special installer. The sites are particularly deceptive because even when users hover over a download button, the browser can display a genuine destination such as Steam or VideoLAN, while JavaScript redirects the actual click elsewhere. (08/20/2026)
ClickFix Social Engineering Campaign targeting macOS
A novel cyberattack campaign targeting macOS users relies on fake CAPTCHAs and misleading browser error prompts to deceive victims. Employees are instructed to copy and execute a command directly inside their system terminal under the guise of solving a verification issue. Once executed, the malicious code silently installs AmnesiaStealer to harvest sensitive credentials, session cookies, and digital wallet keys. (08/18/2026)
Financial Sector Targeted in Sophisticated IT Helpdesk Vishing Wave
Attackers are directly contacting employees at financial institutions and law firms while posing as internal IT helpdesk personnel. Under the pretense of urgent technical maintenance, the fraudsters persuade victims to log into fake corporate authentication portals. Utilizing an Adversary-in-the-Middle (AiTM) setup, the adversaries successfully intercept both login credentials and multi-factor authentication (MFA) tokens to compromise enterprise accounts. (08/18/2026)
Study: AI-Powered Personalization Makes Phishing Significantly More Effective
A large-scale study involving more than 7,700 participants found that LLM-generated, personalized phishing e-mails nearly tripled click rates, increasing them from 3.9% for generic phishing to 10.0%. Attackers can automatically collect publicly available information about individuals and use it to create highly convincing, tailored phishing messages at a cost of only around $0.03 per e-mail.
The study shows that traditional warning signs such as poor language or generic content are becoming less reliable. (08/12/2026)
Exploiting Outlook Web Access Zero-Day: New 'Half-Click' Attack Deploys OWAReaper Malware
A Russia-aligned threat actor, is exploiting CVE-2026-42897, a cross-site scripting flaw in Outlook Web Access, in a "half-click" campaign where merely opening or previewing an e-mail triggers infection. The exploit deploys a novel browser-based implant called OWAReaper, which harvests credentials and OAuth tokens, grants itself persistent server-side mailbox access, and survives password resets and even full device re-imaging. Targeting government, telecom, finance, hospitality, and aerospace organizations across the US and Europe with intentionally bland lure e-mails. This may have exploited the vulnerability as a zero-day months before Microsoft's patch. (08/01/2026)
Secure Programming / Coding Failures
Stored XSS in 'directory-serve' Node.js Package
A Stored Cross-Site Scripting (XSS) vulnerability was identified in the 'directory-serve' Node.js package (up to version 1.3.7) due to unsanitized input in its 'lib/helper/html.js' component. The flaw allows remote attackers to upload or create files with maliciously crafted filenames containing HTML or JavaScript code. When users or administrators view the directory listings via the web UI, the injected scripts execute automatically in their browser context, enabling session hijacking and unauthorized data access. (08/18/2026)
XSS2Shell: WordPress XSS Vulnerability Can Lead to Remote Code Execution
Security researchers at Pwn.ai disclosed CVE-2026-64638, a pre-authentication XSS vulnerability affecting WordPress versions under active maintenance before 7.0.3. The flaw exploits differences between WordPress's HTML sanitizers and can ultimately allow an attacker to execute JavaScript in the WordPress origin without requiring an account. When combined with an authenticated administrator session, the attack chain can be escalated to full remote code execution on the server. WordPress released an emergency security update, version 7.0.3, on August 6, making prompt patching essential. (08/12/2026)
General IT Security Awareness Content
Security Awareness Training - for real and for ISO audits?
Are you on a platform or are you owning your awareness program? Make sure you can easily report the status of your employee awareness education:
How do you measure whether your security awareness training is actually working?
Completion rates? Click rates? Incident reports?


