IT Security Awareness News Roundup for September 2026
Added at 09/01/2026, last update at 09/22/2026
What matters most this month in IT security and awareness, and what should guide the attention of CIOs, CISOs, and CEOs? (regularly updated)
Secure Programming / Coding Failures
Harvard, Oxford, DuckDuckGo Hacked: One Coding Mistake Compromised 700 Websites
A mass exploitation campaign targeting CVE-2026-26980, a critical blind SQL injection flaw in Ghost CMS's Content API, has compromised over 700 websites - including the blogs of Harvard University, Oxford University, and DuckDuckGo - by allowing unauthenticated attackers to extract admin API keys from the database. The root cause is a textbook secure coding failure: user-supplied values were concatenated directly into raw SQL statements with no sanitization or parameterized query binding. (09/22/2026)
Cross-Site Scripting (XSS) still exists in professional Applications!
- XSS2Shell WordPress XSS Vulnerability (08/2026)
- MS Exchange Server XSS Vulnerability (06/2026)
- Stored Cross-Site Scripting (XSS) Vulnerabilities in VMware Products (06/2026)
- ...
What about your in-house development? Security in custom-made software – do you rely solely on frameworks? Is Secure Programming background knowledge important to your team and project managers:
General IT Security Awareness Content
IT Security Awareness Failures
Phishers Turn Google's Own Infrastructure Into a Trust Proxy
Researchers uncovered an active, targeted phishing campaign that routes victims through a deliberate chain of six legitimate Google services - including Meet, DoubleClick, Custom Search, Image Search, Tag Manager, and Analytics - before landing them on a credential-harvesting page or silently installing the ScreenConnect remote access tool. By the time a defender inspects the sending domain, the embedded link, or the intermediate hops, everything still looks clean, because security gateways see only trusted Google domains at every step. The landing page dynamically builds a fake corporate login screen using the victim's own e-mail address, pulls a live screenshot of their company website, and exfiltrates stolen credentials to a Telegram bot within seconds. (09/16/2026)
Microsoft/Malwarebytes/HackerNews: Fake CAPTCHA Turns Users into Their Own Attackers
Cybercriminals are using compromised websites and fake Cloudflare CAPTCHA prompts to trick users into copying and executing malicious PowerShell commands on their own Windows systems. The TerminalFix campaign then deploys a multi-stage payload that performs Active Directory reconnaissance and establishes a reverse tunnel, potentially giving attackers access to other systems inside the corporate network. (09/03/2026)
A quick update from us
New free Employee Phishing Simulator QuickCheck as SCORM module
In this free E-Mail Phishing Simulator, Employees shall review each message, identify whether it is legitimate or phishing, and use the clues to sharpen their judgment. LMS reporting gives managers valuable insights into how their employees respond to common and sometimes deceptive phishing emails, helping identify potential gaps in security awareness and areas...
