IT Security Awareness News Roundup for September 2026

Added at 09/01/2026, last update at 09/22/2026

What matters most this month in IT security and awareness, and what should guide the attention of CIOs, CISOs, and CEOs? (regularly updated)

Secure Programming / Coding Failures

Harvard, Oxford, DuckDuckGo Hacked: One Coding Mistake Compromised 700 Websites

A mass exploitation campaign targeting CVE-2026-26980, a critical blind SQL injection flaw in Ghost CMS's Content API, has compromised over 700 websites - including the blogs of Harvard University, Oxford University, and DuckDuckGo - by allowing unauthenticated attackers to extract admin API keys from the database. The root cause is a textbook secure coding failure: user-supplied values were concatenated directly into raw SQL statements with no sanitization or parameterized query binding. (09/22/2026)

Developer security awareness takeaway: Simple secure programming failures like SQL Code Injections still exists → teach secure programming to your managers and developers. Provide space and time for learning!
Secure Programming Failures - SQL Code Injection still exists

Cross-Site Scripting (XSS) still exists in professional Applications!

What about your in-house development? Security in custom-made software – do you rely solely on frameworks? Is Secure Programming background knowledge important to your team and project managers:

Secure Code Training - XSS Fact Sheet

General IT Security Awareness Content

IT Security Audits following ISO27001/27002 through LMS

How do you deal with IT Security Audits regarding Employee Security Awareness within your organization? In case you are using a Learning Management System (LMS), you might be able to rely on strong reporting:
Security Awareness Training Reporting for ISO 27001 through LMS

IT Security Awareness Failures

Phishers Turn Google's Own Infrastructure Into a Trust Proxy

Researchers uncovered an active, targeted phishing campaign that routes victims through a deliberate chain of six legitimate Google services - including Meet, DoubleClick, Custom Search, Image Search, Tag Manager, and Analytics - before landing them on a credential-harvesting page or silently installing the ScreenConnect remote access tool. By the time a defender inspects the sending domain, the embedded link, or the intermediate hops, everything still looks clean, because security gateways see only trusted Google domains at every step. The landing page dynamically builds a fake corporate login screen using the victim's own e-mail address, pulls a live screenshot of their company website, and exfiltrates stolen credentials to a Telegram bot within seconds. (09/16/2026)

Awareness takeaway: Cybersecurity Awareness for Employees → Understand attacker concepts - even in new scenarios
Security Awareness - Detect phishing attack vectors

Microsoft/Malwarebytes/HackerNews: Fake CAPTCHA Turns Users into Their Own Attackers

Cybercriminals are using compromised websites and fake Cloudflare CAPTCHA prompts to trick users into copying and executing malicious PowerShell commands on their own Windows systems. The TerminalFix campaign then deploys a multi-stage payload that performs Active Directory reconnaissance and establishes a reverse tunnel, potentially giving attackers access to other systems inside the corporate network. (09/03/2026)

Awareness takeaway: Cybersecurity Awareness for Employees → A CAPTCHA or "Verify you are human" prompt should never require users to run commands, open PowerShell, or paste anything into Windows Terminal.
Security Awareness - User detects fake phishing link

A quick update from us

New free Employee Phishing Simulator QuickCheck as SCORM module

In this free E-Mail Phishing Simulator, Employees shall review each message, identify whether it is legitimate or phishing, and use the clues to sharpen their judgment. LMS reporting gives managers valuable insights into how their employees respond to common and sometimes deceptive phishing emails, helping identify potential gaps in security awareness and areas... Phishing Simulator QuickCheck for LMS
Phishing Simulator QuickCheck Demo