IT Security Awareness News Roundup for August 2026

Added at 08/01/2026, last update at 08/01/2026

What matters most this month in IT security and awareness, and what should guide the attention of CIOs, CISOs, and CEOs? (regularly updated)

IT Security Awareness Failures

Exploiting Outlook Web Access Zero-Day: New 'Half-Click' Attack Deploys OWAReaper Malware

A Russia-aligned threat actor, is exploiting CVE-2026-42897, a cross-site scripting flaw in Outlook Web Access, in a "half-click" campaign where merely opening or previewing an email triggers infection. The exploit deploys a novel browser-based implant called OWAReaper, which harvests credentials and OAuth tokens, grants itself persistent server-side mailbox access, and survives password resets and even full device re-imaging. Targeting government, telecom, finance, hospitality, and aerospace organizations across the US and Europe with intentionally bland lure emails. This may have exploited the vulnerability as a zero-day months before Microsoft's patch. (08/01/2026)

Teach e-mail security to your team, why disabling the Outlook reading/preview pane might be important: IT Security Awareness Training for Employees.
Security Awareness - Outlook Zeroday vs E-Mail Security