IT Security Awareness News Roundup for August 2026

Added at 08/01/2026, last update at 08/11/2026

What matters most this month in IT security and awareness, and what should guide the attention of CIOs, CISOs, and CEOs? (regularly updated)

General IT Security Awareness Content

How do you manage your employees' IT security awareness?

How do you measure whether your security awareness training is actually working? Completion rates? Click rates? Incident reports?
Security Awareness Training vs Driver Training

Importance of Backups!

Do you backup your important files? Are you sure, have you ever simulated a full restore? What about your organizations' servers? How (fast) do you recover from an IT disaster?
Security Awareness and Importance of Backups

A quick update from us

Security Awareness: Internet Hops vs Encryption

Throwback: 8 years ago, we shared this post on an issue that is still highly relevant today and always will be: Security Awareness: Internet Hops vs Encryption

IT Security Awareness Failures

Exploiting Outlook Web Access Zero-Day: New 'Half-Click' Attack Deploys OWAReaper Malware

A Russia-aligned threat actor, is exploiting CVE-2026-42897, a cross-site scripting flaw in Outlook Web Access, in a "half-click" campaign where merely opening or previewing an email triggers infection. The exploit deploys a novel browser-based implant called OWAReaper, which harvests credentials and OAuth tokens, grants itself persistent server-side mailbox access, and survives password resets and even full device re-imaging. Targeting government, telecom, finance, hospitality, and aerospace organizations across the US and Europe with intentionally bland lure emails. This may have exploited the vulnerability as a zero-day months before Microsoft's patch. (08/01/2026)

Teach e-mail security to your team, why disabling the Outlook reading/preview pane might be important: IT Security Awareness Training for Employees.
Security Awareness - Outlook Zeroday vs E-Mail Security