IT Security Awareness News Roundup for September 2026
Added at 09/01/2026, last update at 09/11/2026
What matters most this month in IT security and awareness, and what should guide the attention of CIOs, CISOs, and CEOs? (regularly updated)
A quick update from us
New free Employee Phishing Simulator QuickCheck as SCORM module
In this free E-Mail Phishing Simulator, Employees shall review each message, identify whether it is legitimate or phishing, and use the clues to sharpen their judgment. LMS reporting gives managers valuable insights into how their employees respond to common and sometimes deceptive phishing emails, helping identify potential gaps in security awareness and areas...
Secure Programming / Coding Failures
Cross-Site Scripting (XSS) still exists in professional Applications!
- XSS2Shell WordPress XSS Vulnerability (08/2026)
- MS Exchange Server XSS Vulnerability (06/2026)
- Stored Cross-Site Scripting (XSS) Vulnerabilities in VMware Products (06/2026)
- ...
What about your in-house development? Security in custom-made software – do you rely solely on frameworks? Is Secure Programming background knowledge important to your team and project managers:
IT Security Awareness Failures
Microsoft/Malwarebytes/HackerNews: Fake CAPTCHA Turns Users into Their Own Attackers
Cybercriminals are using compromised websites and fake Cloudflare CAPTCHA prompts to trick users into copying and executing malicious PowerShell commands on their own Windows systems. The TerminalFix campaign then deploys a multi-stage payload that performs Active Directory reconnaissance and establishes a reverse tunnel, potentially giving attackers access to other systems inside the corporate network. (09/03/2026)