IT Security Awareness News Roundup for September 2026

Added at 09/01/2026, last update at 09/11/2026

What matters most this month in IT security and awareness, and what should guide the attention of CIOs, CISOs, and CEOs? (regularly updated)

A quick update from us

New free Employee Phishing Simulator QuickCheck as SCORM module

In this free E-Mail Phishing Simulator, Employees shall review each message, identify whether it is legitimate or phishing, and use the clues to sharpen their judgment. LMS reporting gives managers valuable insights into how their employees respond to common and sometimes deceptive phishing emails, helping identify potential gaps in security awareness and areas... Phishing Simulator QuickCheck Demo

Secure Programming / Coding Failures

Cross-Site Scripting (XSS) still exists in professional Applications!

What about your in-house development? Security in custom-made software – do you rely solely on frameworks? Is Secure Programming background knowledge important to your team and project managers:

Secure Code Training - XSS Fact Sheet

IT Security Awareness Failures

Microsoft/Malwarebytes/HackerNews: Fake CAPTCHA Turns Users into Their Own Attackers

Cybercriminals are using compromised websites and fake Cloudflare CAPTCHA prompts to trick users into copying and executing malicious PowerShell commands on their own Windows systems. The TerminalFix campaign then deploys a multi-stage payload that performs Active Directory reconnaissance and establishes a reverse tunnel, potentially giving attackers access to other systems inside the corporate network. (09/03/2026)

Awareness takeaway: Cybersecurity Awareness for Employees → A CAPTCHA or "Verify you are human" prompt should never require users to run commands, open PowerShell, or paste anything into Windows Terminal.
Security Awareness - User detects fake phishing link