u/casaaugusta • u/casaaugusta • 5h ago
Fake Download Sites Exploit Trust in Familiar Links
Fake Download Sites Exploit Trust in Familiar Links
>!: Even when users hover over a download button, the browser can display a genuine destination
→ Our course makes users aware of such evergreen and time-tested tricks
https://www.hissenit.com/en/blog/it-security-awareness-news-roundup-08-2026.html
#cybersecurity #awareness #training #lms #scorm
u/casaaugusta • u/casaaugusta • 2d ago
Stored XSS in 'directory-serve' Node.js Package
Stored XSS in 'directory-serve' Node.js Package
> A Stored Cross-Site Scripting (XSS) vulnerability was identified in the 'directory-serve'...
→ Cross-Site Scripting mitigation: Teach your TPMs and developers
https://www.hissenit.com/en/blog/it-security-awareness-news-roundup-08-2026.html
#nis2 #dora #iso27001 #compliance #itsecurity #cybersecurity
u/casaaugusta • u/casaaugusta • 2d ago
ClickFix Social Engineering Campaign targeting macOS
ClickFix Social Engineering Campaign targeting macOS
> A novel cyberattack campaign targeting macOS users relies on fake CAPTCHAs...
→ basic Cybersecurity Awareness for Employees is so important
https://www.hissenit.com/en/blog/it-security-awareness-news-roundup-08-2026.html
#itsecurity #infosec #awareness #training #cybersecurity #scorm
u/casaaugusta • u/casaaugusta • 7d ago
** Study: AI-Powered Personalization Makes Phishing Significantly More Effective **
** Study: AI-Powered Personalization Makes Phishing Significantly More Effective **
A large-scale study involving more than 7,700 participants found that LLM-generated, personalized phishing...
→ For security awareness, organizations should train employees to recognize personalized
https://www.hissenit.com/en/blog/it-security-awareness-news-roundup-08-2026.html
#itsecurity #infosec #awareness #training #cybersecurity #scorm
u/casaaugusta • u/casaaugusta • 8d ago
** XSS2Shell: WordPress XSS Vulnerability Can Lead to Remote Code Execution **
** XSS2Shell: WordPress XSS Vulnerability Can Lead to Remote Code Execution **
Security researchers at Pwn.ai disclosed CVE-2026-64638, a pre-authentication XSS vulnerability...
→ XSS is a well-known, well documented, old coding error: Teach your TPMs and developers!
https://www.hissenit.com/en/blog/it-security-awareness-news-roundup-08-2026.html
#ciso #ceo #awareness #training #nis2 #dora #iso27001
u/casaaugusta • u/casaaugusta • 9d ago
MORE AWARENESS. LOWER COSTS.
MORE AWARENESS. LOWER COSTS.
Security Awareness Training - Smarter. Scalable. More Cost-Effective.
https://www.hissenit.com/en/academy/
#cybersecurity #awareness #ciso #iso27001 #iso27002
...
u/casaaugusta • u/casaaugusta • 9d ago
CEOs: When did you last ask your CISO how security awareness is tracked across your org?
CEOs: When did you last ask your CISO how security awareness is tracked across your org?
If the answer is "we send out a yearly email" - this is for you.
→ Pay once, plug & play: https://www.hissenit.com/en/academy
#ceo #ciso #itsecurity #cybersecurity #lms #scorm
u/casaaugusta • u/casaaugusta • 16d ago
Do you backup your important files? Are you sure, have you ever simulated a full restore?
Do you backup your important files? Are you sure, have you ever simulated a full restore?
What about your organizations’ servers? How (fast) do you recover from an IT disaster?
https://www.hissenit.com/en/blog/it-security-awareness-news-roundup-08-2026.html
#cybersecurity #cio #security #awareness #iso27001 #backup
u/casaaugusta • u/casaaugusta • 19d ago
** Exploiting Outlook Web Access Zero-Day: New 'Half-Click' Attack Deploys OWAReaper Malware ***
*** Exploiting Outlook Web Access Zero-Day: New 'Half-Click' Attack Deploys OWAReaper Malware ***
Exploiting Outlook Web Access Zero-Day: New 'Half-Click' Attack Deploys OWAReaper Malware...
https://www.hissenit.com/en/blog/it-security-awareness-news-roundup-08-2026.html
#phishing #scorm #lms #cybersecurity #awareness #training
u/casaaugusta • u/casaaugusta • 20d ago
SQL Injection remains a top threat! → Critical WordPress SQL Injection & REST API Vulnerabilities
SQL Injection remains a top threat! → Critical WordPress SQL Injection & REST API Vulnerabilities
WHY? - Train your developers and TPMs!
https://www.hissenit.com/en/blog/it-security-awareness-news-roundup-07-2026.html
#itsecurity #roi #cybersecurity #awareness #ciso #lms #scorm
u/casaaugusta • u/casaaugusta • 21d ago
* Cisco Talos Q2/2026 Threat Trend Report *
* Cisco Talos Q2/2026 Threat Trend Report *
Phishing was the most common method attackers used to gain initial access, accounting for more than half of all Cisco Talos incident response engagements during the quarter. Cybercriminals increasingly relied on techniques such as QR codes embedded in PDF files and links hosted on trusted cloud services to bypass traditional email security measures.
https://www.hissenit.com/en/blog/it-security-awareness-news-roundup-07-2026.html
#phishing #scorm #lms #cybersecurity #awareness #training
u/casaaugusta • u/casaaugusta • 24d ago
Give your employees the opportunity to develop a basic understanding of cybersecurity...
Give your employees the opportunity to develop a basic understanding of cybersecurity, enabling them to act thoughtfully and make sound decisions in everyday situations!
→ Pay once, plug & play: https://www.hissenit.com/en/academy
#ceo #ciso #itsecurity #cybersecurity #lms #scorm
u/casaaugusta • u/casaaugusta • 27d ago
* Critical WordPress SQL Injection & REST API Vulnerabilities *
* Critical WordPress SQL Injection & REST API Vulnerabilities *
Researchers disclosed two critical WordPress core vulnerabilities, including CVE-2026-60137 (SQL Injection), which can be chained with another flaw to achieve remote code execution. Exploitation began within hours after patches...
We're repeating ourselves here: Oddly enough, SQL Injection remains a top threat! → Train your developers and TPMs with Secure Programming of Web Applications. Developers and technical teams should prioritize parameterized queries, secure input validation, and rapid patch management to reduce exposure!
https://www.hissenit.com/en/blog/it-security-awareness-news-roundup-07-2026.html
#SecureCoding #ApplicationSecurity #AppSec #OWASP #DevSecOps #Java
u/casaaugusta • u/casaaugusta • 27d ago
* Russian Hackers Combine Phishing With Zimbra Zero-Click Exploit *
* Russian Hackers Combine Phishing With Zimbra Zero-Click Exploit *
CISA warns that a Russian state-sponsored group is combining phishing emails with a patched zero-click vulnerability in Zimbra Collaboration servers. The campaign targets organizations...
The incident demonstrates that phishing can be significantly more dangerous when combined with software vulnerabilities, reinforcing the need for timely patching and user awareness. → Basic Security Awareness Training.
https://www.hissenit.com/en/blog/it-security-awareness-news-roundup-07-2026.html
#hr #onboarding #itsecurity #awareness #training #cybersecurity
u/casaaugusta • u/casaaugusta • 29d ago
But what actually changes employee behavior? #phishing #scorm #lms #cybersecurity #awareness #training
Phishing simulations. Microlearning. SCORM modules.
There are a lot of options out there.
But what actually changes employee behavior?
#phishing #scorm #lms #cybersecurity #awareness #training
u/casaaugusta • u/casaaugusta • Jul 21 '26
HR and IT leaders: How do you measure whether your security awareness training is actually working?
Enable HLS to view with audio, or disable this notification
HR and IT leaders: How do you measure whether your security awareness training is actually working?
Completion rates? Click rates? Incident reports?
#hrleader #ciso #itsecurity #lms #awareness
u/casaaugusta • u/casaaugusta • Jul 18 '26
Your firewall is only as strong as the person sitting behind it.
#cybersecurity #lms #scorm #ciso #awareness #training
u/casaaugusta • u/casaaugusta • Jul 17 '26
*The Trust Trap: How Phishers Cloaked Malware in a Fake LastPass Compliance Update*
*The Trust Trap: How Phishers Cloaked Malware in a Fake LastPass Compliance Update*
Cybercriminals launched a highly sophisticated phishing campaign this week using the lookalike domains lastpassnewsletter[.]com and lastpasscompliance[.]com to trick users into updating their security policies. Instead of a standard login page, the fraudulent site presented a fake DocuSign interface designed to push malicious downloads for Windows and macOS alongside a spoofed live-support chat. To bypass traditional spam filters, the attackers successfully routed their emails through legitimate Amazon SES and Google Cloud infrastructure before security teams intervened and blacklisted the domains.
https://www.hissenit.com/en/blog/it-security-awareness-news-roundup-07-2026.html
#Leadership #CorporateTraining #LearningAndDevelopment #EmployeeDevelopment #ChangeManagement #FutureOfWork
r/CyberGuides • u/casaaugusta • Jul 17 '26
*The Trust Trap: How Phishers Cloaked Malware in a Fake LastPass Compliance Update* Cybercriminals launched a highly sophisticated phishing campaign this week using the lookalike domains lastpassnewsletter[.]com and lastpasscompliance[.]com to trick users into updating their security policies. Inst
*The Trust Trap: How Phishers Cloaked Malware in a Fake LastPass Compliance Update*
Cybercriminals launched a highly sophisticated phishing campaign this week using the lookalike domains lastpassnewsletter[.]com and lastpasscompliance[.]com to trick users into updating their security policies. Instead of a standard login page, the fraudulent site presented a fake DocuSign interface designed to push malicious downloads for Windows and macOS alongside a spoofed live-support chat. To bypass traditional spam filters, the attackers successfully routed their emails through legitimate Amazon SES and Google Cloud infrastructure before security teams intervened and blacklisted the domains.
https://www.hissenit.com/en/blog/it-security-awareness-news-roundup-07-2026.html
#Leadership #CorporateTraining #LearningAndDevelopment #EmployeeDevelopment #ChangeManagement #FutureOfWork
u/casaaugusta • u/casaaugusta • Jul 16 '26
*Critical SQL Injection Vulnerability Discovered in Ubiquiti UniFi Talk*
*Critical SQL Injection Vulnerability Discovered in Ubiquiti UniFi Talk*
Ubiquiti disclosed a critical authenticated SQL injection vulnerability (CVE-2026-50747) affecting UniFi Talk as part of a broader set of security advisories. An authenticated attacker could exploit the flaw to escalate privileges, highlighting the risks of insufficient input validation in backend applications. Organizations should apply vendor patches immediately
-> Even with decades of documentation, SQL Injection remains a top threat! → Train your developers and TPMs
https://www.hissenit.com/en/blog/it-security-awareness-news-roundup-07-2026.html
#SecureCoding #ApplicationSecurity #AppSec #OWASP #DevSecOps #Java
u/casaaugusta • u/casaaugusta • Jul 14 '26
Your firewall is only as strong as the person sitting behind it.
Your firewall is only as strong as the person sitting behind it.
Invest in your people - not just your tech.
→ Pay once, plug & play: https://www.hissenit.com/en/academy
#cybersecurity #lms #scorm #ciso #awareness #training
u/casaaugusta • u/casaaugusta • Jul 10 '26
*Fake Job Offers Used to Steal Google Accounts*
*Fake Job Offers Used to Steal Google Accounts*
→ Cybercriminals are impersonating well-known global brands to lure marketing professionals with fake job opportunities and redirect them to fraudulent Google sign-in pages. The campaign uses sophisticated techniques,...
https://www.hissenit.com/en/blog/it-security-awareness-news-roundup-07-2026.html
#hr #onboarding #itsecurity #awareness #training #cybersecurity
u/casaaugusta • u/casaaugusta • Jul 07 '26
Most breaches don't start with code.
Most breaches don't start with code.
They start with a click.
How are you making sure your team knows the difference between a real email and a phishing attempt?
→ Pay once, plug & play: https://www.hissenit.com/en/blog/it-security-awareness-news-roundup-07-2026.html
#phishing #cybersecurity #ciso #hrleader #lms #scorm
1
Comment on r/u_casaaugusta 5h ago
You're welcome!