August 2026: Beware Cybersecurity Awareness Month 🎃
Intro
October is approaching, which means it's almost Cybersecurity Awareness Month (CAM). We can expect many well-meaning individuals, organizations, and governments to dust off the same blog post they've published every year since 2010 and call it cybersecurity advice. Some of what's coming will be genuinely useful, like understanding how elder fraud and romance scams work, the stuff that actually empties bank accounts. Those campaigns deserve applause, not a roast.
But, dear hacklore.org reader, you know the other kind is coming too. The kind built entirely out of hacklore: public Wi-Fi warnings dressed up as a threat model, juice jacking making its annual haunted return, a QR code graphic with a skull on it. These campaigns aren't protecting anyone. They're the security equivalent of a garlic necklace: useless against the thing that's actually going to bite you, and recycled every year because nobody's checked whether it ever worked. Trick, not treat. And this October, they've earned the full weight of a public roast.
Here's the thing: there's still time to fix this. Most CAM content gets finalized soon, which means anyone with a hacklore-shaped campaign sitting in a draft folder right now can still swap it out for something that reduces actual victim counts. So forward this newsletter to whoever owns your organization's CAM campaign. Put them on notice. Tell them the alternative to a trick is a treat: advice grounded in how people actually get scammed, not advice that survives because it feels protective.
I'll be honest, though. Some part of me is looking forward to this October's crop of hacklore. It's good material. I'll be collecting the “best of the worst” all month, and the November newsletter will feature a proper CAM roundup, worst offenders included.
Zombie advice 🧟
Zombie of the Month! 🥇
Our Zombie of the month article was sent in by Chris Palmer, and it’s a doozy. Trend Micro has a page that warns people about “IP Address Hacking”. What is, you ask, IP address hacking? I won’t be able to do it justice, so here is what the web site says:
IP address hacking is when someone sneaks into computers or networks without permission by finding weaknesses in their IP addresses, which are like digital home addresses for devices connected to the internet.
Visit their web page to read more. Every sentence seems less tethered to reality than the previous one. If the people who do the Drunk History videos ever turn to cybersecurity, this is the kind of result I would expect to see.
Runners-up 🥈
➡️ Newsweek says “the FCC said in 2023 that it was yet to find an example of juice jacking in the wild” but then engages in FUD by saying “The best way to avoid juice jacking is to simply carry a charger and plug it into the wall, rather than a USB port”. Giving advice to stop a non-existent crime is classic hacklore.
➡️ KOB channel 4 in Albuquerque, NM writes:
Free Wi-Fi is tempting, especially when you’re in an airport or restaurant but security experts warn some of those networks are not what they seem.
…
The good news is that most banking apps and shopping websites use encryption, which hides passwords and bank logins. However, hackers don’t need to crack encryption if they fool you into handing the information over.
…
Avoid shopping and banking on public Wi-Fi. If a new network suddenly asks you to log into Amazon or Facebook, that’s a red flag.Even with all the protections of today’s phones and sites, man-in-the-middle attacks still account for about 20% of all cyberattacks and cause billions in losses every year.
Of course, they don't cite any sources for this FUD. I mean… 20%‽ Verizon's 2025 DBIR puts it at 4% of the entire breach dataset, for AiTM, password dumping, and hijacking combined, not 20% of "all cyberattacks." See the "Verizon 2025 Data Breach Investigations Report: Small- and Medium-Sized Business Snapshot," page 10.
➡️ The AP published an article titled “One Tech Tip: Logging on at a cafe? Privacy and security guidelines for remote workers”. They write:
Avoid a public Wi-Fi network that doesn’t need a password, because any data sent over it is vulnerable to theft or manipulation, the National Security Agency warns.
We haven’t really talked about that and other NSA docs, but they are generally intended for National Security System (NSS), Department of Defense (DoD), and Defense Industrial Base (DIB) users, not everyday people. In my opinion, they are also wrong.
(Hat tip to Cliff Barbier!)
Captive Crunch 🏴☠
Here's where it gets tricky. Everything above was hacklore because the threat was fake or overstated. This one requires some nuance: security researchers found a genuine, active campaign hijacking corporate accounts through compromised public Wi-Fi gateways. Although it's real, only a tiny number of people will ever encounter this attack, and most people still haven't done the basics that stop the scams that are actually emptying their bank accounts. Elevating a rare, targeted campaign into general public advice is its own kind of misdirection, just with better credentials than a garlic necklace. Nevertheless, people have asked about it, so we'll cover it here.
A company called ReliaQuest released a report that a threat actor was compromising public Wi-Fi gateways at hotels, conference centers, and other shared venues to hijack the accounts of traveling corporate employees. They believe that the tradecraft resembles APT28, a Russian military intelligence group previously linked to similar router-based campaigns against Microsoft 365 accounts.
They concluded with advice for Microsoft-shop admins: deploy always-on corporate VPNs, disable WPAD (a legacy proxy auto-discovery protocol that is still strangely enabled by default on Microsoft Windows), and block Microsoft's device-code sign-in flow.
A few people chimed in with interesting points.
Noted CISO Geoff Belknap wrote a LinkedIn post with advice for Microsoft admins that ended: "Why are these manual options and not secure defaults, vs tell employees to avoid Wi-Fi and don't click things?" He also hinted at what Microsoft itself should do to protect all its customers, which is the actually scalable fix.
It's almost like he's calling for software that's secure by design. 🤔
Per Thorsheim wrote about his efforts as CISO at a hotel chain to remove captive portals entirely, here and here.
As for what everyday people can do, here are a few things that don't require buying a personal VPN product.
General advice, corporate or everyday user: Follow the advice on the main hacklore.org site. The basics are still the basics.
As much as I hate to advocate for user vigilance when really the software manufacturers should fix their products, the reality is that captive portals introduce a real security problem. So here are a few tips to help compensate for insufficient effort by the software makers:
- Don't type anything sensitive into a captive portal. Room number, your name, the shared network password: fine. Credentials, payment details, anything else: nope.
- Don't act on anything the portal tells you to do. If it wants you to download a file or run a command to "finish connecting," close the tab. Legitimate wifi doesn't require you to execute code.
- A certificate error means disconnect, immediately. Don't click through it, don't retry. Get off that network.
There are a few other technical settings that might help that are outside the scope of this newsletter, but the quick summary is to enable strong DNS encryption at the browser level, and at the OS level. You can also disable WPAD if you don’t need it; it’s on by default in Windows, and was flagged as risky since at least 2016. 🙄
As I always say when I hear advice for everyday people that sounds like it's for real-life spies: someone is trying to hack you for sure. Just not that way.
Community update
Subscribers 🗞
We have 770+ subscribers! Send this newsletter to 2 friends so we can get to 1,000 before the end of the year.
Podcasts 📻
I made a guest appearance on the Inverted Podcast with Jeroen Kemperman, Dana Kaufman, and Dario Salice. It was great fun!
In the news 📰
📣 Big news! One of our subscribers has published a book! 💥 📖
I am honored that Frank Riccardi used the term "hacklore" in "CTRL+ALT+PWN: The Hacker's Playbook (And How to Beat It)". I contributed a quote for the back cover. It is out now for pre-order, and it's very much in the Hacklore spirit.
Frank's been a reader here for a while, and it shows. He goes after the same target we do: the myth that hacking is some cinematic, hoodie-in-a-basement feat. It is great to have him set the record straight on how to stay safe online.
If you've been reading Hacklore, this book will feel familiar, and it's a great gift idea for friends and family who need to better secure their digital lives. Grab a copy on Amazon, or find Frank on LinkedIn if you want to talk shop with him directly. Thank you Frank! 🙏
➡️ I spoke at the Swiss Post Cybersecurity’s “Genev’Hack” and “Limmat’Hack” conferences in Switzerland. The conference organizers and attendees were fantastic, and I made some new friends! 🇨🇭
➡️ Hacklore.org got a shout out in an academic paper titled “Public Wi-Fi Security and the Spread of Fear, Uncertainty, and Doubt” by Jonas Schmitt, Maximilian Golla, and Jonas Hielscher. They write, “In this short paper, we aim to make the case to eliminate the FUD around public Wi-Fi. We take public Wi-Fi as a prime example of FUD, as there are strong economic incentives to keep it alive. However, multiple other outdated pieces of security advice need to be addressed. A good starting point is the open letter published by a group of Chief Information Security Officers (CISOs) in November 2025.” Hey! That's us! 😆
➡️ Alexis Dorais-Joncas mentions busts some hacklore myths in this article.
➡️ Check out “Please stop paying for a VPN to be ‘safe’ on coffee shop Wi-Fi” by Gavin Phillips. It’s an informative article, despite not giving us a shoutout. 😜
Misc.
➡️ Reminder to check out the Hacklore Blue Sky account. And to boost it with your followers!
➡️ I whipped up a quick slide deck that you can use during a brown bag lunch session. Feel free to remix and share! Formats: Gamma, PowerPoint
➡️ A reader sent this image from the Barcelona metro. 🤔

Closing thoughts 🔚
I know Halloween is fun, but zombie advice doesn't belong in Cybersecurity Awareness Month campaigns. So if you can stop them from showing up, please do. And if you come across any, please send them our way. We'll add them to the November roundup.
See you in November. In the meantime, don't believe everything you read.
— Bob