Identity Beats Exploits, a Windows Zero-Day PoC & SharePoint Under Attack (07/15/2026)
- › Sophos found 67% of the incidents its response teams handled last year were rooted in identity attacks, with a lack of MFA in 59% of cases.
- › A researcher released a Windows zero-day proof-of-concept called LegacyHive hours after Microsoft's record Patch Tuesday.
- › CISA warns that attackers are actively exploiting three SharePoint vulnerabilities against internet-exposed on-premises servers.
- › Zoom disclosed a critical flaw in its Windows desktop client and SDK that lets an unauthenticated attacker hijack accounts.
- › The OkoBot framework injects seed-phrase phishing into Ledger and Trezor apps to drain hardware wallets.
The headline number today is the one that should reset your budget. Two thirds of the incidents Sophos responded to last year started with a login, not an exploit. Meanwhile a researcher dropped a Windows zero-day the day after Microsoft’s record patch dump, CISA says three SharePoint bugs are under active attack, and Zoom is warning about account takeover. Patch the things being exploited, then go look at how your people authenticate.
Top 5 Critical Security Alerts
1. Identity Attacks Now Outrank Exploits as the Way In
Sophos reports that 67% of all incidents its incident response and managed detection teams investigated last year were rooted in identity-related attacks, with a lack of multi-factor authentication (MFA) in 59% of cases, and brute-force activity (15.6%) drawing almost level with exploitation (16%) as an initial access method (Dark Reading, Sophos). The adversary stopped picking the lock because the front door accepts a valid credential, and we break down what that means for your defense in why attackers log in instead of breaking in.
Operator Note: If MFA coverage is a question mark anywhere in your estate, that is your top finding this week. A gap in 59% of cases is not an edge case, it is the norm.
2. Researcher Drops a Windows Zero-Day PoC After Patch Tuesday
A security researcher released a new Windows proof-of-concept exploit called LegacyHive hours after Microsoft shipped its record July update (The Hacker News, Ars Technica). A public PoC compresses the timeline from disclosure to exploitation to about as long as it takes an attacker to read the writeup, and it lands while every Windows team is still digging out of 570 fixes.
3. CISA Warns of Three Actively Exploited SharePoint Flaws
CISA warned that attackers are actively exploiting three vulnerabilities in internet-exposed on-premises SharePoint servers, with two more critical holes adding to the pressure (BleepingComputer, The Register). On-prem SharePoint holds the documents an organization runs on and is often left exposed because migrating it is painful, which is exactly why crews keep coming back to it.
Operator Note: Actively exploited plus internet-exposed is the only combination that jumps the queue. Patch these before you touch the rest of the backlog.
4. Zoom Discloses a Critical Account Takeover Flaw
Zoom warned of a critical vulnerability in its Windows desktop client and software development kit that an unauthenticated party could exploit to hijack accounts (BleepingComputer). Unauthenticated account takeover in a tool installed on nearly every corporate endpoint is a wide door, and Zoom sits in the trusted-by-default category most asset inventories never revisit.
5. OkoBot Steals Seed Phrases From Ledger and Trezor Apps
The OkoBot malware framework, running on Windows machines since April 2025, includes a module built to con hardware wallet owners out of their recovery seed phrases by injecting phishing into Ledger and Trezor apps (The Hacker News, Securelist). A hardware wallet is supposed to keep the keys off the computer, and this sidesteps that entirely by attacking the human at the moment they type the phrase in.
Additional Security Alerts
Threat Intelligence
- Cursor Flaw Runs a Repo’s Own git.exe: Opening a repository in Cursor on Windows executes a
git.exesitting in the project root, with no click, approval, or warning, which turns cloning an untrusted repo into code execution. The Hacker News
Security Standards & Frameworks
- US Unveils an AI-Supported Vulnerability Clearinghouse: The Gold Eagle program will let industry, critical infrastructure operators, and government use AI to detect, prioritize, and patch vulnerabilities faster. The Record
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.