Webwire Pty Ltd - What Business Leaders Need to Know: Digital Identity, Zero Trust and Access Security Updates

Explore the latest zero trust and identity security news—from MFA bypasses to ransomware‑linked credential theft—and what small businesses can do now.

 · 5 min read

What Business Leaders Need to Know: Digital Identity, Zero Trust and Access Security Updates

A fresh wave of developments in digital identity and zero trust over the past week puts practical tools and unexpected risks front and centre for small and mid‑sized businesses.

In the past several days, we’ve seen urgent new vulnerabilities and active attacks alongside emerging identity‑centric trends and deployment options. Whether you're reassessing access controls, patching ageing tools, or eyeing zero trust steps that fit your size and budget, there’s plenty to act on now.

1. Active Threat: Microsoft 365 MFA Bypass via OAuth Abuse

A massive 81 million credential attempts have targeted Azure CLI and Microsoft 365 accounts between June 12 and 26. Attackers abused the OAuth Resource Owner Password Credentials (ROPC) flow — a legacy authentication path — to mint access tokens and bypass multi‑factor authentication, even when MFA appeared enabled. The campaign hit at least 64 organisations with 78 confirmed account compromises.

Why it matters for businesses: - Legacy authentication routes, like ROPC, can undermine MFA protections if not explicitly blocked. - Even with robust identity controls in place, unmonitored legacy flows remain a serious risk.

Practical recommendations: - Review Azure and Entra sign‑in logs for abnormal OAuth or CLI activity. - Disable or restrict the ROPC flow wherever possible. - Enforce MFA for all cloud apps and paths, not just interactive logins. - Reset any accounts showing suspicious or unusual access patterns. - Communicate with your team about secure authentication practices and the risks of legacy paths.

According to security researchers, this campaign underscores how partial coverage can leave doors wide open — even when MFA looks enforced across the board. (seclog.org)

2. CISA Flags SharePoint Server Remote‑Code‑Execution (CVE‑2026‑45659)

A critical deserialization vulnerability in Microsoft SharePoint Server (CVE‑2026‑45659) is under active exploitation. CISA successfully added it to its Known Exploited Vulnerabilities catalog, and urged patching immediately for on‑prem SharePoint instances — especially those exposed to the internet — as attackers can achieve remote code execution even with low‑privilege access.

Why it matters for businesses: - Many mid‑sized firms still run on‑prem SharePoint and may not have updated it regularly in recent months. - This is urgent: exploitation is happening now and has real-world consequences.

Practical recommendations: - Apply the latest security updates for SharePoint 2016, 2019 or Subscription Edition without delay. - Review server exposure, firewall rules and internet access to SharePoint. - Investigate logs for suspicious code execution or admin-level changes. - Restrict access to SharePoint admin interfaces if possible. - Inform your IT team and train users to report odd behaviours related to SharePoint.

Reports confirm attackers are weaponising this flaw in the field — immediate action is needed to avoid compromise. (seclog.org)

3. FortiBleed Campaign Harvests FortiGate Credentials for Ransomware

A global credential‑harvesting campaign known as FortiBleed has targeted hundreds of thousands of FortiGate devices worldwide. About 19,000 devices were found to have sniffers deployed, enabling attackers to steal admin credentials. The stolen credentials are then used in follow‑on ransomware operations attributed to INC and Lynx groups.

Why it matters for businesses: - FortiGate firewalls and VPN gateways are commonly used by SMEs — you may be at risk even if patched recently. - Harvested credentials enable network takeover and ransomware deployment even without zero‑day exploits.

Practical recommendations: - Ensure your FortiGate firmware is up‑to‑date and patch any known vulnerabilities quickly. - Monitor administrative access logs on firewalls for abnormal logins or configuration changes. - Change passwords and consider rotating admin credentials as a precaution. - Enable and review multi‑factor authentication for admin access if supported. - Treat firewall credential hygiene as a core part of your zero trust posture.

Incident analysis highlights that attackers exploited compromised FortiGate credentials to take over network control and deploy ransomware — a reminder that perimeter devices remain high‑value targets. (seclog.org)

4. New Study: SME Readiness for Zero Trust Remains Mixed

A recent pilot study of small and medium enterprises across Asia‑Pacific reveals strong awareness of zero trust necessity, especially when cloud‑ready, but identity and access management complexity remain key adoption hurdles. Researchers propose a staged three‑phase path: strengthen identity governance, segment high‑value assets, then introduce targeted monitoring aligned with operational capacity.

Why it matters for businesses: - Most SMEs recognise the value of zero trust, but are struggling with cost, complexity and scaling identity management. - A phased roadmap offers realistic, resource‑aware progress instead of attempting a full zero trust rollout all at once.

Practical recommendations: - Start with clear ownership and policy for identity governance, such as centralising user access control. - Segment critical systems or data — treat them differently from general access. - Implement basic monitoring early — such as logging failed access attempts or anomalous logins. - Scale in line with budget and capability — avoid over‑engineering from day one. - Revisit and refine your approach as automation tools become feasible.

This study confirms that with a realistic, incremental approach, SMEs can make zero trust work — even on a budget. (arxiv.org)

5. Growing Role of Identity Management across Disconnected Environments

At a recent federal cybersecurity summit, officials emphasised that identity management is now the backbone of zero trust, particularly in environments that include disconnected clinics, remote workers and AI-driven devices. As traditional network‑centric security crumbles, identity has become the reference point for trust.

Why it matters for businesses: - Even small firms increasingly operate hybrid, disconnected or remote setups — identity must secure the connections. - Identity governance, federation, MFA and lifecycle controls are core to any modern security stance.

Practical recommendations: - Use identity‑centric controls like single sign‑on (SSO) and MFA across your systems. - Manage device identity: ensure company devices, not just users, are authenticated and authorised. - Enforce lifecycle policies: revoke access when staff or contractors leave or change roles. - Explore identity as a service (IDaaS) or managed IAM where in‑house expertise is limited. - Keep your identity platform documentation current and share basic policies across teams.

Identity aware design is no longer optional — it’s central to defending a distributed business. (govciomedia.com)


What This Means For Your Business

Over the past week, we’ve seen that the biggest identity and access threats don’t always come from zero‑day exploits — they often exploit legacy routes, misconfigurations or credential gaps. At the same time, zero trust remains an appealing model, but one that must be tailored, affordable and staged.

If you’re a manager or decision‑maker at a small or mid‑sized business, here’s how to proceed:

  • Don’t wait for perfection — patch critical systems such as SharePoint and FortiGate immediately.
  • Review and lock down all authentication paths, especially legacy flows like OAuth ROPC in Microsoft cloud services.
  • Treat identity governance as your foundational control — unify access, enforce MFA, manage credentials proactively.
  • Segment and monitor — establish basic controls around critical assets now, add automation later.
  • Explore trusted IAM or identity‑as‑a‑service options if internal skills are limited.

By focusing on the basics — patching, credential hygiene, identity control and graduated zero trust steps — your business builds resilience without overhauling everything all at once. It’s practical, it’s affordable, and ultimately it’s what keeps small businesses safe.

Call Webwire on 08 9386 0053 or contact us at enquiries@webwire.com.au.