
The AI & Security Insights Show Episode - 000 | Just the Security Savages you know.
Show notes
Purview is a thing or so we heard…or as my cat says it …Purrrrrr-view.
Words of Wisdom:
“Take the stairs.”
Security Insights - Foresight - Hindsight
08/27/2026
General
* What’s new in Microsoft Security: August 2026 | Microsoft Security Blog
* The patch window is collapsing: Why security needs a new control plane | Microsoft Security Blog (Aug 25)
* Rethinking security for the age of AI – Project Perception | Microsoft Blog
AI Security
* When AI infrastructure becomes the target: Securing gateways and control points | Microsoft Security Blog (Aug 26) — LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining
* OpenAI autonomous agent incident affecting Hugging Face and additional services | Hugging Face + OpenAI disclosure
Agent365 / Agentic Security – Project Perception
* What is Project Perception? | Microsoft Learn (Limited Public Preview)
* Get started with Project Perception | Microsoft Learn
* Project Perception product page | Microsoft Security
* Introducing MAI-Cyber-1-Flash inside MDASH | Microsoft AI
Project Perception snapshot (as of late August)Microsoft documents Perception as a Limited Public Preview — invitation-only for a defined window before broader availability. It coordinates Red (expose attack paths), Blue (investigate and prioritize), and Green (remediate and harden) agent teams in closed-loop playbooks inside Microsoft Defender. High-impact actions stay under human control.
Azure Security & Defender for Cloud News
* Microsoft named a Leader in Frost Radar 2026: Cloud Workload Protection Platforms | Microsoft Security Blog
* What’s new in Defender for Cloud | Microsoft Learn
Threat Intelligence
* Hunting MacSync Stealer infrastructure through behavioral pivots | Microsoft Security Blog (Aug 18)
* Email threat landscape: Q2 2026 | Microsoft Security Blog
Microsoft Entra
* Entra Tenant Governance and identity foundations for the AI era | Microsoft Security Blog
* Entra ID CVE-2026-69836 was patched server-side; Microsoft later clarified it was not exploited in the wild
Device Management & Protection (Intune)
* Windows Autopilot device association + Unattended Support with Remote Sign-In | Microsoft Security Blog
* What’s new in Microsoft Intune | Microsoft Learn
Defender XDR & Sentinel
* Monthly news – August 2026 | Microsoft Defender XDR Blog
* What’s new in Microsoft Defender XDR | Microsoft Learn
* What’s new in Microsoft Sentinel | Microsoft Learn — new UEBA sources (Fortinet FortiGate behaviors) and anomalies on behaviors
* Defender Experts MDR P2 now covers third-party data ingested through Sentinel (Palo Alto, AWS, Okta, and more)
Copilot for Security
* Security Copilot overview | Microsoft Learn
Purview – Compliance & Governance
* Purview data protection for AI agents | Microsoft Learn
* Secure Now guidance for agentic containment in Microsoft Security Exposure Management
Non Microsoft Security News
* August Patch Tuesday: very large release including exploited WinSock/afd.sys elevation of privilege (CVE-2026-68820)
* CISA added additional KEV entries this week (including NetScaler and other actively exploited flaws)
AI for the Masses
* LiteLLM / AI gateway attacks (Microsoft Threat Intelligence, Aug 26)
* Open-weight model and agent-harness risk discussions
* Agent pentesting and safety-rail bypass trends
Featured Resources & Deep Dives
* Defender XDR deployment guide
* Advanced hunting best practices
* Security for AI solutions hub
What’s New in Defender (August 2026)
* What’s new in Microsoft Defender XDR | Microsoft Learn
* AI agent posture risk + Agent 365 runtime/threat detection
* Project Perception Limited Public Preview — Red / Blue / Green agent teams in Defender
* MAI-Cyber-1-Flash inside MDASH
* Defender Experts MDR P2 third-party coverage via Sentinel
* Linux AV audit mode (preview) and Linux offboarding API (GA)
Daily Defender Dispatch – August 27, 2026
Daily Defender Dispatch: August Security Recap, AI Gateways Under Fire, Perception Preview
1. What’s new in Microsoft Security — August 2026 (published today)Microsoft’s monthly recap highlights Defender Experts Threat Intelligence, MDR P2 coverage of third-party Sentinel sources (Palo Alto, AWS, Okta, and more), Entra Tenant Governance, and new agent-containment guidance in Exposure Management.→ Read it
2. AI infrastructure is now a primary targetMicrosoft Threat Intelligence published a deep dive on attacks against exposed AI workloads — including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining. Treat AI gateways as production control planes, not side projects.→ Read it
3. Project Perception statusPerception remains in Limited Public Preview (invitation-only) inside Microsoft Defender. Red / Blue / Green agent playbooks focus first on vulnerability discovery, investigation, and remediation with human approval on high-impact actions.→ Overview | Get started | Announcement | MAI-Cyber-1-Flash + MDASH
4. Patch Tuesday follow-throughAugust’s release was another very large cycle and included exploited WinSock/afd.sys EoP (CVE-2026-68820). Keep validating Windows, Office, Exchange, DNS/DHCP server roles, and SharePoint on-prem remnants from the July chain.
Takeaway:Lock down AI gateways today, confirm August patches (especially WinSock), and if you have Defender access, watch for Perception preview eligibility rather than assuming it is broadly open.
This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com