0:00
/

The AI & Security Insights Show Episode - 000 | Just the Security Savages you know.

We talk and speculate on AI and Security topics before we had out for our late summer / early fall break.

Purview is a thing or so we heard…or as my cat says it …Purrrrrr-view.

Words of Wisdom:

“Take the stairs.”

Security Insights - Foresight - Hindsight

08/27/2026

General

AI Security

Agent365 / Agentic Security – Project Perception

Project Perception snapshot (as of late August)

Microsoft documents Perception as a Limited Public Preview — invitation-only for a defined window before broader availability. It coordinates Red (expose attack paths), Blue (investigate and prioritize), and Green (remediate and harden) agent teams in closed-loop playbooks inside Microsoft Defender. High-impact actions stay under human control.

Azure Security & Defender for Cloud News

Threat Intelligence

Microsoft Entra

Device Management & Protection (Intune)

Defender XDR & Sentinel

Copilot for Security

Purview – Compliance & Governance

Non Microsoft Security News

  • August Patch Tuesday: very large release including exploited WinSock/afd.sys elevation of privilege (CVE-2026-68820)

  • CISA added additional KEV entries this week (including NetScaler and other actively exploited flaws)

AI for the Masses

  • LiteLLM / AI gateway attacks (Microsoft Threat Intelligence, Aug 26)

  • Open-weight model and agent-harness risk discussions

  • Agent pentesting and safety-rail bypass trends

Featured Resources & Deep Dives

What’s New in Defender (August 2026)


Daily Defender Dispatch – August 27, 2026

Daily Defender Dispatch: August Security Recap, AI Gateways Under Fire, Perception Preview

1. What’s new in Microsoft Security — August 2026 (published today)

Microsoft’s monthly recap highlights Defender Experts Threat Intelligence, MDR P2 coverage of third-party Sentinel sources (Palo Alto, AWS, Okta, and more), Entra Tenant Governance, and new agent-containment guidance in Exposure Management.

Read it

2. AI infrastructure is now a primary target

Microsoft Threat Intelligence published a deep dive on attacks against exposed AI workloads — including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining. Treat AI gateways as production control planes, not side projects.

Read it

3. Project Perception status

Perception remains in Limited Public Preview (invitation-only) inside Microsoft Defender. Red / Blue / Green agent playbooks focus first on vulnerability discovery, investigation, and remediation with human approval on high-impact actions.

Overview | Get started | Announcement | MAI-Cyber-1-Flash + MDASH

4. Patch Tuesday follow-through

August’s release was another very large cycle and included exploited WinSock/afd.sys EoP (CVE-2026-68820). Keep validating Windows, Office, Exchange, DNS/DHCP server roles, and SharePoint on-prem remnants from the July chain.

Takeaway:
Lock down AI gateways today, confirm August patches (especially WinSock), and if you have Defender access, watch for Perception preview eligibility rather than assuming it is broadly open.


Discussion about this video

User's avatar

Ready for more?