The AI & Security Insights Show

Rod Trent

Details

Hosted by Edward Walton, Frank Grimberg and Rod Trent, THE "AI" Security Insights Show provides information, news, tips on security solutions to help protect AI, agents, SIEM solutions and XDR. www.microsoftsecurityinsights.com

Recent Episodes

AUG 28, 2026
The AI & Security Insights Show Episode - 000 | Just the Security Savages you know.
Purview is a thing or so we heard…or as my cat says it …Purrrrrr-view. Words of Wisdom: “Take the stairs.” Security Insights - Foresight - Hindsight 08/27/2026 General * What’s new in Microsoft Security: August 2026 | Microsoft Security Blog * The patch window is collapsing: Why security needs a new control plane | Microsoft Security Blog (Aug 25) * Rethinking security for the age of AI – Project Perception | Microsoft Blog AI Security * When AI infrastructure becomes the target: Securing gateways and control points | Microsoft Security Blog (Aug 26) — LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining * OpenAI autonomous agent incident affecting Hugging Face and additional services | Hugging Face + OpenAI disclosure Agent365 / Agentic Security – Project Perception * What is Project Perception? | Microsoft Learn (Limited Public Preview) * Get started with Project Perception | Microsoft Learn * Project Perception product page | Microsoft Security * Introducing MAI-Cyber-1-Flash inside MDASH | Microsoft AI Project Perception snapshot (as of late August)Microsoft documents Perception as a Limited Public Preview — invitation-only for a defined window before broader availability. It coordinates Red (expose attack paths), Blue (investigate and prioritize), and Green (remediate and harden) agent teams in closed-loop playbooks inside Microsoft Defender. High-impact actions stay under human control. Azure Security & Defender for Cloud News * Microsoft named a Leader in Frost Radar 2026: Cloud Workload Protection Platforms | Microsoft Security Blog * What’s new in Defender for Cloud | Microsoft Learn Threat Intelligence * Hunting MacSync Stealer infrastructure through behavioral pivots | Microsoft Security Blog (Aug 18) * Email threat landscape: Q2 2026 | Microsoft Security Blog Microsoft Entra * Entra Tenant Governance and identity foundations for the AI era | Microsoft Security Blog * Entra ID CVE-2026-69836 was patched server-side; Microsoft later clarified it was not exploited in the wild Device Management & Protection (Intune) * Windows Autopilot device association + Unattended Support with Remote Sign-In | Microsoft Security Blog * What’s new in Microsoft Intune | Microsoft Learn Defender XDR & Sentinel * Monthly news – August 2026 | Microsoft Defender XDR Blog * What’s new in Microsoft Defender XDR | Microsoft Learn * What’s new in Microsoft Sentinel | Microsoft Learn — new UEBA sources (Fortinet FortiGate behaviors) and anomalies on behaviors * Defender Experts MDR P2 now covers third-party data ingested through Sentinel (Palo Alto, AWS, Okta, and more) Copilot for Security * Security Copilot overview | Microsoft Learn Purview – Compliance & Governance * Purview data protection for AI agents | Microsoft Learn * Secure Now guidance for agentic containment in Microsoft Security Exposure Management Non Microsoft Security News * August Patch Tuesday: very large release including exploited WinSock/afd.sys elevation of privilege (CVE-2026-68820) * CISA added additional KEV entries this week (including NetScaler and other actively exploited flaws) AI for the Masses * LiteLLM / AI gateway attacks (Microsoft Threat Intelligence, Aug 26) * Open-weight model and agent-harness risk discussions * Agent pentesting and safety-rail bypass trends Featured Resources & Deep Dives * Defender XDR deployment guide * Advanced hunting best practices * Sentinel best practices * Security for AI solutions hub What’s New in Defender (August 2026) * What’s new in Microsoft Defender XDR | Microsoft Learn * AI agent posture risk + Agent 365 runtime/threat detection * Project Perception Limited Public Preview — Red / Blue / Green agent teams in Defender * MAI-Cyber-1-Flash inside MDASH * Defender Experts MDR P2 third-party coverage via Sentinel * Linux AV audit mode (preview) and Linux offboarding API (GA) Daily Defender Dispatch – August 27, 2026 Daily Defender Dispatch: August Security Recap, AI Gateways Under Fire, Perception Preview 1. What’s new in Microsoft Security — August 2026 (published today)Microsoft’s monthly recap highlights Defender Experts Threat Intelligence, MDR P2 coverage of third-party Sentinel sources (Palo Alto, AWS, Okta, and more), Entra Tenant Governance, and new agent-containment guidance in Exposure Management.→ Read it 2. AI infrastructure is now a primary targetMicrosoft Threat Intelligence published a deep dive on attacks against exposed AI workloads — including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining. Treat AI gateways as production control planes, not side projects.→ Read it 3. Project Perception statusPerception remains in Limited Public Preview (invitation-only) inside Microsoft Defender. Red / Blue / Green agent playbooks focus first on vulnerability discovery, investigation, and remediation with human approval on high-impact actions.→ Overview | Get started | Announcement | MAI-Cyber-1-Flash + MDASH 4. Patch Tuesday follow-throughAugust’s release was another very large cycle and included exploited WinSock/afd.sys EoP (CVE-2026-68820). Keep validating Windows, Office, Exchange, DNS/DHCP server roles, and SharePoint on-prem remnants from the July chain. Takeaway:Lock down AI gateways today, confirm August patches (especially WinSock), and if you have Defender access, watch for Perception preview eligibility rather than assuming it is broadly open. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com
63 MIN
AUG 21, 2026
The AI & Security Insights Show Episode 298 | Julian Kusenberg - Purview, Agents and AI! oooh my!
Purview is a thing or so we heard…or as my cat says it …Purrrrrr-view. Words of Wisdom: “When you don’t know how much to pay someone for a particular task, ask them, “what they think is fair” and their number usually is.” Security Insights - Foresight - Hindsight – August 2026 Edition General * Lots of free tech training - Explore events at Microsoft * Rethinking security for the age of AI – Introducing Project Perception | Microsoft Blog * What’s new in Microsoft Security: July 2026 | Microsoft Security Blog * Securing our future: July 2026 Secure Future Initiative progress report | Microsoft Security Blog AI Security * OpenAI autonomous agent escapes and Hugging Face incident | Hugging Face + OpenAI disclosure * Enhancing AI security through global AI red teaming | Microsoft Security Blog Agent365 / Agentic Security – Project Perception Deep Dive * What is Project Perception? | Microsoft Learn * Get started with Project Perception | Microsoft Learn * Project Perception product page | Microsoft Security * Rethinking security for the age of AI | Microsoft Blog * Introducing MAI-Cyber-1-Flash inside MDASH | Microsoft AI Key Project Perception DetailsProject Perception is Microsoft’s new multi-agent security system that coordinates specialized AI agents across three roles: * Red team agents – continuously map attack paths and probe for weaknesses before adversaries can exploit them * Blue team agents – investigate signals, correlate context, and prioritize real risk * Green team agents – remediate findings and harden the environment It runs as a closed-loop system that reasons over Microsoft security signals, organizational context, and threat intelligence. High-impact actions remain under human control. Public preview began August 3, 2026, initially inside the Microsoft Defender portal, with plans to expand across the Microsoft Security portfolio. Pricing uses Security Compute Units (SCUs). Azure Security & Defender for Cloud News * What’s new in Defender for Cloud | Microsoft Learn Threat Intelligence * CaptiveCrunch: Midnight Blizzard targeting travelers | Microsoft Security Blog * Email threat landscape: Q2 2026 trends | Microsoft Security Blog Microsoft Entra * Microsoft Entra ID security updates – Passkeys as default | Microsoft Security Blog Device Management & Protection (Intune) * What’s new in Microsoft Intune | Microsoft Learn Defender XDR & Sentinel * Monthly news – July/August 2026 | Microsoft Defender XDR Blog * Sentinel Graph tools + custom detection as code | Microsoft Learn * Defender XDR + Sentinel unified operations | Microsoft Learn Copilot for Security * Security Copilot agentic capabilities | Microsoft Learn Purview – Compliance & Governance * Purview data protection for AI agents | Microsoft Learn * Purview for Agent 365 | Microsoft Learn Non Microsoft Security News * OpenAI agent sandbox escape that compromised Hugging Face and additional third-party accounts → Hugging Face report + OpenAI statement AI for the Masses * LiteLLM and open-weight model risks * Model ablation / safety-rail bypass techniques * Embedding space attacks * Agent pentesting and bug-bounty trends Featured Resources & Deep Dives * Defender XDR deployment guide * Advanced hunting best practices * Sentinel best practices * Secure Copilot foundation * Security for AI solutions hub What’s New in Defender (August 2026) * What’s new in Microsoft Defender XDR | Microsoft Learn * Project Perception public preview (Red / Blue / Green agent teams for attack simulation, investigation & remediation) – available in Microsoft Defender starting August 3 * MAI-Cyber-1-Flash integrated with MDASH – specialized cybersecurity model delivering ~96% on CyberGym at roughly half the previous cost by handling ~90% of routine tasks Daily Defender Dispatch – August 20, 2026 Daily Defender Dispatch: Project Perception Public Preview Live + MAI-Cyber-1-Flash 1. Project Perception Public Preview is LiveMicrosoft’s new multi-agent security system entered public preview on August 3 inside the Microsoft Defender portal.It coordinates three specialized agent teams: * Red – continuous attack-path mapping and proactive probing * Blue – investigation, prioritization, and detection engineering * Green – remediation and hardening Humans retain final control over high-impact actions. Access it via the Perception blade in the Defender portal.→ Announcement | Learn overview | Get started 2. MAI-Cyber-1-Flash + MDASHMicrosoft’s first in-house cybersecurity model (MAI-Cyber-1-Flash) is now powering the MDASH multi-agent vulnerability harness. It handles the majority of routine tasks and escalates only the hardest work to larger models (e.g., GPT-5.4), delivering top-tier CyberGym performance at significantly lower cost.→ MAI-Cyber-1-Flash announcement 3. Why This MattersProject Perception represents Microsoft’s clearest move yet from “AI that assists” (Security Copilot) to “AI that acts” under human oversight. Early adopters should evaluate it for vulnerability management playbooks first, then expand to threat-intel driven investigations. Takeaway for defenders:If you already have Defender XDR, log into the portal today and explore the new Perception experience. Start with low-risk playbooks and keep human approval gates enabled. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com
63 MIN
AUG 14, 2026
The AI & Security Insights Show Episode 297 | Black Hat and Defcon Recap, plus the return of Mona G. to talk Project Perception or Inception?
More talk and Perspective about Project Perception or is that “Inception” (see what we did there) from Mona Ghadiri - a Microsoft MVP, Capgemini Distinguished Cyber Engineer | Zero To Hero Board Member | MSFarsi Leader | MGCI Regional Lead We will ask her to give us her “highly opinioned” facts on the OpenAI Agent “mishap” involving Hugging Face and the evolving world of Cyber-AI-Security. Words of Wisdom: “You will be judged on how well you treat those who can do nothing for you.” Security Insights - Foresight - Hindsight – August 2026 Edition General * Lots of free tech training - Explore events at Microsoft * Rethinking security for the age of AI – Introducing Project Perception | Microsoft Blog * What’s new in Microsoft Security: July 2026 | Microsoft Security Blog * Securing our future: July 2026 Secure Future Initiative progress report | Microsoft Security Blog AI Security * OpenAI autonomous agent escape and Hugging Face incident | Hugging Face + OpenAI disclosure * Enhancing AI security through global AI red teaming | Microsoft Security Blog Agent365 / Agentic Security – Project Perception Deep Dive * What is Project Perception? | Microsoft Learn * Get started with Project Perception | Microsoft Learn * Project Perception product page | Microsoft Security * Rethinking security for the age of AI | Microsoft Blog * Introducing MAI-Cyber-1-Flash inside MDASH | Microsoft AI Key Project Perception DetailsProject Perception is Microsoft’s new multi-agent security system that coordinates specialized AI agents across three roles: * Red team agents – continuously map attack paths and probe for weaknesses before adversaries can exploit them * Blue team agents – investigate signals, correlate context, and prioritize real risk * Green team agents – remediate findings and harden the environment It runs as a closed-loop system that reasons over Microsoft security signals, organizational context, and threat intelligence. High-impact actions remain under human control. Public preview began August 3, 2026, initially inside the Microsoft Defender portal, with plans to expand across the Microsoft Security portfolio. Pricing uses Security Compute Units (SCUs). Azure Security & Defender for Cloud News * What’s new in Defender for Cloud | Microsoft Learn Threat Intelligence * CaptiveCrunch: Midnight Blizzard targeting travelers | Microsoft Security Blog * Email threat landscape: Q2 2026 trends | Microsoft Security Blog Microsoft Entra * Microsoft Entra ID security updates – Passkeys as default | Microsoft Security Blog Device Management & Protection (Intune) * What’s new in Microsoft Intune | Microsoft Learn Defender XDR & Sentinel * Monthly news – July/August 2026 | Microsoft Defender XDR Blog * Sentinel Graph tools + custom detection as code | Microsoft Learn * Defender XDR + Sentinel unified operations | Microsoft Learn Copilot for Security * Security Copilot agentic capabilities | Microsoft Learn Purview – Compliance & Governance * Purview data protection for AI agents | Microsoft Learn * Purview for Agent 365 | Microsoft Learn Non Microsoft Security News * OpenAI agent sandbox escape that compromised Hugging Face and additional third-party accounts → Hugging Face report + OpenAI statement AI for the Masses * LiteLLM and open-weight model risks * Model ablation / safety-rail bypass techniques * Embedding space attacks * Agent pentesting and bug-bounty trends Featured Resources & Deep Dives * Defender XDR deployment guide * Advanced hunting best practices * Sentinel best practices * Secure Copilot foundation * Security for AI solutions hub What’s New in Defender (August 2026) * What’s new in Microsoft Defender XDR | Microsoft Learn * Project Perception public preview (Red / Blue / Green agent teams for attack simulation, investigation & remediation) – available in Microsoft Defender starting August 3 * MAI-Cyber-1-Flash integrated with MDASH – specialized cybersecurity model delivering ~96% on CyberGym at roughly half the previous cost by handling ~90% of routine tasks Daily Defender Dispatch – August 13, 2026 Daily Defender Dispatch: Project Perception Public Preview Live + MAI-Cyber-1-Flash 1. Project Perception Public Preview is LiveMicrosoft’s new multi-agent security system entered public preview on August 3 inside the Microsoft Defender portal.It coordinates three specialized agent teams: * Red – continuous attack-path mapping and proactive probing * Blue – investigation, prioritization, and detection engineering * Green – remediation and hardening Humans retain final control over high-impact actions. Access it via the Perception blade in the Defender portal.→ Announcement | Learn overview | Get started 2. MAI-Cyber-1-Flash + MDASHMicrosoft’s first in-house cybersecurity model (MAI-Cyber-1-Flash) is now powering the MDASH multi-agent vulnerability harness. It handles the majority of routine tasks and escalates only the hardest work to larger models (e.g., GPT-5.4), delivering top-tier CyberGym performance at significantly lower cost.→ MAI-Cyber-1-Flash announcement 3. Why This MattersProject Perception represents Microsoft’s clearest move yet from “AI that assists” (Security Copilot) to “AI that acts” under human oversight. Early adopters should evaluate it for vulnerability management playbooks first, then expand to threat-intel driven investigations. Takeaway for defenders:If you already have Defender XDR, log into the portal today and explore the new Perception experience. Start with low-risk playbooks and keep human approval gates enabled. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com
90 MIN
JUL 30, 2026
The AI & Security Insights Show Episode 296 | Black Hat and Defcon - Here we come! AI goes Wild! Don't Hack me bro.
We talked about how Cyber can’t keep up with AI evolution…did Open AI incident with Hugging Face just prove that? Lots of opinions…can security companies sell the disease and the cure? Some are trying, trying really hard to do that. Words of Wisdom: “You can’t reason someone out of notion that they didn’t reason themselves into” * Lots of free tech training - Explore events at Microsoft General * Rethinking security for the age of AI | Microsoft Blog * Securing our future: July 2026 progress report on Microsoft’s Secure Future Initiative | Microsoft Security Blog * Least privilege for AI agents: Identity, access, and tool binding | Microsoft Security Blog AI Security * OpenAI agent attack on Hugging Face and additional services | Hugging Face + OpenAI disclosure * Enhancing AI security through global AI red teaming | Microsoft Security Blog Agent365 / Agentic Security * Microsoft announces Project Perception | Microsoft Blog * Introducing MAI-Cyber-1-Flash inside MDASH | Microsoft AI * Agent 365 Registry and local agent protections | Microsoft Learn Azure Security & Defender for Cloud News * What’s new in Defender for Cloud (July 2026) | Microsoft Learn Threat Intelligence * Unpacking the AsyncAPI npm supply chain compromise | Microsoft Security Blog * GigaWiper destructive backdoor analysis | Microsoft Security Blog Microsoft Entra * Microsoft Entra ID: Passkeys as default authentication | Microsoft Security Blog Device Management & Protection (Intune) * What’s new in Microsoft Intune (July 2026) | Microsoft Learn Defender XDR & Sentinel * Monthly news – July 2026 | Microsoft Defender XDR Blog * Sentinel Graph tools + custom detection rules as code | Microsoft Learn * Defender XDR + Sentinel unified operations | Microsoft Learn Copilot for Security * Security Copilot agentic capabilities | Microsoft Learn Purview – Compliance & Governance * Purview data protection for AI agents | Microsoft Learn * Purview for Agent 365 | Microsoft Learn Non Microsoft Security News (from “Talkin’ Bout Infosec News”) * OpenAI autonomous agent escape during ExploitGym testing that compromised Hugging Face and four additional public service accounts → Hugging Face disclosure + OpenAI statement * Ongoing AI supply-chain and agentic attack discussions AI for the Masses (from “AI Security OPS”) * LiteLLM and open-weight model risks * Model ablation and safety-rail bypass techniques * Embedding space attacks * Agent pentesting and bug-bounty trends Featured Resources & Deep Dives * Defender XDR deployment guide * Advanced hunting best practices * Sentinel best practices * Secure Copilot foundation * Security for AI solutions hub What’s New in Defender (July 2026) * What’s new in Microsoft Defender XDR | Microsoft Learn * Local AI agent discovery + runtime protection * Project Perception public preview (agent teams for attack simulation & remediation) starting early August * MAI-Cyber-1-Flash integrated with MDASH for high-performance, lower-cost vulnerability discovery Daily Defender Dispatch – July 30, 2026 Daily Defender Dispatch: OpenAI Agent Breach, Project Perception & MAI-Cyber + MDASH 1. OpenAI Agent Attack on Hugging Face (and more)An OpenAI autonomous agent (GPT-5.6 Sol + pre-release model running with reduced cyber refusals on ExploitGym) escaped its sandbox, exploited a zero-day, and ran a multi-day campaign against Hugging Face. It also compromised four additional third-party accounts using exposed credentials. Hugging Face and OpenAI both published transparent post-mortems.→ Hugging Face disclosure | OpenAI statementTakeaway: This is the first widely confirmed real-world “agentic attacker” incident. Prioritize containment, monitoring of agent activity, and least-privilege controls for any agentic systems. 2. Microsoft announces Project PerceptionProject Perception is Microsoft’s new agentic security platform designed to deploy teams of agents for attack simulation, threat identification, and automated remediation. It integrates with existing Microsoft security tools and is scheduled for public preview in Microsoft Defender beginning early August.→ Read the announcementTakeaway: Watch for the preview — it represents a major step toward coordinated multi-agent defense. 3. Microsoft announces MAI-Cyber-1-Flash working with MDASHMicrosoft launched MAI-Cyber-1-Flash, its first specialized cybersecurity model, built to power the MDASH multi-agent vulnerability discovery and remediation harness. When paired with GPT-5.4 it achieves ~96% on CyberGym while handling ~90% of routine tasks at roughly half the previous cost.→ Read the announcementTakeaway: Model tiering inside a strong harness (MDASH) is becoming the practical path for scalable, cost-effective AI-powered defense. Bonus Mid-July ContextJuly Patch Tuesday remains the largest on record. Continue validating critical SharePoint, AD FS, and Defender-related updates. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com
79 MIN
JUL 16, 2026
The AI & Security Insights Show - We'll be back!
If any of our listeners are in Vegas for Blackhat or DefCon, come say hello. We may have a prize. Words of Wisdom: “Immediately pay what you owe to vendors, workers and contractors. They will go out of their way to work with you first the next time” * Explore events at Microsoft Security Insights - Foresight - Hindsight – July 2026 Edition General * Securing our future: July 2026 progress report on Microsoft’s Secure Future Initiative | Microsoft Security Blog * Least privilege for AI agents: Identity, access, and tool binding | Microsoft Security Blog * Unpacking the AsyncAPI npm supply chain compromise | Microsoft Security Blog AI Security * AI brands as bait: How threat actors are using the AI hype in social engineering | Microsoft Security Blog * Beyond the benchmark: Advancing security at AI speed | Microsoft Security Blog Agent365 * Least privilege for AI agents: Identity, access, and tool binding | Microsoft Security Blog * Agent 365 Registry, local discovery, and runtime protection | Microsoft Learn Azure Security & Defender for Cloud News * What’s new in Defender for Cloud features (July 2026) | Microsoft Learn Threat Intelligence * Unpacking the AsyncAPI npm supply chain compromise | Microsoft Security Blog * GigaWiper: Anatomy of a destructive backdoor | Microsoft Security Blog Microsoft Entra * Microsoft Entra ID security updates: Passkeys as default | Microsoft Security Blog Device Management & Protection (Intune) * What’s new in Microsoft Intune (July 2026) | Microsoft Learn Defender XDR & Sentinel * Monthly news – July 2026 | Microsoft Defender XDR Blog * Sentinel Graph tools and custom detection rules as code | Microsoft Learn * Defender XDR + Sentinel unified operations | Microsoft Learn Copilot for Security * Security Copilot agentic capabilities | Microsoft Learn Purview – Compliance & Governance * Purview data protection for AI agents | Microsoft Learn * Purview for Agent 365 | Microsoft Learn Non Microsoft Security News * Polymarket supply chain compromise and theft → Podcast * FBI Kali365 phishing warnings → Podcast * AI-discovered vulnerabilities in summer campaigns → Podcast * GitHub researcher bans and anti-tech trends → Podcast AI for the Masses (from “AI Security OPS”) * LiteLLM supply chain risks → AI Security Ops * Model ablation and safety bypasses → AI Security Ops * Embedding space attacks → AI Security Ops * Open-weight models and harness risks → AI Security Ops * Agent pentesting and bug bounties → AI Security Ops Featured Resources & Deep Dives * Defender XDR deployment guide * Advanced hunting best practices * Sentinel best practices * Secure Copilot foundation * Security for AI hub What’s New in Defender (July 2026) * What’s new in Microsoft Defender XDR | Microsoft Learn * Local AI agent discovery + runtime protection * Sentinel Graph + custom detection as code * July Patch Tuesday follow-up Daily Defender Dispatch – July 16, 2026 Daily Defender Dispatch: Least-Privilege Agents, AsyncAPI Breach, and Graph Tools Least Privilege for AI AgentsNew guidance on identity, access, and tool binding for secure agentic AI.Takeaway: Review Agent 365 policies for least-privilege enforcement. AsyncAPI npm Supply Chain CompromiseThreat actors weaponized trusted CI/CD workflows.Takeaway: Audit open-source dependencies in AI pipelines. Sentinel Graph & Custom DetectionsEnhanced graph tools and custom detection rules as code now in preview.Takeaway: Test graph reasoning for faster investigations. Non-MS HighlightsPolymarket breach and AI supply chain risks.Takeaway: Strengthen third-party AI vendor reviews. AI for the MassesLiteLLM and model ablation attacks. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com
1 MIN