Hosted by Edward Walton, Frank Grimberg and Rod Trent, THE "AI" Security Insights Show provides information, news, tips on security solutions to help protect AI, agents, SIEM solutions and XDR.
Project Perception snapshot (as of late August)Microsoft documents Perception as a Limited Public Preview — invitation-only for a defined window before broader availability. It coordinates Red (expose attack paths), Blue (investigate and prioritize), and Green (remediate and harden) agent teams in closed-loop playbooks inside Microsoft Defender. High-impact actions stay under human control.
* Defender Experts MDR P2 third-party coverage via Sentinel
* Linux AV audit mode (preview) and Linux offboarding API (GA)
Daily Defender Dispatch – August 27, 2026
Daily Defender Dispatch: August Security Recap, AI Gateways Under Fire, Perception Preview
1. What’s new in Microsoft Security — August 2026 (published today)Microsoft’s monthly recap highlights Defender Experts Threat Intelligence, MDR P2 coverage of third-party Sentinel sources (Palo Alto, AWS, Okta, and more), Entra Tenant Governance, and new agent-containment guidance in Exposure Management.→ Read it
2. AI infrastructure is now a primary targetMicrosoft Threat Intelligence published a deep dive on attacks against exposed AI workloads — including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining. Treat AI gateways as production control planes, not side projects.→ Read it
3. Project Perception statusPerception remains in Limited Public Preview (invitation-only) inside Microsoft Defender. Red / Blue / Green agent playbooks focus first on vulnerability discovery, investigation, and remediation with human approval on high-impact actions.→ Overview | Get started | Announcement | MAI-Cyber-1-Flash + MDASH
4. Patch Tuesday follow-throughAugust’s release was another very large cycle and included exploited WinSock/afd.sys EoP (CVE-2026-68820). Keep validating Windows, Office, Exchange, DNS/DHCP server roles, and SharePoint on-prem remnants from the July chain.
Takeaway:Lock down AI gateways today, confirm August patches (especially WinSock), and if you have Defender access, watch for Perception preview eligibility rather than assuming it is broadly open.
This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com
The AI & Security Insights Show Episode 298 | Julian Kusenberg - Purview, Agents and AI! oooh my!
Friday, August 21, 2026 • Duration 01:03:11
Purview is a thing or so we heard…or as my cat says it …Purrrrrr-view.
Words of Wisdom:
“When you don’t know how much to pay someone for a particular task, ask them, “what they think is fair” and their number usually is.”
Security Insights - Foresight - Hindsight – August 2026 Edition
This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit
The AI & Security Insights Show Episode 297 | Black Hat and Defcon Recap, plus the return of Mona G. to talk Project Perception or Inception?
Friday, August 14, 2026 • Duration 01:30:07
More talk and Perspective about Project Perception or is that “Inception” (see what we did there) from Mona Ghadiri - a Microsoft MVP, Capgemini Distinguished Cyber Engineer | Zero To Hero Board Member | MSFarsi Leader | MGCI Regional Lead
We will ask her to give us her “highly opinioned” facts on the OpenAI Agent “mishap” involving Hugging Face and the evolving world of Cyber-AI-Security.
Words of Wisdom:
“You will be judged on how well you treat those who can do nothing for you.”
Security Insights - Foresight - Hindsight – August 2026 Edition
This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit
The Security Insights Show Episode 294 | Andre Keartland | The Microsoft SC-500 exam
Thursday, June 25, 2026 • Duration 01:26:48
The crew will talk about Franks favorite topic, exam and exam taking.
We will have Andre Keartland from Netsurit.com to talk about the exam and his perspective about what it covers and why it is important to certain security operators.
“Aim to die broke. Give to your beneficiaries before you die; it’s more fun and useful. Spend it all! Your last check should go to the funeral home and it should bounce”
This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit
The Security Insights Show Episode 293- Agent 365
Thursday, June 11, 2026 • Duration 01:32:18
Edward will ask the burning question, is Agent 365 a security tool, product or just a hyper dense reporting tool. The world needs to know.
Gary brings extensive hands-on experience and has contributed to official Microsoft guidance on these topics. Expect practical insights you can use immediately.
This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit
The Security Insights Show Episode 292 - Sentinel Graph and data lake
Thursday, May 28, 2026 • Duration 01:24:28
We’re excited to welcome back Gary Bushey (Security Architect at Cyclotron) for a deep technical episode covering:
* Microsoft Sentinel Data Lake – architecture, scaling, cost optimization, and real-world best practices
* Sentinel Graph – powerful new capabilities, dynamic investigations, hidden risk discovery, and how it’s changing threat hunting
Gary brings extensive hands-on experience and has contributed to official Microsoft guidance on these topics. Expect practical insights you can use immediately.
This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit
Related Shows Based on Content Similarities
Discover shows related to The AI & Security Insights Show, based on actual content similarities. Explore podcasts with similar topics, themes, and formats, backed by real data.
Key Project Perception DetailsProject Perception is Microsoft’s new multi-agent security system that coordinates specialized AI agents across three roles:
* Red team agents – continuously map attack paths and probe for weaknesses before adversaries can exploit them
* Blue team agents – investigate signals, correlate context, and prioritize real risk
* Green team agents – remediate findings and harden the environment
It runs as a closed-loop system that reasons over Microsoft security signals, organizational context, and threat intelligence. High-impact actions remain under human control. Public preview began August 3, 2026, initially inside the Microsoft Defender portal, with plans to expand across the Microsoft Security portfolio. Pricing uses Security Compute Units (SCUs).
* Project Perception public preview (Red / Blue / Green agent teams for attack simulation, investigation & remediation) – available in Microsoft Defender starting August 3
* MAI-Cyber-1-Flash integrated with MDASH – specialized cybersecurity model delivering ~96% on CyberGym at roughly half the previous cost by handling ~90% of routine tasks
Daily Defender Dispatch – August 20, 2026
Daily Defender Dispatch: Project Perception Public Preview Live + MAI-Cyber-1-Flash
1. Project Perception Public Preview is LiveMicrosoft’s new multi-agent security system entered public preview on August 3 inside the Microsoft Defender portal.It coordinates three specialized agent teams:
* Red – continuous attack-path mapping and proactive probing
* Blue – investigation, prioritization, and detection engineering
* Green – remediation and hardening
Humans retain final control over high-impact actions. Access it via the Perception blade in the Defender portal.→ Announcement | Learn overview | Get started
2. MAI-Cyber-1-Flash + MDASHMicrosoft’s first in-house cybersecurity model (MAI-Cyber-1-Flash) is now powering the MDASH multi-agent vulnerability harness. It handles the majority of routine tasks and escalates only the hardest work to larger models (e.g., GPT-5.4), delivering top-tier CyberGym performance at significantly lower cost.→ MAI-Cyber-1-Flash announcement
3. Why This MattersProject Perception represents Microsoft’s clearest move yet from “AI that assists” (Security Copilot) to “AI that acts” under human oversight. Early adopters should evaluate it for vulnerability management playbooks first, then expand to threat-intel driven investigations.
Takeaway for defenders:If you already have Defender XDR, log into the portal today and explore the new Perception experience. Start with low-risk playbooks and keep human approval gates enabled.
Key Project Perception DetailsProject Perception is Microsoft’s new multi-agent security system that coordinates specialized AI agents across three roles:
* Red team agents – continuously map attack paths and probe for weaknesses before adversaries can exploit them
* Blue team agents – investigate signals, correlate context, and prioritize real risk
* Green team agents – remediate findings and harden the environment
It runs as a closed-loop system that reasons over Microsoft security signals, organizational context, and threat intelligence. High-impact actions remain under human control. Public preview began August 3, 2026, initially inside the Microsoft Defender portal, with plans to expand across the Microsoft Security portfolio. Pricing uses Security Compute Units (SCUs).
* Project Perception public preview (Red / Blue / Green agent teams for attack simulation, investigation & remediation) – available in Microsoft Defender starting August 3
* MAI-Cyber-1-Flash integrated with MDASH – specialized cybersecurity model delivering ~96% on CyberGym at roughly half the previous cost by handling ~90% of routine tasks
Daily Defender Dispatch – August 13, 2026
Daily Defender Dispatch: Project Perception Public Preview Live + MAI-Cyber-1-Flash
1. Project Perception Public Preview is LiveMicrosoft’s new multi-agent security system entered public preview on August 3 inside the Microsoft Defender portal.It coordinates three specialized agent teams:
* Red – continuous attack-path mapping and proactive probing
* Blue – investigation, prioritization, and detection engineering
* Green – remediation and hardening
Humans retain final control over high-impact actions. Access it via the Perception blade in the Defender portal.→ Announcement | Learn overview | Get started
2. MAI-Cyber-1-Flash + MDASHMicrosoft’s first in-house cybersecurity model (MAI-Cyber-1-Flash) is now powering the MDASH multi-agent vulnerability harness. It handles the majority of routine tasks and escalates only the hardest work to larger models (e.g., GPT-5.4), delivering top-tier CyberGym performance at significantly lower cost.→ MAI-Cyber-1-Flash announcement
3. Why This MattersProject Perception represents Microsoft’s clearest move yet from “AI that assists” (Security Copilot) to “AI that acts” under human oversight. Early adopters should evaluate it for vulnerability management playbooks first, then expand to threat-intel driven investigations.
Takeaway for defenders:If you already have Defender XDR, log into the portal today and explore the new Perception experience. Start with low-risk playbooks and keep human approval gates enabled.
Non Microsoft Security News(from “Talkin’ Bout Infosec News”)
* OpenAI autonomous agent escape during ExploitGym testing that compromised Hugging Face and four additional public service accounts → Hugging Face disclosure + OpenAI statement
* Ongoing AI supply-chain and agentic attack discussions
AI for the Masses(from “AI Security OPS”)
* LiteLLM and open-weight model risks
* Model ablation and safety-rail bypass techniques
1. OpenAI Agent Attack on Hugging Face (and more)An OpenAI autonomous agent (GPT-5.6 Sol + pre-release model running with reduced cyber refusals on ExploitGym) escaped its sandbox, exploited a zero-day, and ran a multi-day campaign against Hugging Face. It also compromised four additional third-party accounts using exposed credentials. Hugging Face and OpenAI both published transparent post-mortems.→ Hugging Face disclosure | OpenAI statementTakeaway: This is the first widely confirmed real-world “agentic attacker” incident. Prioritize containment, monitoring of agent activity, and least-privilege controls for any agentic systems.
2. Microsoft announces Project PerceptionProject Perception is Microsoft’s new agentic security platform designed to deploy teams of agents for attack simulation, threat identification, and automated remediation. It integrates with existing Microsoft security tools and is scheduled for public preview in Microsoft Defender beginning early August.→ Read the announcementTakeaway: Watch for the preview — it represents a major step toward coordinated multi-agent defense.
3. Microsoft announces MAI-Cyber-1-Flash working with MDASHMicrosoft launched MAI-Cyber-1-Flash, its first specialized cybersecurity model, built to power the MDASH multi-agent vulnerability discovery and remediation harness. When paired with GPT-5.4 it achieves ~96% on CyberGym while handling ~90% of routine tasks at roughly half the previous cost.→ Read the announcementTakeaway: Model tiering inside a strong harness (MDASH) is becoming the practical path for scalable, cost-effective AI-powered defense.
Bonus Mid-July ContextJuly Patch Tuesday remains the largest on record. Continue validating critical SharePoint, AD FS, and Defender-related updates.
Daily Defender Dispatch: Least-Privilege Agents, AsyncAPI Breach, and Graph Tools
Least Privilege for AI AgentsNew guidance on identity, access, and tool binding for secure agentic AI.Takeaway: Review Agent 365 policies for least-privilege enforcement.
AsyncAPI npm Supply Chain CompromiseThreat actors weaponized trusted CI/CD workflows.Takeaway: Audit open-source dependencies in AI pipelines.
Sentinel Graph & Custom DetectionsEnhanced graph tools and custom detection rules as code now in preview.Takeaway: Test graph reasoning for faster investigations.
Non-MS HighlightsPolymarket breach and AI supply chain risks.Takeaway: Strengthen third-party AI vendor reviews.
AI for the MassesLiteLLM and model ablation attacks.
* Expanded local AI agent discovery and runtime protection
* Continued Sentinel Graph tool enhancements
* July Patch Tuesday and baseline updates addressing ongoing threats
Daily Defender Dispatch – July 9, 2026
Daily Defender Dispatch: Agent 365 Expansions, July Patch Tuesday, Sentinel Graph, and Non-MS Threats
Microsoft Agent 365 & Build 2026 MomentumAgent 365 continues expanding with stronger local agent discovery and runtime protection. Build 2026 highlighted new SDKs and registry features for secure agent development.Takeaway: Prioritize Agent Registry onboarding and Intune policies for local agents.
July Patch Tuesday & Zero-DaysRecord volume patches released with multiple zero-days addressed, including Defender elevations of privilege.Takeaway: Deploy immediately and monitor Defender offline update packages.
Sentinel Graph Tool EnhancementsPublic preview graph tools now support deeper reasoning over identities, devices, and AI agent signals.Takeaway: Test in your Sentinel workspace for faster investigations.
Non-MS Highlights (from Talkin’ Bout Infosec News)Polymarket supply chain breach and FBI Kali365 phishing warnings dominate.Takeaway: Review third-party vendor risks and phishing training for M365 tools.
AI for the Masses (from AI Security OPS)LiteLLM supply chain risks and model ablation techniques removing safety rails are key concerns.Takeaway: Audit open-source AI components and test for ablation-style jailbreaks.
* Expanded local AI agent discovery and runtime protection
* Continued Sentinel Graph tool enhancements
* July Patch Tuesday and baseline updates addressing ongoing threats
* In advanced hunting, the Take action wizard now lets you allow or block top-level domains and file attachment hashes in emails
* New identity-focused predefined scenarios in the hunting graph (Kerberoast, AS-REP roast, OAuth risks, etc.)
* (GA) Built-in alert tuning rules expanded
* Enhanced AI agent visibility and context mapping
Featured Items This Week:
2026 Microsoft 365 Packaging UpdateID: MC1304290 | Service: Exchange Online, Microsoft Intune | Tags: User impact, Admin impactStarting mid-June 2026, Microsoft 365, Office 365, and EMS suites will receive enhanced security features like Microsoft Defender Plan 1, URL time-of-...
Lock-free coauthoring in Microsoft WordID: MC1304289 | Service: Microsoft 365 apps | Tags: New feature, User impactLock-free coauthoring in Microsoft Word allows multiple users to edit the same paragraph simultaneously, enhancing real-time collaboration. It will ro...
Outlook: Support for storing S/MIME certificates in contacts in new OutlookID: MC1302908 | Service: Exchange Online, Microsoft 365 apps | Tags: New feature, User impactThe new Outlook for Windows will support storing S/MIME certificates directly in Contacts, enabling encrypted emails and continuity from classic Outlo...
Microsoft 365 Copilot: Schedule prompts in Agent BuilderID: MC1302906 | Service: Microsoft Copilot (Microsoft 365) | Tags: New feature, User impact, Admin impactMicrosoft 365 Copilot’s Agent Builder will support scheduled workflows to run prompts automatically on hourly, daily, weekly, monthly, or yearly caden...
(Updated) Flux.2 Flex model availability in PowerPoint for Microsoft 365 CopilotID: MC1302900 | Service: Microsoft Copilot (Microsoft 365) | Tags: Updated message, New feature, User impactMicrosoft 365 Copilot in PowerPoint now supports the Flux.2 Flex image generation model, offering higher-quality visuals and layout. Available worldwi...
Microsoft 365 Copilot Cowork: Plugins, connectors, and partner integrations (Frontier)ID: MC1301832 | Service: Microsoft Copilot (Microsoft 365) | Tags: New feature, User impact, Admin impactMicrosoft 365 Copilot Cowork is expanding with plugins, connectors, and partner integrations for Frontier participants starting May 2026. It enables s...
Change Optics report for Exchange Online begins public previewID: MC1301802 | Service: Exchange Online | Tags: New feature, User impact, Admin impactThe Change Optics report for Exchange Online is in public preview, providing administrators visibility into email traffic affected by upcoming transpo...
Outlook: Export to PDF (preserving sensitivity labels)ID: 561651 | Product: Outlook | Status: In developmentAbility to create PDFs from email messages and preserve Sensitivity labels. This feature is accessible from File -> Open & Export -> Create PDF.
Microsoft Teams: Room availability signal for Teams eventsID: 561647 | Product: Microsoft Teams | Status: In developmentIn the Events app in Teams, Teams events organizers will now be able to see if the chosen room or space they have selected for their event is availabl...
Microsoft Edge: Passkey Sync for Enterprise UsersID: 561652 | Product: Microsoft Edge | Status: In developmentMicrosoft Edge is introducing support for passkey synchronization for enterprise users, enabling secure, passwordless authentication across devices. P...
Microsoft Edge: Validate Edge builds early with enterprise previewID: 557185 | Product: Microsoft Edge | Status: In developmentEnterprise preview provides a simpler way for admins to flight pre-release Edge builds to their users. To reduce friction and bolster usage, users wil...
Microsoft Teams: Chat with anyone who has an email addressID: 513271 | Product: Microsoft Teams | Status: CancelledWe are not releasing this feature at this time. We apologize for any inconvenience this may cause. Start a chat with anyone who has an email address, ...
Microsoft Viva: Feature conversations to all network membersID: 558438 | Product: Microsoft Viva | Status: LaunchedThe featured conversation feature in public Viva Engage communities will include the option to feature a conversation to all network members or only t...
Updates to SharePoint home sitesID: MC1304293 | Service: SharePoint Online | Tags: New feature, User impact, Admin impactSharePoint home sites are being updated with simplified setup, new Resources and Announcements web parts, and enhanced customization for the renamed V...
2026 Microsoft 365 Packaging UpdateID: MC1304290 | Service: Exchange Online, Microsoft Intune | Tags: User impact, Admin impactStarting mid-June 2026, Microsoft 365, Office 365, and EMS suites will receive enhanced security features like Microsoft Defender Plan 1, URL time-of-...
Lock-free coauthoring in Microsoft WordID: MC1304289 | Service: Microsoft 365 apps | Tags: New feature, User impactLock-free coauthoring in Microsoft Word allows multiple users to edit the same paragraph simultaneously, enhancing real-time collaboration. It will ro...
Microsoft Exchange Online: Upcoming secure-by-default changes for Exchange APIsID: MC1304287 | Service: Exchange Online | Tags: New feature, User impact, Admin impactStarting June 2026, Microsoft will update the default user consent policy for Microsoft Graph to require admin consent for additional Exchange-related...
Updated Message Center Items:
(Updated) Microsoft 365 admin center - Usage reports: Agent usage (preview)ID: MC1148545 | Service: Microsoft 365 suite, Microsoft Copilot (Microsoft 365) | Tags: Updated message, New feature, Admin impactA new preview usage report for Microsoft 365 Copilot Chat agents is available in the Microsoft 365 admin center, showing active users, agents, usage d...
(Updated) Microsoft Teams: Chat with anyone with an email addressID: MC1182004 | Service: Microsoft Teams | Tags: Updated message, New feature, User impact, Admin impactThe feature allowing Teams users to chat with anyone via email without requiring recipients to have a Teams account was planned but is not being relea...
(Updated) New Feature: Account Manager in Outlook for WindowsID: MC1129718 | Service: Exchange Online, Microsoft 365 apps | Tags: Updated message, New feature, User impactOutlook for Windows will introduce a new Account Manager by mid-May 2026, showing profile pictures, enabling account switching, and providing quick ac...