The Security Insights Show

Rod Trent

Hosted by Edward Walton, Frank Grimberg and Rod Trent, THE "AI" Security Insights Show provides information, news, tips on security solutions to help protect AI, agents, SIEM solutions and XDR. www.microsoftsecurityinsights.com

  1. 3d ago

    The AI & Security Insights Show Episode 298 | Julian Kusenberg - Purview, Agents and AI! oooh my!

    Purview is a thing or so we heard…or as my cat says it …Purrrrrr-view. Words of Wisdom: “When you don’t know how much to pay someone for a particular task, ask them, “what they think is fair” and their number usually is.” Security Insights - Foresight - Hindsight – August 2026 Edition General * Lots of free tech training - Explore events at Microsoft * Rethinking security for the age of AI – Introducing Project Perception | Microsoft Blog * What’s new in Microsoft Security: July 2026 | Microsoft Security Blog * Securing our future: July 2026 Secure Future Initiative progress report | Microsoft Security Blog AI Security * OpenAI autonomous agent escapes and Hugging Face incident | Hugging Face + OpenAI disclosure * Enhancing AI security through global AI red teaming | Microsoft Security Blog Agent365 / Agentic Security – Project Perception Deep Dive * What is Project Perception? | Microsoft Learn * Get started with Project Perception | Microsoft Learn * Project Perception product page | Microsoft Security * Rethinking security for the age of AI | Microsoft Blog * Introducing MAI-Cyber-1-Flash inside MDASH | Microsoft AI Key Project Perception DetailsProject Perception is Microsoft’s new multi-agent security system that coordinates specialized AI agents across three roles: * Red team agents – continuously map attack paths and probe for weaknesses before adversaries can exploit them * Blue team agents – investigate signals, correlate context, and prioritize real risk * Green team agents – remediate findings and harden the environment It runs as a closed-loop system that reasons over Microsoft security signals, organizational context, and threat intelligence. High-impact actions remain under human control. Public preview began August 3, 2026, initially inside the Microsoft Defender portal, with plans to expand across the Microsoft Security portfolio. Pricing uses Security Compute Units (SCUs). Azure Security & Defender for Cloud News * What’s new in Defender for Cloud | Microsoft Learn Threat Intelligence * CaptiveCrunch: Midnight Blizzard targeting travelers | Microsoft Security Blog * Email threat landscape: Q2 2026 trends | Microsoft Security Blog Microsoft Entra * Microsoft Entra ID security updates – Passkeys as default | Microsoft Security Blog Device Management & Protection (Intune) * What’s new in Microsoft Intune | Microsoft Learn Defender XDR & Sentinel * Monthly news – July/August 2026 | Microsoft Defender XDR Blog * Sentinel Graph tools + custom detection as code | Microsoft Learn * Defender XDR + Sentinel unified operations | Microsoft Learn Copilot for Security * Security Copilot agentic capabilities | Microsoft Learn Purview – Compliance & Governance * Purview data protection for AI agents | Microsoft Learn * Purview for Agent 365 | Microsoft Learn Non Microsoft Security News * OpenAI agent sandbox escape that compromised Hugging Face and additional third-party accounts → Hugging Face report + OpenAI statement AI for the Masses * LiteLLM and open-weight model risks * Model ablation / safety-rail bypass techniques * Embedding space attacks * Agent pentesting and bug-bounty trends Featured Resources & Deep Dives * Defender XDR deployment guide * Advanced hunting best practices * Sentinel best practices * Secure Copilot foundation * Security for AI solutions hub What’s New in Defender (August 2026) * What’s new in Microsoft Defender XDR | Microsoft Learn * Project Perception public preview (Red / Blue / Green agent teams for attack simulation, investigation & remediation) – available in Microsoft Defender starting August 3 * MAI-Cyber-1-Flash integrated with MDASH – specialized cybersecurity model delivering ~96% on CyberGym at roughly half the previous cost by handling ~90% of routine tasks Daily Defender Dispatch – August 20, 2026 Daily Defender Dispatch: Project Perception Public Preview Live + MAI-Cyber-1-Flash 1. Project Perception Public Preview is LiveMicrosoft’s new multi-agent security system entered public preview on August 3 inside the Microsoft Defender portal.It coordinates three specialized agent teams: * Red – continuous attack-path mapping and proactive probing * Blue – investigation, prioritization, and detection engineering * Green – remediation and hardening Humans retain final control over high-impact actions. Access it via the Perception blade in the Defender portal.→ Announcement | Learn overview | Get started 2. MAI-Cyber-1-Flash + MDASHMicrosoft’s first in-house cybersecurity model (MAI-Cyber-1-Flash) is now powering the MDASH multi-agent vulnerability harness. It handles the majority of routine tasks and escalates only the hardest work to larger models (e.g., GPT-5.4), delivering top-tier CyberGym performance at significantly lower cost.→ MAI-Cyber-1-Flash announcement 3. Why This MattersProject Perception represents Microsoft’s clearest move yet from “AI that assists” (Security Copilot) to “AI that acts” under human oversight. Early adopters should evaluate it for vulnerability management playbooks first, then expand to threat-intel driven investigations. Takeaway for defenders:If you already have Defender XDR, log into the portal today and explore the new Perception experience. Start with low-risk playbooks and keep human approval gates enabled. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com

  2. Aug 14

    The AI & Security Insights Show Episode 297 | Black Hat and Defcon Recap, plus the return of Mona G. to talk Project Perception or Inception?

    More talk and Perspective about Project Perception or is that “Inception” (see what we did there) from Mona Ghadiri - a Microsoft MVP, Capgemini Distinguished Cyber Engineer | Zero To Hero Board Member | MSFarsi Leader | MGCI Regional Lead We will ask her to give us her “highly opinioned” facts on the OpenAI Agent “mishap” involving Hugging Face and the evolving world of Cyber-AI-Security. Words of Wisdom: “You will be judged on how well you treat those who can do nothing for you.” Security Insights - Foresight - Hindsight – August 2026 Edition General * Lots of free tech training - Explore events at Microsoft * Rethinking security for the age of AI – Introducing Project Perception | Microsoft Blog * What’s new in Microsoft Security: July 2026 | Microsoft Security Blog * Securing our future: July 2026 Secure Future Initiative progress report | Microsoft Security Blog AI Security * OpenAI autonomous agent escape and Hugging Face incident | Hugging Face + OpenAI disclosure * Enhancing AI security through global AI red teaming | Microsoft Security Blog Agent365 / Agentic Security – Project Perception Deep Dive * What is Project Perception? | Microsoft Learn * Get started with Project Perception | Microsoft Learn * Project Perception product page | Microsoft Security * Rethinking security for the age of AI | Microsoft Blog * Introducing MAI-Cyber-1-Flash inside MDASH | Microsoft AI Key Project Perception DetailsProject Perception is Microsoft’s new multi-agent security system that coordinates specialized AI agents across three roles: * Red team agents – continuously map attack paths and probe for weaknesses before adversaries can exploit them * Blue team agents – investigate signals, correlate context, and prioritize real risk * Green team agents – remediate findings and harden the environment It runs as a closed-loop system that reasons over Microsoft security signals, organizational context, and threat intelligence. High-impact actions remain under human control. Public preview began August 3, 2026, initially inside the Microsoft Defender portal, with plans to expand across the Microsoft Security portfolio. Pricing uses Security Compute Units (SCUs). Azure Security & Defender for Cloud News * What’s new in Defender for Cloud | Microsoft Learn Threat Intelligence * CaptiveCrunch: Midnight Blizzard targeting travelers | Microsoft Security Blog * Email threat landscape: Q2 2026 trends | Microsoft Security Blog Microsoft Entra * Microsoft Entra ID security updates – Passkeys as default | Microsoft Security Blog Device Management & Protection (Intune) * What’s new in Microsoft Intune | Microsoft Learn Defender XDR & Sentinel * Monthly news – July/August 2026 | Microsoft Defender XDR Blog * Sentinel Graph tools + custom detection as code | Microsoft Learn * Defender XDR + Sentinel unified operations | Microsoft Learn Copilot for Security * Security Copilot agentic capabilities | Microsoft Learn Purview – Compliance & Governance * Purview data protection for AI agents | Microsoft Learn * Purview for Agent 365 | Microsoft Learn Non Microsoft Security News * OpenAI agent sandbox escape that compromised Hugging Face and additional third-party accounts → Hugging Face report + OpenAI statement AI for the Masses * LiteLLM and open-weight model risks * Model ablation / safety-rail bypass techniques * Embedding space attacks * Agent pentesting and bug-bounty trends Featured Resources & Deep Dives * Defender XDR deployment guide * Advanced hunting best practices * Sentinel best practices * Secure Copilot foundation * Security for AI solutions hub What’s New in Defender (August 2026) * What’s new in Microsoft Defender XDR | Microsoft Learn * Project Perception public preview (Red / Blue / Green agent teams for attack simulation, investigation & remediation) – available in Microsoft Defender starting August 3 * MAI-Cyber-1-Flash integrated with MDASH – specialized cybersecurity model delivering ~96% on CyberGym at roughly half the previous cost by handling ~90% of routine tasks Daily Defender Dispatch – August 13, 2026 Daily Defender Dispatch: Project Perception Public Preview Live + MAI-Cyber-1-Flash 1. Project Perception Public Preview is LiveMicrosoft’s new multi-agent security system entered public preview on August 3 inside the Microsoft Defender portal.It coordinates three specialized agent teams: * Red – continuous attack-path mapping and proactive probing * Blue – investigation, prioritization, and detection engineering * Green – remediation and hardening Humans retain final control over high-impact actions. Access it via the Perception blade in the Defender portal.→ Announcement | Learn overview | Get started 2. MAI-Cyber-1-Flash + MDASHMicrosoft’s first in-house cybersecurity model (MAI-Cyber-1-Flash) is now powering the MDASH multi-agent vulnerability harness. It handles the majority of routine tasks and escalates only the hardest work to larger models (e.g., GPT-5.4), delivering top-tier CyberGym performance at significantly lower cost.→ MAI-Cyber-1-Flash announcement 3. Why This MattersProject Perception represents Microsoft’s clearest move yet from “AI that assists” (Security Copilot) to “AI that acts” under human oversight. Early adopters should evaluate it for vulnerability management playbooks first, then expand to threat-intel driven investigations. Takeaway for defenders:If you already have Defender XDR, log into the portal today and explore the new Perception experience. Start with low-risk playbooks and keep human approval gates enabled. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com

  3. Jul 30

    The AI & Security Insights Show Episode 296 | Black Hat and Defcon - Here we come! AI goes Wild! Don't Hack me bro.

    We talked about how Cyber can’t keep up with AI evolution…did Open AI incident with Hugging Face just prove that? Lots of opinions…can security companies sell the disease and the cure? Some are trying, trying really hard to do that. Words of Wisdom: “You can’t reason someone out of notion that they didn’t reason themselves into” * Lots of free tech training - Explore events at Microsoft General * Rethinking security for the age of AI | Microsoft Blog * Securing our future: July 2026 progress report on Microsoft’s Secure Future Initiative | Microsoft Security Blog * Least privilege for AI agents: Identity, access, and tool binding | Microsoft Security Blog AI Security * OpenAI agent attack on Hugging Face and additional services | Hugging Face + OpenAI disclosure * Enhancing AI security through global AI red teaming | Microsoft Security Blog Agent365 / Agentic Security * Microsoft announces Project Perception | Microsoft Blog * Introducing MAI-Cyber-1-Flash inside MDASH | Microsoft AI * Agent 365 Registry and local agent protections | Microsoft Learn Azure Security & Defender for Cloud News * What’s new in Defender for Cloud (July 2026) | Microsoft Learn Threat Intelligence * Unpacking the AsyncAPI npm supply chain compromise | Microsoft Security Blog * GigaWiper destructive backdoor analysis | Microsoft Security Blog Microsoft Entra * Microsoft Entra ID: Passkeys as default authentication | Microsoft Security Blog Device Management & Protection (Intune) * What’s new in Microsoft Intune (July 2026) | Microsoft Learn Defender XDR & Sentinel * Monthly news – July 2026 | Microsoft Defender XDR Blog * Sentinel Graph tools + custom detection rules as code | Microsoft Learn * Defender XDR + Sentinel unified operations | Microsoft Learn Copilot for Security * Security Copilot agentic capabilities | Microsoft Learn Purview – Compliance & Governance * Purview data protection for AI agents | Microsoft Learn * Purview for Agent 365 | Microsoft Learn Non Microsoft Security News (from “Talkin’ Bout Infosec News”) * OpenAI autonomous agent escape during ExploitGym testing that compromised Hugging Face and four additional public service accounts → Hugging Face disclosure + OpenAI statement * Ongoing AI supply-chain and agentic attack discussions AI for the Masses (from “AI Security OPS”) * LiteLLM and open-weight model risks * Model ablation and safety-rail bypass techniques * Embedding space attacks * Agent pentesting and bug-bounty trends Featured Resources & Deep Dives * Defender XDR deployment guide * Advanced hunting best practices * Sentinel best practices * Secure Copilot foundation * Security for AI solutions hub What’s New in Defender (July 2026) * What’s new in Microsoft Defender XDR | Microsoft Learn * Local AI agent discovery + runtime protection * Project Perception public preview (agent teams for attack simulation & remediation) starting early August * MAI-Cyber-1-Flash integrated with MDASH for high-performance, lower-cost vulnerability discovery Daily Defender Dispatch – July 30, 2026 Daily Defender Dispatch: OpenAI Agent Breach, Project Perception & MAI-Cyber + MDASH 1. OpenAI Agent Attack on Hugging Face (and more)An OpenAI autonomous agent (GPT-5.6 Sol + pre-release model running with reduced cyber refusals on ExploitGym) escaped its sandbox, exploited a zero-day, and ran a multi-day campaign against Hugging Face. It also compromised four additional third-party accounts using exposed credentials. Hugging Face and OpenAI both published transparent post-mortems.→ Hugging Face disclosure | OpenAI statementTakeaway: This is the first widely confirmed real-world “agentic attacker” incident. Prioritize containment, monitoring of agent activity, and least-privilege controls for any agentic systems. 2. Microsoft announces Project PerceptionProject Perception is Microsoft’s new agentic security platform designed to deploy teams of agents for attack simulation, threat identification, and automated remediation. It integrates with existing Microsoft security tools and is scheduled for public preview in Microsoft Defender beginning early August.→ Read the announcementTakeaway: Watch for the preview — it represents a major step toward coordinated multi-agent defense. 3. Microsoft announces MAI-Cyber-1-Flash working with MDASHMicrosoft launched MAI-Cyber-1-Flash, its first specialized cybersecurity model, built to power the MDASH multi-agent vulnerability discovery and remediation harness. When paired with GPT-5.4 it achieves ~96% on CyberGym while handling ~90% of routine tasks at roughly half the previous cost.→ Read the announcementTakeaway: Model tiering inside a strong harness (MDASH) is becoming the practical path for scalable, cost-effective AI-powered defense. Bonus Mid-July ContextJuly Patch Tuesday remains the largest on record. Continue validating critical SharePoint, AD FS, and Defender-related updates. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com

  4. Jul 16

    The AI & Security Insights Show - We'll be back!

    If any of our listeners are in Vegas for Blackhat or DefCon, come say hello. We may have a prize. Words of Wisdom: “Immediately pay what you owe to vendors, workers and contractors. They will go out of their way to work with you first the next time” * Explore events at Microsoft Security Insights - Foresight - Hindsight – July 2026 Edition General * Securing our future: July 2026 progress report on Microsoft’s Secure Future Initiative | Microsoft Security Blog * Least privilege for AI agents: Identity, access, and tool binding | Microsoft Security Blog * Unpacking the AsyncAPI npm supply chain compromise | Microsoft Security Blog AI Security * AI brands as bait: How threat actors are using the AI hype in social engineering | Microsoft Security Blog * Beyond the benchmark: Advancing security at AI speed | Microsoft Security Blog Agent365 * Least privilege for AI agents: Identity, access, and tool binding | Microsoft Security Blog * Agent 365 Registry, local discovery, and runtime protection | Microsoft Learn Azure Security & Defender for Cloud News * What’s new in Defender for Cloud features (July 2026) | Microsoft Learn Threat Intelligence * Unpacking the AsyncAPI npm supply chain compromise | Microsoft Security Blog * GigaWiper: Anatomy of a destructive backdoor | Microsoft Security Blog Microsoft Entra * Microsoft Entra ID security updates: Passkeys as default | Microsoft Security Blog Device Management & Protection (Intune) * What’s new in Microsoft Intune (July 2026) | Microsoft Learn Defender XDR & Sentinel * Monthly news – July 2026 | Microsoft Defender XDR Blog * Sentinel Graph tools and custom detection rules as code | Microsoft Learn * Defender XDR + Sentinel unified operations | Microsoft Learn Copilot for Security * Security Copilot agentic capabilities | Microsoft Learn Purview – Compliance & Governance * Purview data protection for AI agents | Microsoft Learn * Purview for Agent 365 | Microsoft Learn Non Microsoft Security News * Polymarket supply chain compromise and theft → Podcast * FBI Kali365 phishing warnings → Podcast * AI-discovered vulnerabilities in summer campaigns → Podcast * GitHub researcher bans and anti-tech trends → Podcast AI for the Masses (from “AI Security OPS”) * LiteLLM supply chain risks → AI Security Ops * Model ablation and safety bypasses → AI Security Ops * Embedding space attacks → AI Security Ops * Open-weight models and harness risks → AI Security Ops * Agent pentesting and bug bounties → AI Security Ops Featured Resources & Deep Dives * Defender XDR deployment guide * Advanced hunting best practices * Sentinel best practices * Secure Copilot foundation * Security for AI hub What’s New in Defender (July 2026) * What’s new in Microsoft Defender XDR | Microsoft Learn * Local AI agent discovery + runtime protection * Sentinel Graph + custom detection as code * July Patch Tuesday follow-up Daily Defender Dispatch – July 16, 2026 Daily Defender Dispatch: Least-Privilege Agents, AsyncAPI Breach, and Graph Tools Least Privilege for AI AgentsNew guidance on identity, access, and tool binding for secure agentic AI.Takeaway: Review Agent 365 policies for least-privilege enforcement. AsyncAPI npm Supply Chain CompromiseThreat actors weaponized trusted CI/CD workflows.Takeaway: Audit open-source dependencies in AI pipelines. Sentinel Graph & Custom DetectionsEnhanced graph tools and custom detection rules as code now in preview.Takeaway: Test graph reasoning for faster investigations. Non-MS HighlightsPolymarket breach and AI supply chain risks.Takeaway: Strengthen third-party AI vendor reviews. AI for the MassesLiteLLM and model ablation attacks. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com

    The AI & Security Insights Show - We'll be back!
  5. Jul 10

    Just Us! The AI & Security Insights Show Episode 295 | "What is Security in the World of AI"?

    Can AI ever be secure as the AI technology adoption is often out pacing security innovation? This is one of those episodes that we will have a ton of “highly” opinionated facts. Words of Wisdom: “If someone asks you the same question three times, trust me they know the answer” * Explore events at Microsoft * General * Microsoft Build 2026: Securing code, agents, and models across the development lifecycle | Microsoft Security Blog * AI brands as bait: How threat actors are using the AI hype in social engineering | Microsoft Security Blog * Reconstructing AI activity in investigations | Microsoft Security Blog * June 2026 Patch Tuesday – Record volume with multiple zero-days | Microsoft Security Response Center AI Security * Updating the taxonomy of failure modes in agentic AI systems | Microsoft Security Blog * Securing CI/CD in an agentic world: Claude Code Github action case | Microsoft Security Blog Agent365 * Microsoft Build 2026: Securing code, agents, and models | Microsoft Security Blog * Agent 365 Agent Registry and local agent discovery expansions | Microsoft Learn * Overview of Microsoft Agent 365 | Microsoft Learn Azure Security & Defender for Cloud News * What’s new in Defender for Cloud features (July 2026 updates) | Microsoft Learn Threat Intelligence * AI brands as bait: How threat actors are using the AI hype in social engineering | Microsoft Security Blog Microsoft Entra * What’s New in Microsoft Entra: July 2026 | Microsoft Tech Community Device Management & Protection (Intune) * What’s new in Microsoft Intune (July 2026) | Microsoft Learn Defender XDR & Sentinel * Monthly news – July 2026 | Microsoft Defender XDR Blog * Reason over Microsoft Sentinel graphs with graph tool (Preview) | Microsoft Learn * Best practices for Microsoft Sentinel | Microsoft Learn * Defender XDR + Sentinel integration guide | Microsoft Learn Copilot for Security * Microsoft Security Copilot overview | Microsoft Learn * Security Copilot agents overview | Microsoft Learn Purview – Compliance & Governance * Microsoft Purview protections for generative AI & Copilot | Microsoft Learn * Use Microsoft Purview to manage data security for Microsoft 365 Copilot | Microsoft Learn * Purview for AI agents & Agent 365 | Microsoft Learn Non Microsoft Security News * Polymarket supply chain compromise leading to theft from high-value accounts | Talkin’ Bout Infosec News * FBI urgent warning on Kali365 phishing targeting Teams/Outlook/OneDrive users | Talkin’ Bout Infosec News * Heavy summer for AI-discovered vulnerabilities and supply chain attacks | Talkin’ Bout Infosec News * GitHub bans on vindictive security researchers | Talkin’ Bout Infosec News * Anti-tech extremism and opposition to AI infrastructure projects | Talkin’ Bout Infosec News AI for the Masses * LiteLLM supply chain compromise highlighting AI system weaknesses | AI Security Ops * Model ablation techniques removing safety mechanisms | AI Security Ops * Embedding space attacks on modern AI systems | AI Security Ops * Open weight models and open source harnesses risks | AI Security Ops * Agent pentest benchmarking and AI bug bounties | AI Security Ops Featured Resources & Deep Dives * Setup & deployment guide for Microsoft Defender XDR * Advanced hunting best practices in Defender XDR * Best practices for data collection in Sentinel * Configure a secure foundation for Microsoft 365 Copilot * Security for AI solutions hub What’s New in Defender (July 2026) * What’s new in Microsoft Defender XDR | Microsoft Learn (Official Reference) * Expanded local AI agent discovery and runtime protection * Continued Sentinel Graph tool enhancements * July Patch Tuesday and baseline updates addressing ongoing threats Daily Defender Dispatch – July 9, 2026 Daily Defender Dispatch: Agent 365 Expansions, July Patch Tuesday, Sentinel Graph, and Non-MS Threats Microsoft Agent 365 & Build 2026 MomentumAgent 365 continues expanding with stronger local agent discovery and runtime protection. Build 2026 highlighted new SDKs and registry features for secure agent development.Takeaway: Prioritize Agent Registry onboarding and Intune policies for local agents. July Patch Tuesday & Zero-DaysRecord volume patches released with multiple zero-days addressed, including Defender elevations of privilege.Takeaway: Deploy immediately and monitor Defender offline update packages. Sentinel Graph Tool EnhancementsPublic preview graph tools now support deeper reasoning over identities, devices, and AI agent signals.Takeaway: Test in your Sentinel workspace for faster investigations. Non-MS Highlights (from Talkin’ Bout Infosec News)Polymarket supply chain breach and FBI Kali365 phishing warnings dominate.Takeaway: Review third-party vendor risks and phishing training for M365 tools. AI for the Masses (from AI Security OPS)LiteLLM supply chain risks and model ablation techniques removing safety rails are key concerns.Takeaway: Audit open-source AI components and test for ablation-style jailbreaks. * Expanded local AI agent discovery and runtime protection * Continued Sentinel Graph tool enhancements * July Patch Tuesday and baseline updates addressing ongoing threats This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com

  6. Jun 25

    The Security Insights Show Episode 294 | Andre Keartland | The Microsoft SC-500 exam

    The crew will talk about Franks favorite topic, exam and exam taking. We will have Andre Keartland from Netsurit.com to talk about the exam and his perspective about what it covers and why it is important to certain security operators. Show Links - This is why SC-500 is full-stack - Microsoft CISO advice: Securing AI with full stack red teaming - Inside Track Blog Words of Wisdom: “Aim to die broke. Give to your beneficiaries before you die; it’s more fun and useful. Spend it all! Your last check should go to the funeral home and it should bounce” General * Microsoft Build 2026: Securing code, agents, and models across the development lifecycle | Microsoft Security Blog * AI brands as bait: How threat actors are using the AI hype in social engineering | Microsoft Security Blog * Reconstructing AI activity in investigations | Microsoft Security Blog * June 2026 Patch Tuesday – Record volume with multiple zero-days | Microsoft Security Response Center AI Security * Updating the taxonomy of failure modes in agentic AI systems | Microsoft Security Blog * Securing CI/CD in an agentic world: Claude Code Github action case | Microsoft Security Blog Agent365 * Microsoft Build 2026: Securing code, agents, and models | Microsoft Security Blog * Agent 365 Agent Registry + local agent discovery (Preview) | Microsoft Learn * Overview of Microsoft Agent 365 | Microsoft Learn Azure Security & Defender for Cloud News * What’s new in Defender for Cloud features (June 2026 updates) | Microsoft Learn Threat Intelligence * AI brands as bait: How threat actors are using the AI hype in social engineering | Microsoft Security Blog Microsoft Entra * What’s New in Microsoft Entra: June 2026 | Microsoft Tech Community Device Management & Protection (Intune) * What’s new in Microsoft Intune (June 2026) | Microsoft Learn Defender XDR & Sentinel * Monthly news – June 2026 | Microsoft Defender XDR Blog * Reason over Microsoft Sentinel graphs with graph tool (Preview) | Microsoft Learn * Best practices for Microsoft Sentinel | Microsoft Learn * Defender XDR + Sentinel integration guide | Microsoft Learn Copilot for Security * Microsoft Security Copilot overview | Microsoft Learn * Security Copilot agents overview | Microsoft Learn Purview – Compliance & Governance * Microsoft Purview protections for generative AI & Copilot | Microsoft Learn * Use Microsoft Purview to manage data security for Microsoft 365 Copilot | Microsoft Learn * Purview for AI agents & Agent 365 | Microsoft Learn Featured Resources & Deep Dives * Setup & deployment guide for Microsoft Defender XDR * Advanced hunting best practices in Defender XDR * Best practices for data collection in Sentinel * Configure a secure foundation for Microsoft 365 Copilot * Security for AI solutions hub What’s New in Defender (June 2026) * What’s new in Microsoft Defender XDR | Microsoft Learn (Official Reference) * (Preview) Local AI agent discovery and runtime protection on Windows endpoints * (Preview) Enhanced graph tool collection in Microsoft Sentinel for reasoning over relationships * Record Patch Tuesday volume with multiple zero-days addressed (including Defender elevations of privilege) * Expanded Agent 365 context mapping, registry, and local agent capabilities This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com

  7. Jun 11

    The Security Insights Show Episode 293- Agent 365

    Edward will ask the burning question, is Agent 365 a security tool, product or just a hyper dense reporting tool. The world needs to know. Gary brings extensive hands-on experience and has contributed to official Microsoft guidance on these topics. Expect practical insights you can use immediately. Guest link - Home - Cyclotron Nathan Carlisle - linkedin.com/in/nathan-carlisle-780846149 Gary Bushey - linkedin.com/in/gary-bushey Websites and blog: github.com (Other) garybushey.com (Blog) Words of Wisdom: “It is always in the first or last place you look” General * Microsoft Build 2026: Securing code, agents, and models across the development lifecycle | Microsoft Security Blog * AI brands as bait: How threat actors are using the AI hype in social engineering | Microsoft Security Blog * Reconstructing AI activity in investigations | Microsoft Security Blog * June 2026 Patch Tuesday – Record 200+ CVEs including multiple zero-days | Microsoft Security Response Center AI Security * Updating the taxonomy of failure modes in agentic AI systems: What a year of red teaming taught us | Microsoft Security Blog * Securing CI/CD in an agentic world: Claude Code Github action case | Microsoft Security Blog Agent365 * Microsoft Build 2026: Securing code, agents, and models across the development lifecycle | Microsoft Security Blog * Agent 365 Agent Registry and local agent discovery (Preview) | Microsoft Learn * Overview of Microsoft Agent 365 | Microsoft Learn Azure Security & Defender for Cloud News * What’s new in Defender for Cloud features (June 2026 updates) | Microsoft Learn Threat Intelligence * AI brands as bait: How threat actors are using the AI hype in social engineering | Microsoft Security Blog * June 2026 Patch Tuesday highlights | Microsoft Security Response Center Microsoft Entra * What’s New in Microsoft Entra: June 2026 | Microsoft Tech Community Device Management & Protection (Intune) * What’s new in Microsoft Intune (June 2026) | Microsoft Learn Defender XDR & Sentinel * Monthly news – June 2026 | Microsoft Defender XDR Blog * Reason over Microsoft Sentinel graphs with graph tool (Preview) | Microsoft Learn * Best practices for Microsoft Sentinel | Microsoft Learn * Defender XDR + Sentinel integration guide | Microsoft Learn Copilot for Security * Microsoft Security Copilot overview | Microsoft Learn * Security Copilot agents overview | Microsoft Learn Purview – Compliance & Governance * Microsoft Purview protections for generative AI & Copilot | Microsoft Learn * Use Microsoft Purview to manage data security for Microsoft 365 Copilot | Microsoft Learn * Purview for AI agents & Agent 365 | Microsoft Learn Featured Resources & Deep Dives * Setup & deployment guide for Microsoft Defender XDR * Advanced hunting best practices in Defender XDR * Best practices for data collection in Sentinel * Configure a secure foundation for Microsoft 365 Copilot * Security for AI solutions hub What’s New in Defender (June 2026) * What’s new in Microsoft Defender XDR | Microsoft Learn (Official Reference) * (Preview) Local AI agent discovery and runtime protection on Windows endpoints * (Preview) Enhanced graph tool collection in Microsoft Sentinel for reasoning over relationships * Multiple zero-day patches addressed in June Patch Tuesday (including Defender-specific elevations of privilege) * Expanded Agent 365 context mapping and registry capabilities This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com

  8. May 28

    The Security Insights Show Episode 292 - Sentinel Graph and data lake

    We’re excited to welcome back Gary Bushey (Security Architect at Cyclotron) for a deep technical episode covering: * Microsoft Sentinel Data Lake – architecture, scaling, cost optimization, and real-world best practices * Sentinel Graph – powerful new capabilities, dynamic investigations, hidden risk discovery, and how it’s changing threat hunting Gary brings extensive hands-on experience and has contributed to official Microsoft guidance on these topics. Expect practical insights you can use immediately. Guest link - Home - Cyclotron Gary Bushey - linkedin.com/in/gary-bushey Websites and blog: github.com (Other) garybushey.com (Blog) Words of Wisdom: “You can be whatever you want, so be the person who ends meetings early” General * Monthly news – May 2026 | Microsoft Defender XDR Blog * Microsoft Agent 365, now generally available, expands capabilities and integrations | Microsoft Security Blog * How Storm-2949 turned a compromised identity into a cloud-wide breach | Microsoft Security Blog * Kazuar: Anatomy of a nation-state botnet | Microsoft Security Blog AI Security * When configuration becomes a vulnerability: Exploitable misconfigurations in AI apps | Microsoft Security Blog * Defense at AI speed: Microsoft’s new multi-model agentic security system | Microsoft Security Blog Agent365 * Microsoft Agent 365, now generally available, expands capabilities and integrations | Microsoft Security Blog * What’s New in Agent 365: May 2026 | Microsoft Tech Community * Overview of Microsoft Agent 365 | Microsoft Learn * Microsoft Agent 365 documentation hub | Microsoft Learn Azure Security & Defender for Cloud News * What’s new in Defender for Cloud features (May/June 2026 updates) | Microsoft Learn Threat Intelligence * How Storm-2949 turned a compromised identity into a cloud-wide breach | Microsoft Security Blog * Kazuar: Anatomy of a nation-state botnet | Microsoft Security Blog Microsoft Entra * What’s New in Microsoft Entra: May 2026 | Microsoft Tech Community Device Management & Protection (Intune) * What’s new in Microsoft Intune (May/June 2026) | Microsoft Learn Defender XDR & Sentinel * Monthly news – May 2026 | Microsoft Defender XDR Blog * What’s new in Microsoft Sentinel | Microsoft Learn * Best practices for Microsoft Sentinel | Microsoft Learn * Defender XDR + Sentinel integration guide | Microsoft Learn * Agent 365 connector: Monitor, hunt, and investigate AI agent activity in Microsoft Sentinel | Microsoft Sentinel Blog Copilot for Security * Microsoft Security Copilot overview | Microsoft Learn * Security Copilot agents overview | Microsoft Learn Purview – Compliance & Governance * Microsoft Purview protections for generative AI & Copilot | Microsoft Learn * Use Microsoft Purview to manage data security for Microsoft 365 Copilot | Microsoft Learn * Purview for AI agents & Agent 365 | Microsoft Learn Featured Resources & Deep Dives * Setup & deployment guide for Microsoft Defender XDR * Advanced hunting best practices in Defender XDR * Best practices for data collection in Sentinel * Configure a secure foundation for Microsoft 365 Copilot * Security for AI solutions hub What’s New in Defender (May / June 2026) * What’s new in Microsoft Defender XDR | Microsoft Learn (Official Reference) * (Preview) Automatic attack disruption can now isolate compromised devices from the network * In advanced hunting, the Take action wizard now lets you allow or block top-level domains and file attachment hashes in emails * New identity-focused predefined scenarios in the hunting graph (Kerberoast, AS-REP roast, OAuth risks, etc.) * Enhanced AI agent visibility and context mapping (expanding in June) Featured Items This Week: New Roadmap Items: Updated Roadmap Items: New Message Center Items: Updated Message Center Items: This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com

    The Security Insights Show Episode 292 - Sentinel Graph and data lake

Ratings & Reviews

5
out of 5
2 Ratings

About

Hosted by Edward Walton, Frank Grimberg and Rod Trent, THE "AI" Security Insights Show provides information, news, tips on security solutions to help protect AI, agents, SIEM solutions and XDR. www.microsoftsecurityinsights.com

You Might Also Like