Purview is a thing or so we heard…or as my cat says it …Purrrrrr-view. Words of Wisdom: “Take the stairs.” Security Insights - Foresight - Hindsight 08/27/2026 General * What’s new in Microsoft Security: August 2026 | Microsoft Security Blog * The patch window is collapsing: Why security needs a new control plane | Microsoft Security Blog (Aug 25) * Rethinking security for the age of AI – Project Perception | Microsoft Blog AI Security * When AI infrastructure becomes the target: Securing gateways and control points | Microsoft Security Blog (Aug 26) — LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining * OpenAI autonomous agent incident affecting Hugging Face and additional services | Hugging Face + OpenAI disclosure Agent365 / Agentic Security – Project Perception * What is Project Perception? | Microsoft Learn (Limited Public Preview) * Get started with Project Perception | Microsoft Learn * Project Perception product page | Microsoft Security * Introducing MAI-Cyber-1-Flash inside MDASH | Microsoft AI Project Perception snapshot (as of late August)Microsoft documents Perception as a Limited Public Preview — invitation-only for a defined window before broader availability. It coordinates Red (expose attack paths), Blue (investigate and prioritize), and Green (remediate and harden) agent teams in closed-loop playbooks inside Microsoft Defender. High-impact actions stay under human control. Azure Security & Defender for Cloud News * Microsoft named a Leader in Frost Radar 2026: Cloud Workload Protection Platforms | Microsoft Security Blog * What’s new in Defender for Cloud | Microsoft Learn Threat Intelligence * Hunting MacSync Stealer infrastructure through behavioral pivots | Microsoft Security Blog (Aug 18) * Email threat landscape: Q2 2026 | Microsoft Security Blog Microsoft Entra * Entra Tenant Governance and identity foundations for the AI era | Microsoft Security Blog * Entra ID CVE-2026-69836 was patched server-side; Microsoft later clarified it was not exploited in the wild Device Management & Protection (Intune) * Windows Autopilot device association + Unattended Support with Remote Sign-In | Microsoft Security Blog * What’s new in Microsoft Intune | Microsoft Learn Defender XDR & Sentinel * Monthly news – August 2026 | Microsoft Defender XDR Blog * What’s new in Microsoft Defender XDR | Microsoft Learn * What’s new in Microsoft Sentinel | Microsoft Learn — new UEBA sources (Fortinet FortiGate behaviors) and anomalies on behaviors * Defender Experts MDR P2 now covers third-party data ingested through Sentinel (Palo Alto, AWS, Okta, and more) Copilot for Security * Security Copilot overview | Microsoft Learn Purview – Compliance & Governance * Purview data protection for AI agents | Microsoft Learn * Secure Now guidance for agentic containment in Microsoft Security Exposure Management Non Microsoft Security News * August Patch Tuesday: very large release including exploited WinSock/afd.sys elevation of privilege (CVE-2026-68820) * CISA added additional KEV entries this week (including NetScaler and other actively exploited flaws) AI for the Masses * LiteLLM / AI gateway attacks (Microsoft Threat Intelligence, Aug 26) * Open-weight model and agent-harness risk discussions * Agent pentesting and safety-rail bypass trends Featured Resources & Deep Dives * Defender XDR deployment guide * Advanced hunting best practices * Sentinel best practices * Security for AI solutions hub What’s New in Defender (August 2026) * What’s new in Microsoft Defender XDR | Microsoft Learn * AI agent posture risk + Agent 365 runtime/threat detection * Project Perception Limited Public Preview — Red / Blue / Green agent teams in Defender * MAI-Cyber-1-Flash inside MDASH * Defender Experts MDR P2 third-party coverage via Sentinel * Linux AV audit mode (preview) and Linux offboarding API (GA) Daily Defender Dispatch – August 27, 2026 Daily Defender Dispatch: August Security Recap, AI Gateways Under Fire, Perception Preview 1. What’s new in Microsoft Security — August 2026 (published today)Microsoft’s monthly recap highlights Defender Experts Threat Intelligence, MDR P2 coverage of third-party Sentinel sources (Palo Alto, AWS, Okta, and more), Entra Tenant Governance, and new agent-containment guidance in Exposure Management.→ Read it 2. AI infrastructure is now a primary targetMicrosoft Threat Intelligence published a deep dive on attacks against exposed AI workloads — including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining. Treat AI gateways as production control planes, not side projects.→ Read it 3. Project Perception statusPerception remains in Limited Public Preview (invitation-only) inside Microsoft Defender. Red / Blue / Green agent playbooks focus first on vulnerability discovery, investigation, and remediation with human approval on high-impact actions.→ Overview | Get started | Announcement | MAI-Cyber-1-Flash + MDASH 4. Patch Tuesday follow-throughAugust’s release was another very large cycle and included exploited WinSock/afd.sys EoP (CVE-2026-68820). Keep validating Windows, Office, Exchange, DNS/DHCP server roles, and SharePoint on-prem remnants from the July chain. Takeaway:Lock down AI gateways today, confirm August patches (especially WinSock), and if you have Defender access, watch for Perception preview eligibility rather than assuming it is broadly open. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com