Every Friday

    Cloud Life Security Radar

    Edition 069 · 4 September 2026

    Teams social engineering meets agent memory and context privilege

    This edition puts three active Microsoft 365 attack paths next to new research on agent memory, context assembly, delegation between agents and what a safety score really proves. The question underneath is the same one: can you still see where an agent got its authority, how far it reaches, and how you take it back?

    This needs attention now

    1. 01Review Teams external access, your out-of-band helpdesk verification process and which remote-support tools are permitted on managed devices.
    2. 02Validate that layered Defender for Office 365 protections are active and test how your own mail or AI processing normalizes invisible Unicode before matching.
    3. 03Confirm Tamper Protection, SmartScreen, network protection, cloud-delivered protection and the relevant ASR rules are enforced, and that recovery is tested after containment.
    4. 04Keep permissions in a source-backed history, and check grants, withdrawals, expiry and conflicts again before an agent uses a privileged tool.
    5. 05List every context source and how much you trust it, then test whether untrusted content can cross message-role, session, agent or tool boundaries.

    Tenant actions

    Open actions

    The Radar contains 17 concrete tenant actions. Sign in with your organization account to track progress together.

    Plan this edition

    Add the Friday edition and its tenant actions to Outlook, or download the full edition as a readable document to share internally.

    Microsoft 365 Security

    Changes in Microsoft 365, Entra, Defender, Purview and the exposure landscape that need a decision in your tenant.

    All items
    Microsoft threat intelligence based on an observed active campaign2 September 2026Defender, XDR & MDR

    Teams helpdesk impersonation can become domain-wide compromise

    Microsoft observed a human-operated intrusion campaign in which external Teams users impersonate IT/helpdesk staff, persuade a user to grant an interactive remote session, then use PowerShell to install a malicious MSI. A portable Node.js runtime executes the implant, which performs host and Active Directory reconnaissance, captures screens and pivots with WinRM toward domain controllers and certificate authorities.

    1 tenant action

    Open item
    Microsoft research based on Defender for Office 365 telemetry; campaign-specific measurements3 September 2026Defender, XDR & MDR

    ASCII smuggling crosses from prompt injection into phishing evasion

    Microsoft found a high-volume finance-themed phishing campaign that inserted invisible Unicode Tags characters (U+E0000 to U+E007F) into lure words to interfere with content matching. The tuned signature peaked above 2.3 million messages on 11 February 2026. Microsoft reports that more than 99% of observed messages were still flagged by other layered protections.

    1 tenant action

    Open item
    Microsoft Defender Experts research on an active campaign; attribution assessed with moderate confidence1 September 2026Vulnerability & Exposure

    Counterfeit installers tamper with Defender and inhibit recovery

    Microsoft is tracking fake software-download sites that distribute rotating malicious installers, mainly affecting China-based operations and Chinese-speaking users of multinational organizations. After execution, payloads add broad Defender exclusions, delete shadow copies, disable Windows Update components, persist through scheduled tasks and attempt lateral movement. Defender attack disruption contained devices and accounts in observed cases, but responders still had to eradicate persistence.

    1 tenant action

    Open item

    Agentic & AI Security

    AI agents, Copilot and autonomous defense: what is verified today and what your organization can already control.

    All items
    New empirical preprint; not peer reviewed1 September 2026Agent memory & authorization

    Persistent agent memory can silently create false authority

    A new preprint introduces EAL-Bench, an evaluation of five writer models and two executor models across procurement, cybersecurity and finance scenarios. Incremental memory updates created false authority for up to 50.2% of unauthorized requests, and where that false authority appeared, executor models acted on it in 98.6% of trials. Permission events that stayed backed by their source, combined with bounded event sourcing, reduced the effect substantially but also rejected more legitimate actions. The authors define this as endogenous authorization laundering: authorization drift caused by the agent's own memory, without any external attacker.

    1 tenant action

    Open item
    New empirical security preprint on 12 real-world harnesses; not peer reviewed1 September 2026Agent harness & context

    Agent harnesses can promote untrusted context into privileged instructions

    A new security preprint presents the first systematic analysis of context assembly in twelve real-world agent harnesses, including Claude Code and Codex. It defines two privilege errors: M-CPE, where low-privilege attacker content is placed into a higher-privilege message role, and X-CPE, where attacker content persists beyond the scope in which it was introduced. Observed consequences include full compromise, remote code execution, denial of service and manipulated tool or skill calls. The reported attack surfaces are memory and skill search paths, environment information, recursive imports, markup handling, configuration self-modification, refresh logic and unsandboxed built-in tools.

    1 tenant action

    Open item
    New Systematization of Knowledge preprint covering 197 works and auditing 44 evaluations; not a new operational benchmark1 September 2026Multi-agent risk

    Locally safe agents can still fail across delegation and shared state

    A Systematization of Knowledge preprint reviews 197 works on multi-agent security and audits 44 evaluations. It organizes the field into six interaction interfaces, four adversary positions, seven risk families and eight attack paths, and introduces an A-I-R framework that traces an adversary through an interface to a system-level risk. It also proposes a defense contract that names the targeted path, the observation, the intervention, the trust boundary and the recovery. The audit reports recurring gaps: interaction effects are rarely isolated, metrics are seldom diagnostic, causal provenance is mostly absent, results rarely transfer across multi-agent designs and open-system evaluation is uncommon.

    1 tenant action

    Open item
    New experimental preprint on Qwen3.5-4B and benchmark environments; not production evidence2 September 2026Change control

    Safety controls can co-evolve with the agent, if changes remain bounded and reversible

    A new experimental preprint presents SafeEvolve, which turns trajectory evidence into bounded, versioned updates to safety prompts and hierarchical skills, with paired accept and reject evaluation and rollback metadata, combined with supervised fine-tuning and reinforcement learning. On Qwen3.5-4B the reported AgentDojo attack success rate fell from 2.37% to 0.79% while clean utility moved from 59.79% to 61.86%; on AgentHarm the harm score fell from 56.45 to 12.27 and refusal rose from 28.98% to 83.83. The implementation is published alongside the paper. These are benchmark results on one small model, not evidence from production environments.

    1 tenant action

    Open item

    On the radar

    Early signals that do not require action yet, but that we are following for the next editions.

    • Microsoft Learn lists Memory Scan for Linux and Defender for Endpoint plug-in support for WSL containers as September 2026 previews. The visible page metadata still reports an earlier update date, so confirm tenant/channel availability before planning production use.
    • Independent reproduction of the EAL-Bench and context-privilege results on enterprise agent platforms rather than research harnesses.
    • Whether Microsoft Agent 365 exposes enough context, memory provenance and cross-agent causal telemetry to test these controls in your own tenant.
    • Production evidence for safe co-evolution of agent harnesses beyond Qwen3.5-4B and current benchmark environments.
    • Standards for typed provenance and authorization event sourcing that map onto Entra and Purview audit evidence.

    Receive the Friday edition

    One edition per week, with sources. Written for security leads, IT managers, Microsoft 365 administrators, architects and privacy officers.

    One edition every Friday. Unsubscribe any time.