Every Friday
Cloud Life Security Radar
Edition 069 · 4 September 2026
Teams social engineering meets agent memory and context privilege
This edition puts three active Microsoft 365 attack paths next to new research on agent memory, context assembly, delegation between agents and what a safety score really proves. The question underneath is the same one: can you still see where an agent got its authority, how far it reaches, and how you take it back?
This needs attention now
- 01Review Teams external access, your out-of-band helpdesk verification process and which remote-support tools are permitted on managed devices.
- 02Validate that layered Defender for Office 365 protections are active and test how your own mail or AI processing normalizes invisible Unicode before matching.
- 03Confirm Tamper Protection, SmartScreen, network protection, cloud-delivered protection and the relevant ASR rules are enforced, and that recovery is tested after containment.
- 04Keep permissions in a source-backed history, and check grants, withdrawals, expiry and conflicts again before an agent uses a privileged tool.
- 05List every context source and how much you trust it, then test whether untrusted content can cross message-role, session, agent or tool boundaries.
Tenant actions
Open actionsThe Radar contains 17 concrete tenant actions. Sign in with your organization account to track progress together.
Plan this edition
Add the Friday edition and its tenant actions to Outlook, or download the full edition as a readable document to share internally.
Microsoft 365 Security
Changes in Microsoft 365, Entra, Defender, Purview and the exposure landscape that need a decision in your tenant.
Teams helpdesk impersonation can become domain-wide compromise
Microsoft observed a human-operated intrusion campaign in which external Teams users impersonate IT/helpdesk staff, persuade a user to grant an interactive remote session, then use PowerShell to install a malicious MSI. A portable Node.js runtime executes the implant, which performs host and Active Directory reconnaissance, captures screens and pivots with WinRM toward domain controllers and certificate authorities.
1 tenant action
ASCII smuggling crosses from prompt injection into phishing evasion
Microsoft found a high-volume finance-themed phishing campaign that inserted invisible Unicode Tags characters (U+E0000 to U+E007F) into lure words to interfere with content matching. The tuned signature peaked above 2.3 million messages on 11 February 2026. Microsoft reports that more than 99% of observed messages were still flagged by other layered protections.
1 tenant action
Counterfeit installers tamper with Defender and inhibit recovery
Microsoft is tracking fake software-download sites that distribute rotating malicious installers, mainly affecting China-based operations and Chinese-speaking users of multinational organizations. After execution, payloads add broad Defender exclusions, delete shadow copies, disable Windows Update components, persist through scheduled tasks and attempt lateral movement. Defender attack disruption contained devices and accounts in observed cases, but responders still had to eradicate persistence.
1 tenant action
Agentic & AI Security
AI agents, Copilot and autonomous defense: what is verified today and what your organization can already control.
Persistent agent memory can silently create false authority
A new preprint introduces EAL-Bench, an evaluation of five writer models and two executor models across procurement, cybersecurity and finance scenarios. Incremental memory updates created false authority for up to 50.2% of unauthorized requests, and where that false authority appeared, executor models acted on it in 98.6% of trials. Permission events that stayed backed by their source, combined with bounded event sourcing, reduced the effect substantially but also rejected more legitimate actions. The authors define this as endogenous authorization laundering: authorization drift caused by the agent's own memory, without any external attacker.
1 tenant action
Agent harnesses can promote untrusted context into privileged instructions
A new security preprint presents the first systematic analysis of context assembly in twelve real-world agent harnesses, including Claude Code and Codex. It defines two privilege errors: M-CPE, where low-privilege attacker content is placed into a higher-privilege message role, and X-CPE, where attacker content persists beyond the scope in which it was introduced. Observed consequences include full compromise, remote code execution, denial of service and manipulated tool or skill calls. The reported attack surfaces are memory and skill search paths, environment information, recursive imports, markup handling, configuration self-modification, refresh logic and unsandboxed built-in tools.
1 tenant action
Locally safe agents can still fail across delegation and shared state
A Systematization of Knowledge preprint reviews 197 works on multi-agent security and audits 44 evaluations. It organizes the field into six interaction interfaces, four adversary positions, seven risk families and eight attack paths, and introduces an A-I-R framework that traces an adversary through an interface to a system-level risk. It also proposes a defense contract that names the targeted path, the observation, the intervention, the trust boundary and the recovery. The audit reports recurring gaps: interaction effects are rarely isolated, metrics are seldom diagnostic, causal provenance is mostly absent, results rarely transfer across multi-agent designs and open-system evaluation is uncommon.
1 tenant action
Safety controls can co-evolve with the agent, if changes remain bounded and reversible
A new experimental preprint presents SafeEvolve, which turns trajectory evidence into bounded, versioned updates to safety prompts and hierarchical skills, with paired accept and reject evaluation and rollback metadata, combined with supervised fine-tuning and reinforcement learning. On Qwen3.5-4B the reported AgentDojo attack success rate fell from 2.37% to 0.79% while clean utility moved from 59.79% to 61.86%; on AgentHarm the harm score fell from 56.45 to 12.27 and refusal rose from 28.98% to 83.83. The implementation is published alongside the paper. These are benchmark results on one small model, not evidence from production environments.
1 tenant action
On the radar
Early signals that do not require action yet, but that we are following for the next editions.
- Microsoft Learn lists Memory Scan for Linux and Defender for Endpoint plug-in support for WSL containers as September 2026 previews. The visible page metadata still reports an earlier update date, so confirm tenant/channel availability before planning production use.
- Independent reproduction of the EAL-Bench and context-privilege results on enterprise agent platforms rather than research harnesses.
- Whether Microsoft Agent 365 exposes enough context, memory provenance and cross-agent causal telemetry to test these controls in your own tenant.
- Production evidence for safe co-evolution of agent harnesses beyond Qwen3.5-4B and current benchmark environments.
- Standards for typed provenance and authorization event sourcing that map onto Entra and Purview audit evidence.
Receive the Friday edition
One edition per week, with sources. Written for security leads, IT managers, Microsoft 365 administrators, architects and privacy officers.