THE PROMPT for Microsoft Security - Issue #76
Recharging my silicon stars and stripes. Because even defenders need fireworks and a firmware update
Things from Me
Happy Friday everyone!
A quick heads up before you dive in.
Issue #76 is here, but I wanted to let you know that there will be no newsletter next week. Honestly, two reasons: first, I just need the brain space. Anyone who follows this stuff knows the Microsoft Security world moves fast, and sometimes you have to step back to stay sharp. Second - and this one’s a good reason - we’re celebrating the USA’s 250th birthday, and that feels like something worth actually being present for. So, the newsletter is taking the week of July 4th off along with me.
And while I’m being upfront about the schedule: I’ll also be going dark for a couple of weeks toward the end of July. If you’re in the Microsoft ecosystem, you already know what that means - it’s end of fiscal year, and things get a little hectic. I’ll be back before you miss me too much.
Thanks for being part of this community. Now, on to the good stuff.
Talk soon.
-Rod
Things that are Related
AutoJack: How a single page can RCE the host running your AI agent - Ongoing research into AI agent framework security identified an exploit chain in AutoGen Studio (AutoGen’s open-source prototyping user interface) that allows untrusted web content rendered by a browsing agent to reach a local Model Context Protocol (MCP) WebSocket and spawn arbitrary processes on the host. The technique, which we call AutoJack, jacks the agent into becoming the attacker’s last-mile delivery vehicle by crossing the localhost trust boundary that many developer tools rely on.
Guarding AI memory - AI memory transforms an AI system from a stateless tool into a learning collaborator. That unlocks powerful experiences, but it also increases the attack surface of the AI system. Without memory, attackers need to achieve their objective in a single prompt. With AI memory, they can shape behavior gradually over time or plant memories that influence agent reasoning after the original context is gone and user awareness is lower.
Things for Partners
June update: What’s new in Security for partners - As AI adoption accelerates, security expectations and partner opportunities are increasing just as fast. In this June Security partner update, Microsoft Security partners will find the latest product updates, incentives, and skilling designed to help you secure AI workloads, strengthen customer trust, and grow repeatable security services. From new capabilities across Microsoft Defender, Microsoft Sentinel, Microsoft Purview, and Microsoft Agent 365 to expanded go‑to‑market resources and partner‑ready offers, this month’s updates focus on what you can sell, deliver, and operationalize now to stay ahead of an evolving threat landscape.
Things in the News
New Forrester study shows customers who unified with Microsoft Security benefited from 124% ROI - Across many industries, organizations are unifying security and putting AI agents to work. Security teams are utilizing agents that reason, decide, and act on their behalf, under their governance. At Microsoft, we see this firsthand—more than 80% of the Fortune 500 are already using AI.1 The promise of this moment is enormous. The responsibility that comes with it is just as significant. This year, Microsoft commissioned Forrester Consulting to conduct a Total Economic Impact™ (TEI) study for our AI-first, end-to-end security platform.
One intrusion, two cyberattackers: Uncovering parallel threat activity - What began as a routine ransomware investigation quickly revealed something far more complex. In this ninth cyberattack series report, DART details how a single intrusion uncovered parallel activity from two unrelated threat actors operating simultaneously—blending tactics, obscuring signals, and challenging traditional assumptions about how multi-stage intrusion campaigns unfold across hybrid environments.
Microsoft Sentinel Things
A guide to innovating threat hunting with Microsoft Sentinel custom graph - Sentinel graph is a relationship-first method for organizing and querying data within Microsoft Sentinel data lake. Activities amongst entities (users, devices, emails, IPs, applications, etc.) become a navigable structure that avoids a complex table structure. Rather than stitching together data and evidence via complex joins, users can follow multi-hop connections in order to understand insights such as blast radius, unseen pivots in malicious behavior, and investigative details that may not be as obvious within regular logs, all while visualizing these paths to assist in communicating evidence and findings.
Defender for Cloud Things
CNAPP evolution: How Microsoft aligns with leading cloud risk management platforms - Cloud security is shifting from visibility to context-aware risk reduction, helping security teams understand which exposures matter most, prioritize what can be exploited, and reduce risk across the application lifecycle. As organizations continue to expand across multicloud environments, Kubernetes, APIs, and AI-powered workloads, security teams are overwhelmed with signals. The challenge is no longer identifying individual risks, but determining which combinations of vulnerabilities, identities, and data exposures are most critical to address at the source.
Defender Threat Intelligence Things
StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them - Infostealers continue to be some of the most pervasive and impactful threats across the cybercrime ecosystem. They play a central role in intrusions, silently harvesting passwords, cookies, and session tokens before exfiltrating stolen data to attacker-controlled infrastructure. If not mitigated, these threats can turn a single consumer-device compromise into an enterprise risk: an infostealer infection on an employee’s personal device could yield corporate virtual private network (VPN) credentials, single sign-on (SSO) tokens, and session cookies that could allow an attacker to bypass multifactor authentication (MFA).




