The Week at a Glance
- 🔴 TerminalFix social-engineering campaign is actively targeting your workforce - attackers are using fake browser CAPTCHA prompts to trick employees into running malicious code, opening a backdoor into your network; confirm endpoint detection coverage and push employee awareness this week.
- 🟡 AI infrastructure is now an active attack target - Microsoft Threat Intelligence has documented real-world attacks against AI gateway services, including credential theft and cryptomining; organizations deploying Copilot connectors or custom AI workloads need to review exposure within 30 days.
- 🟡 Classic SharePoint experiences will be retired - Microsoft has announced a formal deprecation timeline for the classic SharePoint publishing interface; organizations still relying on classic sites need to begin a modern migration plan.
- 🟢 August brought a strong wave of productivity and governance improvements - Intune, Purview, Teams, and Copilot all received meaningful updates this month; no urgent action required, but several items deserve a spot on your planning calendar.
Sources: Microsoft Security Blog - TerminalFix Campaign · Microsoft Security Blog - AI Infrastructure Threats · SharePoint Blog - Classic Experience Changes
Why This Week Matters
Two separate Microsoft Threat Intelligence reports published this week confirm that attackers have shifted focus: one campaign targets employees directly through browser manipulation, and another targets the AI platforms organizations are actively building on. The window between discovering a threat and fully patching it continues to shrink, and Microsoft’s own research makes clear that organizations need active controls running in that gap, not just a patching schedule. Leadership should treat AI infrastructure governance as a security requirement on the same level as endpoint protection, not an afterthought to AI adoption.
Sources: Microsoft Security Blog - What’s New in Security August 2026 · Microsoft Security Blog - The Patch Window Is Collapsing
Risk & Compliance
🔴 TerminalFix campaign deploys a reverse tunnel through multistage intrusion: Attackers are using fake CAPTCHA prompts to manipulate employees into executing malicious code that installs a persistent backdoor - a direct threat to HIPAA, SOC 2, and CMMC environments; your security team should verify endpoint detection rules are current and brief employees on the social-engineering lure this week.
🔴 AI infrastructure under active attack - gateways and control points: Microsoft Threat Intelligence has documented live exploitation of AI gateway services, including credential harvesting and unauthorized cryptomining that runs up cloud costs and exfiltrates tokens; any organization using Copilot connectors, MCP servers, or custom AI workloads should audit exposure immediately, as this is relevant to cyber insurance requirements and SOC 2 controls.
🟡 The patch window is collapsing - a new security control plane is needed: Microsoft’s analysis confirms that the time between vulnerability disclosure and active exploitation has shrunk to the point where patching alone cannot close the risk; this strengthens the case for runtime endpoint controls and should inform your next cyber insurance renewal or NIST CSF assessment.
🟡 Instant revocation of service principal tokens with CAE: Entra now supports real-time token revocation for automated service accounts and integrations - closing an implicit-trust gap that attackers exploit during incident response by reusing stolen tokens; security teams should evaluate which service principals are in scope and enable this capability, particularly relevant for SOC 2 and CMMC environments.
🟡 Layered data loss prevention across endpoint, browser, and network: Microsoft Purview now provides a documented, three-layer DLP approach that meets employees wherever they work; organizations that have only deployed endpoint DLP are leaving browser and network exfiltration paths uncovered, which creates exposure under HIPAA, GDPR, and state privacy laws.
🟡 Defender for Identity sensor version restriction for new workspaces: New Defender for Identity workspaces restrict sensor v2.x installation to Windows Server 2016 or earlier; organizations standing up new identity monitoring environments need to verify server OS versions before deployment to avoid gaps in identity threat coverage.
🟡 Insider Risk Management - content preview in alerts: Investigators will soon be able to preview flagged file content directly inside an alert without opening a formal case, reducing friction in the review process; compliance officers should confirm that role-based access permissions are scoped correctly before this capability reaches general availability, particularly for HIPAA and financial data environments.
🟡 Universal Print audit logging coming to Purview: Print job submissions and configuration changes will be captured in the Purview Unified Audit Log starting January 2027; organizations under HIPAA or SOC 2 should plan to incorporate print activity into existing audit review workflows before that date.
🟡 Microsoft Edge for iOS spoofing vulnerability - CVE-2026-70331: A network-based spoofing flaw in Edge for iOS could allow an attacker to manipulate what users see in the browser; mobile device management policies should confirm Edge for iOS is on the latest patched version across your fleet.
🟡 Copilot Chat in Edge information disclosure vulnerability - CVE-2026-58616: A race condition in Copilot Chat within Edge could allow an authorized attacker to disclose information over the network; organizations with sensitive data workflows in the browser should ensure Edge is updated promptly.
🟢 Multi-account support for Sentinel connectors - Auth0, CrowdStrike, Salesforce: Security teams managing multiple subsidiaries or segmented environments can now ingest data from multiple accounts through a single Sentinel connector, reducing operational complexity with no compliance risk introduced.
🟢 Centralized SOC across multiple Entra tenants using Azure Lighthouse: Organizations with multiple tenants from acquisitions or regulatory separation can now run a unified security operations center without consolidating sensitive logs into a central repository, preserving data sovereignty obligations.
Sources: Microsoft Security Blog - TerminalFix Campaign · Microsoft Security Blog - AI Infrastructure Threats · Microsoft Security Response Center
What Your Employees Will Notice
- Copilot in Outlook will soon help resolve double-booked calendars - using Work IQ, Copilot can analyze scheduling conflicts and recommend which meetings to reschedule and who to notify; this may prompt questions about what data Copilot is reading.
- Copilot in Word will automatically apply sensitivity labels when drafting documents that draw on protected content from SharePoint and Teams; employees may see labels applied that they did not manually set, which is the intended behavior, not an error.
- GitHub Copilot is now available inside Microsoft Teams - developers can @mention it mid-conversation to spin up code or scaffolding without leaving the channel; this will be visible to technical teams and may prompt licensing questions.
- Profile cards in Teams will show badges for Awards and Certifications starting in October; this is a cosmetic change with no action required.
- The Copilot side pane in Edge will open automatically when following links from Outlook emails, starting in October; employees can expect contextual summaries and suggested next actions to appear alongside web content.
- SharePoint classic sites are on a formal retirement path - employees using older intranet sites built on classic publishing may eventually see changes or loss of functionality; proactive internal communication about migration timing will prevent confusion.
Sources: Teams Blog - GitHub Copilot in Teams · SharePoint Blog - Classic Experience Changes · M365 Roadmap - Edge Copilot Side Pane
What Your Help Desk Should Expect
- Sensitivity label questions from Word users - when Copilot auto-applies a label that restricts sharing or printing, employees may open tickets believing something is broken; help desk staff should be briefed that auto-labeling is policy-driven behavior.
- Edge update inquiries on iOS devices - the two Edge CVEs patched this week (spoofing and information disclosure) may prompt IT to push urgent Edge updates to mobile devices; expect questions from employees on managed iOS devices about unexpected app updates.
- TerminalFix social-engineering reports - if the fake CAPTCHA campaign reaches your workforce, employees who encounter suspicious browser prompts should be directed to report them immediately rather than dismiss or interact; a brief all-staff notice this week can reduce dwell time if an incident occurs.
- Copilot side pane appearing unexpectedly in Edge - once the auto-open feature rolls out in October, employees who are not expecting it may report the pane as an anomaly or ask how to disable it; the M365LinksAutoOpenCopilotEnabled policy gives administrators control.
- Remote Help unattended access questions - now that help desk staff can remotely access Windows devices without a user present, some employees may ask whether their machines can be accessed without their knowledge; clear communication about the policy governing when and how unattended access is used will reduce concern.
Sources: Intune Blog - August What’s New · Microsoft Security Response Center - CVE-2026-70331 · M365 Roadmap - Edge Copilot Side Pane
Cost & Licensing
- AI agent governance through Microsoft Agent 365 is now generally available - this control plane for monitoring and managing AI agents at scale is included in Microsoft 365; organizations that have not yet activated it are forgoing visibility into agent activity they may already be paying for.
- Copilot connectors (API and MCP) extend Work IQ to third-party systems - connecting Copilot to ServiceNow, CRMs, or databases may require reviewing connector licensing and understanding the difference between indexed API connections (read-only) and MCP servers (read and write), as the write-capable option carries additional data governance considerations.
- Dynamics 365 and Power Platform roadmap items are now consolidated into the AI at Work roadmap - organizations that license both M365 and Dynamics 365 can now track all upcoming changes in a single location, reducing planning overhead.
- Remote Help unattended access for Windows - if your organization currently relies on third-party remote access tools for after-hours device maintenance, this new Intune capability may reduce that dependency and its associated licensing cost; worth a conversation with your IT operations team.
Sources: M365 Roadmap - Microsoft Agent 365 · Intune Blog - August What’s New · Power Platform Blog - AI at Work Roadmap Consolidation
Planning Horizon
Immediate - within this week:
Immediate - TerminalFix campaign - employee awareness: Send a brief all-staff notice describing the fake CAPTCHA lure and establish a clear reporting path for suspicious browser prompts before this campaign reaches your workforce.
Immediate - AI infrastructure exposure review: Assign your security team to audit any exposed AI gateways, Copilot connectors, or custom LLM integrations for credential hygiene and access controls before the attack surface expands further.
Within 30 days:
Within 30 days - Instant token revocation for service principals via CAE: Decide which service accounts and integrations should be enrolled in Continuous Access Evaluation to enable real-time token revocation during incidents; this closes a meaningful gap in your Zero Trust identity controls.
Within 30 days - Edge for iOS and Edge desktop updates - patch CVEs: Confirm your mobile device management policy pushes the latest Edge version to all managed iOS devices; validate that desktop Edge is equally current across your workforce.
Within 30 days - Purview layered DLP gap assessment: Determine whether your DLP coverage extends to the browser and network layers, not just endpoints; gaps are directly relevant to HIPAA, GDPR, and cyber insurance requirements.
Within 30 days - Unified app and agent installation management in Teams and M365 Admin Center: Review whether your current Teams app permission policies are correctly migrated to the new unified management model, as the consolidation is already live and policy gaps could allow unintended app access.
Within 30 days - Classic SharePoint migration planning: Commission an inventory of classic SharePoint sites in your environment and initiate a migration timeline before Microsoft’s deprecation schedule forces unplanned work.
Within 90 days:
Within 90 days - AI-generated meeting archive policy decision: Before this feature reaches general availability in October, determine your organization’s retention policy for AI-generated meeting summaries and whether Copilot should retain insights after transcripts expire; this decision touches records management, legal hold obligations, and HIPAA if meetings involve patient or client data.
Within 90 days - Insider Risk Management - content preview permissions review: Before content preview in IRM alerts goes live, confirm that only authorized investigators hold the permissions required to view flagged file content directly in alerts.
Within 90 days - Copilot side pane in Edge - policy decision: Decide whether to enable or restrict the auto-open Copilot side pane for Outlook links before the October rollout, and communicate the decision to employees and help desk staff.
Within 90 days - Teams agent enablement from Admin Center - readiness review: Before the October availability of agent enablement for existing third-party apps in Teams, evaluate which applications in your environment have corresponding agents and whether governance policies should be in place before admins begin enabling them.
Planning for 2027:
By January 2027 - Universal Print audit logging - compliance workflow update: Plan to incorporate print activity from the Purview Unified Audit Log into your existing compliance review workflows before audit logging goes live; relevant to HIPAA and SOC 2 organizations with physical document handling.
By January 2027 - Exchange Online identifier modernization - dependency discovery: Microsoft is soliciting feedback on whether to retire ObjectGuid, SamAccountName, and DistinguishedName in Exchange Online; if your organization uses custom automation, HR integrations, or scripts that reference these identifiers, your IT team should respond to Microsoft’s survey and begin dependency mapping now.
Sources: Microsoft Security Blog - TerminalFix Campaign · Intune Blog - August What’s New · M365 Roadmap
If You Take No Action
TerminalFix campaign reaches your workforce unannounced: If employees encounter the fake CAPTCHA prompt without prior warning and no reporting path in place, the probability of someone executing the payload is high. A successful compromise installs a persistent backdoor and reverse tunnel, giving attackers durable access to your network. Discovery could come weeks later through an unrelated audit or a breach notification from a third party, at which point HIPAA breach reporting timelines, CMMC incident reporting, and cyber insurance notification obligations all begin counting down simultaneously.
AI infrastructure remains ungoverned while under active attack: Microsoft Threat Intelligence has confirmed that LLM gateway services and Copilot-connected endpoints are being actively probed. If your AI deployments have not been reviewed for credential hygiene and access controls, an attacker who gains access to an AI gateway can harvest credentials, establish persistence, and run unauthorized compute workloads at your expense. The financial and reputational cost scales quickly, and most cyber insurance policies require documented controls over third-party integrations and API access.
Service principal tokens remain instantly re-usable after compromise: Without Continuous Access Evaluation enabled for service principals, a stolen bearer token remains valid until it naturally expires, sometimes for hours. During an active incident, that window is exactly what an attacker needs to move laterally, escalate privileges, or exfiltrate data before your security team can contain the threat. This gap is most consequential in environments with automated workflows that carry elevated permissions, common in finance, healthcare, and any organization with deep Microsoft 365 integrations.
Sources: Microsoft Security Blog - TerminalFix Campaign · Microsoft Security Blog - AI Infrastructure Threats · Entra Blog - Instant Token Revocation with CAE
