AI agents, zero-days and the problem with unseen access
OpenAI’s own model broke into Hugging Face’s production systems last month, mid-benchmark, with no human directing it.
In this edition our SOC team focus on what this highlights about AI governance readiness.
Also: Microsoft’s largest ever Patch Tuesday, SharePoint attackers using machine keys to preserve access after patching, a Russian state campaign against critical infrastructure, and Microsoft Threat Intelligence moving into Defender and Sentinel.
What the Hugging Face incident means for AI governance
On 16 July, Hugging Face and OpenAI disclosed an intrusion into Hugging Face’s production infrastructure carried out by an autonomous AI agent, a model running inside an OpenAI security evaluation.
The initial escape sat outside what any governance model controls. The agent left its test environment through a flaw nobody knew about, in an evaluation deliberately run with safeguards reduced to measure full capability. No entitlement model closes an unknown vulnerability, and no access policy makes a capable model less capable.
Once outside its boundary, the agent harvested service credentials and moved laterally between internal clusters. That path depends on two conditions common across estates: credentials that open more than the system they were issued for, and automated activity that passes for routine traffic until someone looks.
Everyone is still adapting to how AI agents behave in live environments, and governance models are catching up alongside them. That is the reason to start now rather than wait for the picture to settle. If you are running agents near production, bring them into your identity governance model and treat each one as a privileged identity in its own right.
Give every agent a named owner. Scope its access to the task it performs. Put an expiry on its credentials. Alert on its activity rather than only logging it.
Further reading
Agentic AI is ready to work. Is your organisation ready to let it?
Kocho CTO Steven Jones explains why access decisions become operational decisions once an AI agent can act on live data and systems.
He sets out what leaders need to know before deploying agentic AI: who approved a use case, what it can access, who owns it once it’s live, and how most Microsoft 365 organisations already have the foundations in Entra, Purview and Defender to answer those questions.
Microsoft’s biggest ever Patch Tuesday, and two zero-days that didn’t wait for it
July’s release fixed roughly 570 vulnerabilities, the largest single Patch Tuesday on record, including two flaws already under active exploitation before patches existed: an Active Directory Federation Services elevation-of-privilege bug (CVE-2026-56155) and a SharePoint Server flaw (CVE-2026-56164).
A third SharePoint vulnerability (CVE-2026-50522) was exploited within hours of a public proof-of-concept appearing later in the month, with attackers stealing machine keys to keep their access even after the hole was patched.
If you run on-premises SharePoint or AD FS, patching alone won’t fully close this one, rotate your machine keys regardless of patch status.
Russian state actors are working through the world’s routers
The NCSC and 18 partner agencies have attributed a global campaign against energy, water, transport and telecoms infrastructure to Russia’s FSB Centre 16. The method: scanning for routers and network devices still running default credentials, outdated firmware, or unrestricted management access. Routers and VPN gateways are frequently the least-monitored devices on a network, this advisory is a prompt to check whether yours are an exception.
SharePoint attackers are using machine keys to keep access after patching
The NCSC has urged UK organisations to act after active exploitation of vulnerabilities affecting on-premises Microsoft SharePoint Server products. CISA also warned that attackers are exploiting multiple SharePoint flaws to gain unauthorised access, establish remote code execution, steal IIS machine keys, and deploy malware.
For organisations still running SharePoint on-premises, this is not just a patching issue. If attackers have stolen machine keys, they may be able to maintain access even after the original vulnerability is closed. Security teams should apply updates, confirm AMSI is enabled, deploy endpoint protection, rotate SharePoint ASP.NET machine keys, and hunt for signs of compromise.
Threat intelligence moves into Defender and Sentinel at no extra cost
Microsoft Defender Threat Intelligence (MDTI) reaches end of life on 1 August 2026, but nothing is being taken away.
The standalone licence is being retired because its threat intelligence capabilities, used to understand emerging threats, investigate incidents, and inform response, are now built directly into Microsoft Defender and Microsoft Sentinel. Customers already using either product get access at no additional cost and with no migration or deployment work required.
It’s part of a wider pattern from Microsoft of consolidating security tooling into fewer portals and licences rather than maintaining separate standalone products, and a welcome one for any team that previously had to budget for MDTI as a separate line item.
This month’s priority actions
References and Resources
With thanks to the Kocho Security Operations Centre (SOC) team.
Stay safe. Stay informed.
Get cyber confident
Real partnership. Microsoft expertise. Complete transparency.
Request a call back today.
- AI-powered rapid protection, from day one
- Dedicated Microsoft experts, by your side
- Powerful, intuitive reporting tools
- Collaboration and transparency as standard
Got a question? Need more information?
Our expert team is here to help.