August 2026
Harmer was laying out the zero-trust philosophy — that no service should be trusted by default. His line compresses the whole idea: trust isn't a status you hand out, it's something a system earns only by behaving predictably again and again.
I agree with Bill. I think like that, certainly the endpoint endpoint protection is going to include the behavioral detections and other type of things that we're seeing with the agents. It's part of the future. It's the reality.
I need like a WPA poster that just says in flight is too late. Like I need like a mid-century propaganda poster just to start spreading around here. Spread the good word, excellent points all around. Before we dive into some of our deeper dev, we'll get into some of those AI agent escapes and some of the follow-up with that as well. Got to spend a few moments and thank our sponsor for today. And that is, of course, Vanta. Your GRC team is dealing with more and more frameworks, vendors, and risk. The board wants it all in one place, but your compliance data lives all over. Vanta's Agentic Trust platform connects compliance, risk, and trust at enterprise scale and delivers a 526% ROI over three years. 16,000 companies trust Vanta, including Snowflake, Atlassian, and Ramp. Visit Vanta.com/slash CISO to learn more. All right, let's dive into our next story here. This one was particularly interesting to me this week. The malware is coming from inside the Microsoft. Researchers at Ontinue Cyber Defense Center detailed a new malware framework called Twin Loot. And what makes this stand out is it basically takes living off the land to its extreme here. It's entire command and control infrastructure running on Microsoft services. So we got SharePoint Online and Microsoft Graph APIs for C2 communication, Microsoft Teams turn relay infrastructure used for access, and the edge browser itself to disguise Graph API communications. The researchers warned that the only way to really distinguish twin loot traffic is to look for deviations from baselines on traffic to trusted services. Bill, obviously living off the land, nothing new here, tried and true tactic. Hey, let's use Dropbox to host all of our stuff here. But this seems like it was almost created on a dare to use as much Microsoft stuff as possible here. Anything here stand out to you? And do attacks like these have to change how we treat so-called trusted services? I know Zero Trust has been on everybody's lips for years. At this point, nothing new there.
Yeah, so there are no trusted services. Just don't trust them. That is what zero trust, that's the philosophy. Trust is simply repetition over time. And not to slag on Microsoft, but I don't know, Patch Tuesday. You know, vulnerability in Microsoft is like a Tuesday. But they are running something at a massive scale and running things at massive scale requires a lot of coordination. And you can hide these things really, really well inside some of these in some of these platforms. So I think, you know, as you build out, as you develop on more of the platforms, use them, right? Move them into a category of known, not necessarily trusted, but known. And then once inside known, you can adjust that trust level based on how much you've used them and how much repetition over time you've had without issue. Unfortunately for Microsoft, I think you're going to probably see them sit in the known but vulnerable or the known but risky category. There's nothing wrong with that. That's that's how we run business, right? You go find your solutions. I don't think they'll ever end up in a very quiet corner where nothing bad is happening. There's just too many moving components on that side.
Yeah, always talking about, you know, consciously accepting risk, right? And if we know, you know, to that, to that point, you know, Microsoft is a known, it carries some risk. Obviously, a lot of businesses are still going to choose to accept that based on, I don't know, the entire history of digital business here. David, I'm curious for you. How did this story strike you? Anything unusual here? Any kind of lessons to tease out kind of along those lines?
Well, I think that Bill really kind of talked about here a little bit. It's like it's zero trust, right? It means you're zero trust everybody. You know, all your SaaS providers, you cannot trust them. You cannot trust these domains, right? And I think that's the reality. And so just kind of blacklisting and things like that. Nope. And it really comes back to, hey, if you're using SaaS services, you need to have SSPM, everybody, right? And also, just like with the AI, I'm going to bring it up again. It's all about, you know, the identity anomalies, right? That is our pivot. That's kind of our hub, right? And different agentity behaviors and things. And that's how we're going to detect it. I think that's the reality. And so we can't just say, oh, I'm using name your favorite SaaS service. It's a trusted domain. No, I think that world's changed. And I think the malicious agents are going to take it to the next level. And I think we have to watch for that even more in the context of the identities and their actions.
This is a whole nother issue, but I'm just so curious because we're talking about that. We've been talking a lot internally at the CISO series just about the challenges of SMB security, one as an SMB ourselves, but two, just in this category. And this kind of living off the land stuff feels like, again, one of those situations where it feels like so easy. Like if I was a threat actor, I'd be going after an SME, SMB, something like that, where even if they want to, they're not going to be establishing those baselines as often. It's a one or two person IT shop that a guy does, someone does on their team does security on the side, essentially. And that to me feels like this, this story, again, if I needed more empathy for SMBs and cybersecurity, this story to me kind of pushed me over the top there. We