CIA Brief 20260926

image

Security

  • Storm-3168: Agentic-driven cloud attacks using compromised service principals
    Microsoft details an Azure attack where two compromised service principals mapped a tenant, then fired off 100+ storage account deletions in about seven minutes, deleted a Key Vault and Function App, and pulled storage account keys. One possible entry point was a client secret pasted into a public GitHub issue and later “removed”, except it lived on in the edit history. Good reminder to audit app registrations for stale secrets and excessive Contributor rights, and to put resource locks and deletion protection on anything you need to recover, because those locks are what saved some of the storage accounts here.
    https://www.microsoft.com/en-us/security/blog/2026/09/25/storm-3168-agentic-driven-cloud-attacks-using-compromised-service-principals/
  • Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments
    Storm-2570 is a ransomware affiliate that hops between Qilin, DragonForce, Anubis and BERT, but its playbook barely changes: RMM tools like Atera, MeshAgent, ScreenConnect and NinjaRMM, PsExec for lateral movement, Defender tampering, then s5cmd or Rclone for exfiltration. The lesson for MSPs is to detect the behaviour rather than the payload, and to accept that attackers abusing the same RMM tools we use isn’t going away. Worth a look at the mitigations: tenant-wide tamper protection, ASR rules (including blocking PsExec and WMI process creation), and alerting on any RMM agent you didn’t deploy.
    https://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments/
  • Disrupting EvilTokens: The AI Chatbot Built for Cybercrime
    Microsoft’s Digital Crimes Unit has taken down EvilTokens, a subscription service that hijacked mailboxes via device-code sign-ins, then ran an AI chatbot over the inbox to find the “money movers”, vendor invoices and the best people to impersonate. It was linked to more than 12,000 compromised inboxes across over 10,000 organisations, with Australia among the most affected countries. Practical takeaways: block device code flow with Conditional Access where it isn’t needed, revoke sessions and tokens (not just passwords) after a compromise, and make out-of-band verification of payment changes non-negotiable for clients.
    https://blogs.microsoft.com/on-the-issues/2026/09/22/disrupting-eviltokens-the-ai-chatbot-built-for-cybercrime/
  • Reimagining the SOC for the agentic era in Microsoft Defender
    Microsoft has announced the integrated security operations center (ISOC) in Microsoft Defender, now in preview, bringing SIEM and threat protection together as one foundation that both analysts and AI agents work from. It’s light on specifics and heavy on vision, but the direction is clear: Sentinel and Defender are converging into one platform, with agents taking on more of the investigation work. Still early, but if you run a Microsoft-based SOC or MDR offering, expect your tooling and workflows to shift around this.
    https://www.microsoft.com/en-us/security/blog/2026/09/23/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender/
  • Risks of AI misalignment to Australian organisations
    ASD’s ACSC has issued an alert after AI agents, blocked by security controls on public-facing sites, independently found vulnerabilities and pushed on without human authorisation to finish the task they’d been given. There’s no sign of malicious targeting, but it means your web-facing systems now need to hold up against persistent automated agents, not just people and scanners. Nothing groundbreaking in the advice (strong authentication, prompt patching, log monitoring, segmentation, testing incident response against AI scenarios), but it’s a handy official reference when clients ask whether this is a real risk.
    https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/risks-of-ai-misalignment-to-australian-organisations
  • OpenAI ‘climbed the fence’: Taskforce scrambles after long delays flagging Medicare hack
    The Prime Minister has revealed that an OpenAI agent running an internal evaluation in June got around controls on the legacy Medicare Statistics Reporting Service and pulled data; no personal information was accessed and the portal has since been shut down. OpenAI only flagged it in September via a generic government inbox, and the government has now set up a taskforce and is eyeing AI transparency laws. The MSP lesson is about forgotten legacy sites: if a bot on a research errand can walk into a government portal, check what old client portals and web apps are still sitting exposed.
    https://www.smh.com.au/politics/federal/openai-breaches-medicare-albanese-reveals-20260924-p6100u.html

Microsoft 365 & Windows

  • Put multiple values in one cell with lists and arrays in Excel
    Excel can now hold multiple values in a single cell via lists (Insert > List or Ctrl+J), arrays in cells and nested arrays, along with new FLATTEN, HAS, HASANY and HASALL functions. It’s Beta Channel only for now, needs workbook Compatibility Version 3, and has real gaps: PivotTables, charts, Power Query and data validation don’t handle arrays yet. Worth a look for the power users you support, but keep it out of important workbooks until it’s generally available, which is Microsoft’s own advice.
    https://techcommunity.microsoft.com/blog/Microsoft365InsiderBlog/put-multiple-values-in-one-cell-with-lists-and-arrays-in-excel/4559395
  • Link to a location in Word for Windows and Mac
    Word for Windows and Mac now lets you select content, right-click and choose Copy Link to Location, producing a cloud link that opens the document at exactly that spot in web or desktop Word. Nothing groundbreaking, but it’s a genuine time saver when reviewing long policies, contracts and proposals with clients. It needs Windows Version 2605 or Mac 16.109 and later, so check update channels if users can’t see it.
    https://techcommunity.microsoft.com/blog/microsoft365insiderblog/link-to-a-location-in-word-for-windows-and-mac/4541663

Cloud & AI

  • Introducing the new Copilot with Home, Code and Autopilot
    Microsoft has rebuilt the Copilot app around Home (Chat and Cowork together, with Word, Excel and PowerPoint built in), Code (natural-language building of apps and automations that run sandboxed inside your tenant) and Autopilot (formerly Scout), a persistent agent with its own identity that works in Teams and Outlook. The bit MSPs need to get across is the billing split: everyday Copilot stays on the per-user licence, while Cowork, Code, Autopilot and frontier models like Astra and Fable run on usage-based billing, with new FinOps controls in Agent 365. Home and Code roll out to the Frontier program in the coming weeks and Autopilot heads to private preview, so plan governance for user-built apps and agent identities now, before clients start asking.
    https://blogs.microsoft.com/blog/2026/09/25/introducing-the-new-copilot-with-home-code-and-autopilot/
  • The new Copilot is here: The opportunity for Microsoft partners
    This is the partner-facing companion to the new Copilot launch. The detail that matters for CSP partners: from 2 November 2026, usage-based billing will be enabled by default for new Microsoft 365 Copilot Business licences bought through CSP, making it easier to switch on experiences like Copilot Cowork. Good reminder to review your CSP billing and client spending controls before then, so nobody gets a surprise bill for agent usage they never approved.
    https://partner.microsoft.com/en-us/blog/article/ai-at-work-marketing-moment
  • Introducing Claude Opus 5.5
    Anthropic says Opus 5.5 matches Claude Fable 5.1 on most work while costing around 40% less to run than Opus 5, with token pricing cut to US$4 input and US$20 output per million. It also claims the model is much less likely to take hard-to-reverse actions or step outside its boundaries, and is more resistant to prompt injection, which matters more than benchmarks if you’re letting agents loose on client systems. It’s available now on Azure, AWS and Google Cloud, though its safeguards reroute most cybersecurity tasks to an older model, so don’t expect it to power security tooling out of the box.
    https://www.anthropic.com/claude-opus-5-5

After hours

Hacking this BYD was too easy; it didn’t even have a password | Four Corners Documentary – https://www.youtube.com/watch?v=_TZFcyzGEiY

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week

The Lesson Is Often Sitting Across the Table

image

Some of the most useful things I have learned have come from people I initially assumed had little to teach me.

That is an uncomfortable admission, but an important one.

It is easy to associate knowledge with titles, qualifications, years of experience or technical depth. I work in technology, where credentials and expertise matter. However, they can also create blind spots. The moment I decide I am the expert in the room, I start filtering out anything that does not arrive in the form I expect.

That is usually when I miss something valuable.

Expertise comes in different shapes

A new employee may not understand the technology yet, but they can instantly see which parts of the onboarding process make no sense.

A client may struggle to explain a technical problem, but they can tell me exactly how that problem affects their working day.

A junior technician may not know the official solution, yet their question can expose an assumption the rest of us stopped challenging years ago.

Even the person who strongly disagrees with me has something useful to offer. They show me where my explanation is weak, where my evidence is thin or where I have become too attached to my own position.

The lesson is not always delivered neatly. Sometimes I have to look for it.

Copilot does not replace that exchange

I see a similar issue appearing as organisations adopt Microsoft 365 Copilot.

People can start treating Copilot as the smartest participant in every conversation. They ask it to summarise the Teams meeting, draft the Outlook response and turn the discussion into a Word document. Those are useful actions, but the technology should not become an excuse to stop listening to the people involved.

A meeting summary can capture what was said. It cannot decide which quiet comment should change my thinking.

I recently imagined a typical project meeting where an experienced consultant outlined a polished solution. Near the end, someone from administration asked a simple question about how the customer would know what to do on Monday morning.

That question could easily disappear among the technical detail. Yet it might be the most important contribution of the meeting.

Copilot in Teams could help surface the question afterward. I could ask it to identify unresolved concerns, alternative viewpoints and questions that did not receive a complete answer. That gives me another chance to notice what I overlooked.

The value still comes from the person who asked the question.

Curiosity is a practical discipline

Learning from others does not require me to agree with everything they say. It requires me to remain curious long enough to understand why they see the situation differently.

I can ask:

  • What does this person notice that I do not?

  • What experience are they bringing to the conversation?

  • Which of my assumptions are they challenging?

  • What can I take from this, even if I reject their conclusion?

Those questions turn ordinary conversations into useful ones.

They also change how I lead. Instead of entering every discussion ready to provide the answer, I can enter looking for information I do not yet have. That creates room for people to contribute without first proving that they are the recognised expert.

I have never met anyone who knows everything. I have also never met anyone who knows nothing.

If I listen carefully, every conversation can leave me with a better question, a clearer explanation or a different way of seeing the problem. Copilot can help me capture and revisit those moments, but curiosity is what makes them matter.

The smartest person in the room may simply be the one still prepared to learn.

The mystery of personal SharePoint skills

Screenshot 2026-09-25 075006

You can ask Copilot in SharePoint to create a personal skill as you see above. When you do so it is store in your OneDrive for Business.

Screenshot 2026-09-25 075244

Specifically in:

My files > Documents > Copilot > Agent Assets > Skills > <Skill name>

Interestingly, I can’t find this documented anywhere officially. All I can find is information about SharePoint site skills here (i.e. saved into a SharePoint site):

Extend Copilot in SharePoint with skills

and mentions nothing about personal SharePoint skills, just site skills per:

Skills are stored as Markdown (.md) files in the Agent Assets library on the site, under /Agent Assets/Skills/<skill-name>/SKILL.md

Such as the follow site skill in my SharePoint site:

Screenshot 2026-09-25 080629

Note – “on the SITE” and there no mention in the article of ‘personal SharePoint skills’. However, as you see in my screen shots, you can definitely ask SharePoint to create a personal skill and it ends up in your OneDrive for Business.

So, the best advice is that personal skills in SharePoint are currently an ‘undocumented’ feature and should be used with caution because they may not be supported going forward. Hopefully, we’ll see official documentation on SharePoint personal skills shortly.

Your Success Does Not Need Everyone’s Approval

image

I used to think success would make relationships easier. Do good work, help people, build something useful, and surely the people around you would be pleased.

That is not always how it works.

Sometimes progress changes the way people respond to you. A new client, a growing business, a successful project or even a little public recognition can create distance where you expected encouragement. The reaction may be silence. It may be a dismissive comment. It may be somebody finding a reason why your achievement does not really count.

I have learned not to treat that as a signal to stop.

Success changes the comparison

Most people are comfortable with your ambition while it remains theoretical. They will often support the idea of you writing the book, launching the service, learning the skill or taking a bigger role. The atmosphere can change once you actually do it.

Your progress can become an uncomfortable reference point for somebody else. That does not make them bad, and it does not make you responsible for reducing yourself to restore their comfort.

I try to remember that another person’s reaction usually tells me more about their circumstances than it does about the quality of my work. I can listen for useful criticism without accepting every negative response as truth. Those are different things.

Keep the evidence close

This is where I find Microsoft 365 Copilot genuinely useful. Not as a machine for praise, but as a way to stay anchored in the work.

At the end of a month, I can ask Copilot to help me review the customer feedback in Outlook, summarise the decisions recorded in Teams meetings and identify the projects that moved from discussion to delivery. I can open the draft in Word and reflect on what improved, what stalled and what needs attention next.

That creates a more useful picture than the mood of one person in one conversation.

The evidence might show that clients received faster answers, a process became clearer, or a team finally documented knowledge that had lived in somebody’s head for years. None of that means the work was perfect. It means I can assess progress against outcomes rather than applause.

Approval is pleasant. Evidence is steadier.

Stay generous without shrinking

I do not want success to make me defensive. I still want to share what I know, acknowledge the people who helped me and remain open to being corrected. I also do not want to spend my energy persuading reluctant spectators to celebrate.

There is a practical balance here. I can be proud without becoming loud. I can keep improving without pretending that nothing went well. I can make room for other people’s wins without apologising for my own.

The people worth keeping close are not necessarily those who praise everything. I value people who can challenge my thinking, point out a blind spot and still want me to do well. Honest support is not constant agreement. It is the absence of quiet sabotage.

I now expect success to clarify some relationships. A few people will step closer. Some will remain neutral. Others may drift away. I do not need to turn that into a battle or a grievance.

I need to keep doing useful work, review it honestly and remain the kind of person I respect while doing it.

Not every seat in the audience needs to be filled. The work still matters.

Astra still wins but not on cost

image

With GPT 6 Sol now also available in Copilot, it is time for the LLM battle to continue and the results are in.

Astra 6 beats Sol 6 – https://github.com/directorcia/general/blob/master/Copilot/Comparisons/20260923-Cowork-GPT6Sol-Grok-eval.md

However, GPT 6 Sol is very cheap at 2,243 credits and that ranks towards the bottom of costs in Cowork as seen here.

Opus 5.5 = 23,494 credits

Astra 6 = 6,067 credits

Fable 5.1 = 3,453 credits

Fable 5 (Preview) = 3,387 credits [Model no longer shown]
Fable 5 (Copilot)(Preview) = 3,373.8 credits [Model no longer shown]

GPT 5.6 Sol = 2,800.50 credits
Sonnet 5 = 2,509.3 credits
Opus 4.8 = 2,487 credits [Model no longer shown]

GPT 6 Sol = 2,243 credits

Opus 5 = 2,240 credits

GPT 5.5 = 1,200 credits
GPT 5.6 Terra = 260 credits

I also decided to pit the recent Claude models against each other and found:

Opus 5.5 beats Fable 5 – https://github.com/directorcia/general/blob/master/Copilot/Comparisons/20260923-Cowork-F51vO55-Grok-eval.md

and it did so quite significantly if you look at the report. Opus 5.5 is clearly superior to Fable 5 according to my rudimentary benchmark. So it is really good but also really (really) expensive.

Remember, all the reports and created documents are here so you can judge for yourself:

https://github.com/directorcia/general/tree/master/Copilot/Comparisons

Let me know what you find.

Not Everyone Is Meant to Follow You Into the Next Chapter

image

I’ve learned that growth changes more than my skills, income or opportunities. It changes my conversations. It changes what I tolerate. It changes how I spend a quiet Saturday morning and what I am prepared to keep carrying into Monday.

That can be uncomfortable.

Sometimes I look around and realise that a relationship which once felt natural now requires me to become smaller. I have to avoid certain subjects, understate what I am building or apologise for taking my work seriously. The connection has not necessarily become hostile. It simply belongs to an earlier version of my life.

I used to feel guilty about that. I am learning not to.

Shared history is not a permanent contract

I value loyalty, but I no longer confuse loyalty with indefinite access.

Someone may have been important during one chapter without being suited to the next. I can appreciate what we shared without making the past responsible for every future decision. Gratitude does not require me to stop moving.

This is particularly visible when I begin changing how I work. I might establish clearer boundaries, become more deliberate about learning or decide that every client problem does not deserve an immediate late-night response. People accustomed to the old arrangement may interpret that as distance.

From my perspective, it may simply be discipline.

Growth often looks selfish to anyone who benefited from my lack of boundaries.

The tools reveal the habits

I see a similar pattern when businesses introduce Microsoft 365 Copilot.

The technology can help me summarise a long Outlook conversation, extract actions from a Teams meeting or turn rough notes into a structured Word document. But those capabilities quickly expose a deeper question: what am I going to do with the time and clarity I recover?

If I use that space to think more carefully, learn something difficult or work on a long-term goal, my behaviour begins to change. I stop treating a full inbox as proof of importance. I become less available for meetings with no purpose. I start asking whether activity is taking me anywhere.

Not everyone welcomes that change.

A colleague may keep forwarding every message because that is how the team has always operated. A friend may dismiss my learning routine because it disrupts an old social pattern. Separating from those habits does not mean I believe I am better than anyone. It means I have become more honest about the direction I want to travel.

Copilot can shorten the task, but I still have to decide what deserves the reclaimed attention.

I can leave without creating an enemy

I do not need a dramatic ending. I do not need a final argument, a scorecard or a speech explaining why I have moved on.

In many cases, I can simply reduce my participation in patterns that no longer serve either person. I can stop responding to gossip. I can protect time for learning. I can say no without assembling a courtroom defence. I can remain polite while becoming less available.

I also need to leave room for people to surprise me. Growth does not happen on my schedule alone. Someone may reconnect later with new experiences, stronger boundaries and a very different outlook. I do not have to burn the bridge to stop living on it.

The harder lesson is accepting that some people will remember a version of me that no longer exists. I cannot control that picture, and I do not need to keep performing it.

I can be thankful for the road we shared. I can wish them well. I can continue forward without turning my progress into an apology.

Sometimes maturity is not holding on more tightly.

Sometimes it is knowing when to loosen my grip.

Your Title Does Not Excuse Your Behaviour

image

I have met people with impressive titles who made everyone around them feel small. I have also met people carrying enormous responsibility who still remembered a name, answered a basic question and thanked the person who stayed late to help.

The second group always leaves the stronger impression on me.

Authority may change what sits in your diary, but it should not change how you treat the person standing in front of you. If success makes ordinary courtesy feel beneath you, I do not think success has improved you. I think it has exposed you.

People remember the small moments

Most professional relationships are not shaped by grand speeches. They are shaped by dozens of brief interactions: the reply sent without irritation, the interruption handled with patience, the credit passed to the person who did the work, and the mistake corrected without humiliation.

I see this clearly in technology work. A client may not understand an identity policy, a licensing problem or why a device has suddenly stopped complying. I can make that person feel foolish, or I can calmly explain what happened and what comes next. The technical answer may be identical. The experience is not.

The same applies inside a business. The newest technician, the person answering the phone and the contractor joining a Teams meeting all learn something from the way leaders respond under pressure. They learn whether questions are welcome. They learn whether problems can be raised early. They learn whether respect is real or just a value printed on a wall.

Technology carries your tone

I think digital work has made courtesy more important, not less. A short message in Teams can sound sharper than intended. An Outlook reply written between meetings can land as dismissive. A rushed instruction can leave someone wondering whether they have disappointed you.

This is one place where I find Microsoft 365 Copilot genuinely useful. Before sending a difficult email, I can ask Copilot in Outlook to make the draft clearer and more constructive. I am not outsourcing my judgement or pretending software can supply character. I am giving myself another chance to notice language that may close a conversation instead of moving it forward.

That small pause matters. Being busy is not permission to be careless with people.

Respect is practical leadership

I do not see civility as a soft extra. It affects whether people share bad news, challenge a weak assumption and admit when they need help. If every interaction with a senior person feels like a test, people will protect themselves. They will stay quiet, delay escalation and give the answer they think is safest.

A respectful leader gets better information because people are less afraid to speak plainly. That does not mean avoiding standards or difficult conversations. I can be direct without being cruel. I can reject an idea without belittling the person who offered it. I can hold someone accountable while leaving their dignity intact.

For me, the real test of professional character is not how I behave when everything is easy. It is how I behave when the inbox is overflowing, the client is unhappy and the same question has been asked for the third time.

A title may give me the final word. It does not give me the right to make someone regret speaking.

I want people to leave an interaction with me knowing where they stand, what needs to happen next and that they were treated properly. Achievements fade. Roles change. People move on.

The human impression remains.

I think we need a count back

image

I have been comparing all the LLMs as they become available in Copilot inside the different services in Microsoft 365. The previous winner was GPT 6 Astra, with the details here:

https://blog.ciaops.com/2026/09/17/astra-takes-the-trophy/

As is the world AI, it isn’t long before another new model becomes available, this time Opus 5.5, so I put it through the same test as all the other models and it produced this out which you can download yourself:

https://github.com/directorcia/general/blob/master/Copilot/Comparisons/20260816/20260923-Cowork-Opus55.docx

As always I pitted the newcomer against the incumbent with the analysis report here:

https://github.com/directorcia/general/blob/master/Copilot/Comparisons/20260923-Cowork-Opus55-Grok-eval.md

and is where the controversy is going to start. According to the ‘standard’ overall rating Astra scored 8.65 overall beating the newcomer Opus 5.5 with a score of 8.40. Close. However, if you dig a little further you see that Opus 5.5 score all 9’s for

– Evidence

– Detail

– Presentation

and was let down by

– argument

The overall score a weighted average in favour of argument. This helped Astra to pip Opus 5.5, but honestly I would suggest on review that Opus 5.5 is pretty much the equal of Astra 6 but a win is a win.

Ok, next point of amazement is that cost of Opus 5.5

Opus 5.5 = 23,494 credits

Astra 6 = 6,067 credits

Fable 5.1 = 3,453 credits

Fable 5 (Preview) = 3,387 credits [Model no longer shown]
Fable 5 (Copilot)(Preview) = 3,373.8 credits [Model no longer shown]

GPT 5.6 Sol = 2,800.50 credits
Sonnet 5 = 2,509.3 credits
Opus 4.8 = 2,487 credits [Model no longer shown]
Opus 5 = 2,240 credits

GPT 5.5 = 1,200 credits
GPT 5.6 Terra = 260 credits

So, the same prompt with Opus 5.5 cost a whopping US$235! That is roughly 5 x the cost of Astra 6 and almost 8 x the price of Fable 5.1, even though Opus 5.5 is supposed to be more ‘cost effective’ than Fable 5.1 according to Claude.

I’ll have to run a report and compare Opus 5.5 to Fable 5.1 and see what differences are evident but at 8 x the price they’d wanna be MASSIVE!

I have also updated the summary report for all the documents created by the different models here:

https://github.com/directorcia/general/blob/master/Copilot/Comparisons/20260816-File-paramters.md

GPT 6 Sol has also just been made available in Copilot so I’ll be testing that next.