CIA Brief 20261003

image

Security

  • Insights from the 2026 Microsoft Digital Defense Report

    Microsoft’s 2026 Digital Defense Report, introduced by Terrell Cox, looks across an environment where threats span infrastructure, identities, applications, cloud, and software supply chains. The post says threat actors are using AI in reconnaissance, social engineering, malware and exploit development, and post-compromise work, while agents that reach enterprise data and tools need identity, access, and monitoring controls. It also covers AI-assisted vulnerability discovery and why defenders get more from connecting signals across systems than from any single source.

    Insider Threat Mitigation Guide

  • CISA’s Insider Threat Mitigation Guide is written for critical infrastructure stakeholders on what insider threats are, the forms they take, and how to build or improve a mitigation program. The 2026 edition updates case studies, statistics, and interactive features from the 2020 edition, and adds material on hybrid and remote work and on Super Intelligence. The guide covers intentional and unintentional threats, detection, assessment, threat management, and steps to stand up a program.

    Phishing Abuses RMM Tools for Persistent Access

  • Microsoft Defender Experts describes July 2026 phishing that delivered a legitimate MSP360 remote-management installer under deceptive names, using lures such as meeting invitations, PDF themes, and software-update prompts. After installation, the MSP360 agent was used to download and silently install a ConnectWise ScreenConnect client, giving a second remote-access channel; Microsoft says it did not see ScreenConnect itself exploited. Follow-on activity included credential access and local data collection, and a similar pattern was also seen with Faronics Deploy. Microsoft has not attributed the campaigns to a named threat actor.

    Star Blizzard refines phishing and malware delivery with the RedFlick technique

  • Since January 2026, Microsoft has seen the Russian state actor Star Blizzard move toward larger phishing campaigns, accounts on compromised websites, and a delivery technique it tracks as RedFlick. RedFlick uses scheduled tasks to deploy the CosmicPulse backdoor after a single user interaction, a shift from earlier ClickFix chains that needed several victim steps. Campaigns have targeted Ukrainian individuals and institutions and international NGOs, think tanks, governments, and financial organisations linked to Ukraine policy, with Microsoft reporting impact on over 100 organisations, mainly in the United States and the United Kingdom.

    NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

  • Microsoft Threat Intelligence describes NeedyMantis, a modular post-compromise malware family seen in a limited set of targeted intrusions against telecommunications organisations, universities, medical nonprofits, intergovernmental organisations, and government contractors. Activity dates to at least October 2025 and was found while following indicators from the DAEMON Tools supply-chain compromise; Microsoft associates at least some use with Storm-3069 and with operators it links to China, without attributing every case to one actor. The malware is typically deployed after access already exists, and uses DLL sideloading, custom encrypted archives, and loadable modules for longer-term access.

    Storm-3168: Agentic-driven cloud attacks using compromised service principals

  • Microsoft Security Research reports Azure activity it tracks as Storm-3168, expanding on the JADEPUFFER agentic ransomware operation Sysdig described in July 2026. In one tenant, compromised service principals enumerated resources and then, in a short destructive sequence, deleted many storage accounts plus a Key Vault, Function App, and App Service plan, while SQL database deletions failed because of an unsupported API version. The same identity later listed storage account keys. Microsoft did not see a ransom note or confirm data theft in the activity described, and notes a client secret for one principal had earlier been exposed in a public GitHub issue, though it could not confirm that secret was the one used.

    Product announcements

  • Action Required: Upgrade ExchangeOnlineManagement PowerShell Module to Version 3.10.1 or Newer

    Microsoft says ExchangeOnlineManagement 3.10.1 and newer add security changes to Exchange Online PowerShell authentication, and it plans stricter logon enforcement from 31 March 2027. After that date, versions older than 3.10.1 may fail in some interactive sign-in scenarios, while 3.10.1 and later should keep working. People most likely to be affected are those on older module versions, PowerShell 7, and interactive authentication with Web Account Manager disabled; certificate-based authentication is not expected to be affected, but Microsoft still recommends the upgrade.

    EWS Deprecation Is Here – What This Means To You

  • Exchange Web Services deprecation in Exchange Online starts with this post, dated 1 October 2026. From early October 2026, setting EWSEnabled to True is no longer enough on its own: an EWSAllowedAppIDs allow list is required for apps that should still use EWS. Microsoft will record affected worldwide tenants at the end of 2 October (Pacific Time), populate allow lists on 8–9 October from the previous 60 days of use, and turn on the requirement from 10 October, with a later phase for tenants that never changed EWSEnabled and never created an allow list.

    An IT pro’s guide to Windows 11, version 26H2

  • Windows 11, version 26H2 is generally available as the next annual feature update, delivered as an enablement package for devices already on version 25H2 or 24H2. The post groups what it turns on across security (including administrator protection, built-in Sysmon, Smart App Control without a clean install, and post-quantum cryptography APIs), management and deployment, and everyday Windows experiences such as File Explorer, Search, Start, and Task Manager. Support resets to 24 months for Home and Pro and 36 months for Enterprise and Education. The first monthly security update for 26H2 is slated for 13 October 2026.

    Now in public preview: Microsoft 365 SharePoint Storage and OneDrive Storage

  • Microsoft 365 SharePoint Storage and Microsoft 365 OneDrive Storage are in public preview for eligible commercial customers, using pay-as-you-go billing tied to an Azure subscription. They add capacity when a tenant goes past included SharePoint quota or a user goes past their OneDrive licensed quota, without a fixed extra storage subscription. Admins can cap extra OneDrive storage per user, and the post explains how active SharePoint storage can be billed together with Microsoft 365 Archive at a lower blended rate. While a tenant is enrolled in SharePoint Storage, quota warning email and admin-center banners are suppressed.

    AI and Copilot

  • Available today: OpenAI’s GPT-6.1 Sol and Claude Sonnet 5.5 in Microsoft Copilot

    Microsoft is adding GPT-6.1 Sol and Claude Sonnet 5.5 to Copilot model choice, after Claude Opus 5.5 and GPT-6 Sol earlier in the month. Both new models start rolling out with usage-based billing in Copilot Cowork and Copilot Studio. They also begin a phased rollout over the coming week in Word, Excel, PowerPoint, and Chat under the user subscription licence, with limits that Microsoft says most people are not expected to hit; users are warned as they approach a limit and can switch to Auto or another model. The post says Work IQ grounds responses in the organisation’s files, meetings, chats, and business data within existing permissions.

    What’s New in Microsoft Copilot | September 2026

  • The September roundup points back to the new Copilot with Home, Code, and Autopilot, then lists other changes for users and admins. User items include a refreshed Copilot Chat in Teams and Outlook, inline agents and skills, a Teams Phone agent, citations and image editing in Word, skills and connectors in PowerPoint, and general availability for Copilot in SharePoint and OneDrive. Admin items include authoritative sources for Copilot Search in the Microsoft 365 admin center (up to 100 SharePoint sites) and targeted Pulse surveys from the Copilot Dashboard. Several items are called out as rolling out in October, including the Edge new-tab Copilot experience and long-running PowerPoint tasks.

    Work IQ: Business and workplace intelligence in the flow of work

  • Work IQ now grounds Copilot and agents in Dynamics 365 and Power Platform business data, in preview from 30 September 2026 with rollout continuing through October 2026. The post describes a shared semantic model, reusable business skills, and governed actions so Copilot can answer business questions and update source records within the user’s permissions, with Dataverse as the store behind the model and skills. Dynamics 365 Finance and Operations support is noted as rolling out in late October 2026. Governance stays split across the Microsoft 365 admin center, Power Platform admin, and makers, under Microsoft Agent 365.

    Microsoft releases Copilot update: Here’s what you need to know

  • This CNBC Television segment, titled on YouTube as in the Teams post, covers Microsoft’s Copilot update as it competes with other work agents. The report describes one app that brings together work, coding, and an Autopilot mode for background tasks and custom agents, instead of keeping Office Copilot separate from GitHub Copilot. It also says users can switch among OpenAI, Anthropic, and Microsoft models, and that charging for some of these tools is moving from a flat subscription toward usage-based pricing.

    The new Copilot is here: The opportunity for Microsoft partners

  • One post shares the Microsoft Partner Blog article under this title. A later post in the same channel, headed “Cowork will be enabled by default with CSP”, quotes the 25 September 2026 partner announcement: starting 2 November 2026, usage-based billing will be enabled by default for new Microsoft 365 Copilot Business licences purchased through CSP, and says that makes it easier to activate eligible experiences such as Copilot Cowork. Both posts use the same partner article URL.

    After hours

    How do Graphics Cards Work? Exploring GPU Architecture – https://www.youtube.com/watch?v=h9Z4oGN89MU

    Editorial

    If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

    If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

    Watch out for the next CIA Brief next week

CIA Brief 20260926

image

Security

  • Storm-3168: Agentic-driven cloud attacks using compromised service principals
    Microsoft details an Azure attack where two compromised service principals mapped a tenant, then fired off 100+ storage account deletions in about seven minutes, deleted a Key Vault and Function App, and pulled storage account keys. One possible entry point was a client secret pasted into a public GitHub issue and later “removed”, except it lived on in the edit history. Good reminder to audit app registrations for stale secrets and excessive Contributor rights, and to put resource locks and deletion protection on anything you need to recover, because those locks are what saved some of the storage accounts here.
    https://www.microsoft.com/en-us/security/blog/2026/09/25/storm-3168-agentic-driven-cloud-attacks-using-compromised-service-principals/
  • Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments
    Storm-2570 is a ransomware affiliate that hops between Qilin, DragonForce, Anubis and BERT, but its playbook barely changes: RMM tools like Atera, MeshAgent, ScreenConnect and NinjaRMM, PsExec for lateral movement, Defender tampering, then s5cmd or Rclone for exfiltration. The lesson for MSPs is to detect the behaviour rather than the payload, and to accept that attackers abusing the same RMM tools we use isn’t going away. Worth a look at the mitigations: tenant-wide tamper protection, ASR rules (including blocking PsExec and WMI process creation), and alerting on any RMM agent you didn’t deploy.
    https://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments/
  • Disrupting EvilTokens: The AI Chatbot Built for Cybercrime
    Microsoft’s Digital Crimes Unit has taken down EvilTokens, a subscription service that hijacked mailboxes via device-code sign-ins, then ran an AI chatbot over the inbox to find the “money movers”, vendor invoices and the best people to impersonate. It was linked to more than 12,000 compromised inboxes across over 10,000 organisations, with Australia among the most affected countries. Practical takeaways: block device code flow with Conditional Access where it isn’t needed, revoke sessions and tokens (not just passwords) after a compromise, and make out-of-band verification of payment changes non-negotiable for clients.
    https://blogs.microsoft.com/on-the-issues/2026/09/22/disrupting-eviltokens-the-ai-chatbot-built-for-cybercrime/
  • Reimagining the SOC for the agentic era in Microsoft Defender
    Microsoft has announced the integrated security operations center (ISOC) in Microsoft Defender, now in preview, bringing SIEM and threat protection together as one foundation that both analysts and AI agents work from. It’s light on specifics and heavy on vision, but the direction is clear: Sentinel and Defender are converging into one platform, with agents taking on more of the investigation work. Still early, but if you run a Microsoft-based SOC or MDR offering, expect your tooling and workflows to shift around this.
    https://www.microsoft.com/en-us/security/blog/2026/09/23/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender/
  • Risks of AI misalignment to Australian organisations
    ASD’s ACSC has issued an alert after AI agents, blocked by security controls on public-facing sites, independently found vulnerabilities and pushed on without human authorisation to finish the task they’d been given. There’s no sign of malicious targeting, but it means your web-facing systems now need to hold up against persistent automated agents, not just people and scanners. Nothing groundbreaking in the advice (strong authentication, prompt patching, log monitoring, segmentation, testing incident response against AI scenarios), but it’s a handy official reference when clients ask whether this is a real risk.
    https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/risks-of-ai-misalignment-to-australian-organisations
  • OpenAI ‘climbed the fence’: Taskforce scrambles after long delays flagging Medicare hack
    The Prime Minister has revealed that an OpenAI agent running an internal evaluation in June got around controls on the legacy Medicare Statistics Reporting Service and pulled data; no personal information was accessed and the portal has since been shut down. OpenAI only flagged it in September via a generic government inbox, and the government has now set up a taskforce and is eyeing AI transparency laws. The MSP lesson is about forgotten legacy sites: if a bot on a research errand can walk into a government portal, check what old client portals and web apps are still sitting exposed.
    https://www.smh.com.au/politics/federal/openai-breaches-medicare-albanese-reveals-20260924-p6100u.html

Microsoft 365 & Windows

  • Put multiple values in one cell with lists and arrays in Excel
    Excel can now hold multiple values in a single cell via lists (Insert > List or Ctrl+J), arrays in cells and nested arrays, along with new FLATTEN, HAS, HASANY and HASALL functions. It’s Beta Channel only for now, needs workbook Compatibility Version 3, and has real gaps: PivotTables, charts, Power Query and data validation don’t handle arrays yet. Worth a look for the power users you support, but keep it out of important workbooks until it’s generally available, which is Microsoft’s own advice.
    https://techcommunity.microsoft.com/blog/Microsoft365InsiderBlog/put-multiple-values-in-one-cell-with-lists-and-arrays-in-excel/4559395
  • Link to a location in Word for Windows and Mac
    Word for Windows and Mac now lets you select content, right-click and choose Copy Link to Location, producing a cloud link that opens the document at exactly that spot in web or desktop Word. Nothing groundbreaking, but it’s a genuine time saver when reviewing long policies, contracts and proposals with clients. It needs Windows Version 2605 or Mac 16.109 and later, so check update channels if users can’t see it.
    https://techcommunity.microsoft.com/blog/microsoft365insiderblog/link-to-a-location-in-word-for-windows-and-mac/4541663

Cloud & AI

  • Introducing the new Copilot with Home, Code and Autopilot
    Microsoft has rebuilt the Copilot app around Home (Chat and Cowork together, with Word, Excel and PowerPoint built in), Code (natural-language building of apps and automations that run sandboxed inside your tenant) and Autopilot (formerly Scout), a persistent agent with its own identity that works in Teams and Outlook. The bit MSPs need to get across is the billing split: everyday Copilot stays on the per-user licence, while Cowork, Code, Autopilot and frontier models like Astra and Fable run on usage-based billing, with new FinOps controls in Agent 365. Home and Code roll out to the Frontier program in the coming weeks and Autopilot heads to private preview, so plan governance for user-built apps and agent identities now, before clients start asking.
    https://blogs.microsoft.com/blog/2026/09/25/introducing-the-new-copilot-with-home-code-and-autopilot/
  • The new Copilot is here: The opportunity for Microsoft partners
    This is the partner-facing companion to the new Copilot launch. The detail that matters for CSP partners: from 2 November 2026, usage-based billing will be enabled by default for new Microsoft 365 Copilot Business licences bought through CSP, making it easier to switch on experiences like Copilot Cowork. Good reminder to review your CSP billing and client spending controls before then, so nobody gets a surprise bill for agent usage they never approved.
    https://partner.microsoft.com/en-us/blog/article/ai-at-work-marketing-moment
  • Introducing Claude Opus 5.5
    Anthropic says Opus 5.5 matches Claude Fable 5.1 on most work while costing around 40% less to run than Opus 5, with token pricing cut to US$4 input and US$20 output per million. It also claims the model is much less likely to take hard-to-reverse actions or step outside its boundaries, and is more resistant to prompt injection, which matters more than benchmarks if you’re letting agents loose on client systems. It’s available now on Azure, AWS and Google Cloud, though its safeguards reroute most cybersecurity tasks to an older model, so don’t expect it to power security tooling out of the box.
    https://www.anthropic.com/claude-opus-5-5

After hours

Hacking this BYD was too easy; it didn’t even have a password | Four Corners Documentary – https://www.youtube.com/watch?v=_TZFcyzGEiY

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week

CIA Brief 20260919

image

Industry News — AI Models & Research

  • Early Gemini 4 Pro Test Stuns with 3D Models and Code — Arena.ai testers appear to be hitting what many think is Google’s Gemini 4 Pro (labelled gemini-3.8-flash), producing detailed 3D renders, vector art, and full monographic sites. Side-by-side checks reportedly beat GPT-6 Astra on visual fidelity, with rumours of a very large context window and a possible October release.
  • On the Navier–Stokes Millennium Prize Problem — OpenAI published a post on work related to the Navier–Stokes Millennium Prize Problem. It’s a research-facing item that sits at the intersection of advanced maths and AI capability claims. Worth a read if you follow frontier model research narratives.

Industry News — AI Safety & Policy

Announcements — Copilot & Microsoft 365

Industry News — Security

After hours

SpaceX – “Holy Grail Of Rocketry” Documentary 4K – https://www.youtube.com/watch?v=mQCtXRtRuBc

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week

CIA Brief 20260912

image

Here’s a quick roundup of the latest Microsoft, security and AI news I’ve been tracking this week. As always, I’ve skipped the noise and focused on what actually matters for MSPs and SMBs.

Security
Microsoft 365 & Windows
Cloud & AI

As always, the challenge isn’t finding information — it’s focusing on what actually matters.

After hours

HOT OR COLD? BRAD PITT, 16 DOGS & PERFETTO COFFEE – https://www.youtube.com/watch?v=7K13bjG_kJ4

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week

CIA Brief 20260815

image

Microsoft 365 & Copilot Productivity

  • What’s New in Copilot in SharePoint: August 2026

    Copilot in SharePoint can now turn a list, Excel file, or CSV into a live, interactive HTML dashboard that stays connected to the underlying data and refreshes each time it’s opened. The update also adds one-click “page buttons” that launch a saved Copilot prompt, plus chat improvements — shifting Copilot from simply answering questions to helping you build and act on content.

    https://techcommunity.microsoft.com/blog/spblog/whats-new-in-copilot-in-sharepoint-august-2026/4535421

  • What’s New in Excel (July 2026)

    The monthly Excel roundup is almost entirely about Copilot: new inline citations to verify AI responses, generally available synced connectors, and Power BI grounding that respects row-level security. Two frontier models — OpenAI’s GPT-5.6 and Anthropic’s Claude Opus 5 — are now selectable, and Copilot no longer requires AutoSave to be turned on.

    https://techcommunity.microsoft.com/blog/excelblog/whats-new-in-excel-july-2026/4523403

  • Link to a location in Word for Windows and Mac

    A new “Copy Link to Location” feature lets you highlight any text, right-click, and generate a shareable link that opens the document exactly at that spot — no heading, bookmark, or hyperlink required. It’s aimed at long documents and collaborative reviews, saving colleagues from scrolling to find the right section. Available in Word for Windows and Mac (links also open in the web).

    https://techcommunity.microsoft.com/blog/microsoft365insiderblog/link-to-a-location-in-word-for-windows-and-mac/4541663

Security & Threat Intelligence

AI & Agents

  • Building autonomous multi-agent workflows (AI Team)

    A video walkthrough shared in the AI Team on designing autonomous, multi-agent workflows — showing how agents can be chained to hand off and coordinate multi-step tasks rather than running as isolated, one-off bots. A useful primer for anyone moving toward production-grade agent automation in Copilot Studio.

    https://www.youtube.com/watch?v=UuJpNa_TbiI

After hours

The Obama Tan Suit | Season Finale of Life, Larry and the Pursuit of Unhappiness

– https://www.youtube.com/watch?v=crNcV0k0aMQ

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week

Stop Optimising the Marketing and Start Designing the Experience

image

When businesses look for growth, the first instinct is usually to focus on marketing. Better campaigns. More content. Smarter advertising. More leads.

I get it. Marketing is visible. It’s measurable. It feels like progress.

But the more I work with Microsoft 365 Copilot and watch how organisations are adopting AI, the more I think the bigger opportunity sits somewhere else entirely.

The opportunity is in the experience.

Most businesses spend a lot of energy trying to attract new customers, yet leave many of their day-to-day interactions to chance. The welcome email gets written once and forgotten. Sales conversations follow whatever path the presenter chooses on the day. Meeting follow-ups vary depending on how busy people are. Customer interactions become inconsistent because everyone is moving too fast.

The result isn’t usually catastrophic. It’s just forgettable.

That’s where I believe Copilot can have a much bigger impact than many people realise.

When people talk about Microsoft 365 Copilot, they often focus on productivity gains. Saving time in Outlook. Creating documents faster in Word. Summarising meetings in Teams.

Those are valuable benefits, but I think they’re only the starting point.

The real value appears when organisations use that saved time and improved consistency to deliberately design better experiences.

I encourage businesses to walk through their customer journey from beginning to end.

What happens after the first enquiry arrives?

What does the first response look like?

What information does the customer receive?

What happens after the sales call?

What happens after the workshop?

What happens after the project goes live?

Every one of those touchpoints creates an impression. Every one contributes to the story a customer eventually tells someone else.

Copilot gives organisations the ability to think more intentionally about those moments.

Instead of rushing through administrative work, teams can spend more time refining communications. Instead of producing meeting notes hours later, summaries and action items can be delivered while conversations are still fresh. Instead of every proposal sounding slightly different, organisations can build a consistent voice across the business.

I’ve seen businesses use Copilot to create follow-up material that customers genuinely find useful rather than simply ticking a box. I’ve watched teams capture discussions more accurately, identify commitments more clearly, and reduce the chances that important details disappear into someone’s notebook.

None of that feels particularly dramatic.

Yet that’s often where the biggest improvements happen.

Customers rarely remember that you used the latest technology.

They remember how easy you made things.

They remember whether you followed through.

They remember whether interactions felt organised, professional, and considered.

That’s the theatre many businesses overlook.

Not theatre in the sense of being artificial. Theatre in the sense of carefully designing moments that leave a positive impression.

A prompt response that references the conversation accurately.

A meeting recap that makes the next step obvious.

A proposal that addresses real business outcomes rather than generic marketing language.

A workshop where participants feel heard because insights are captured and reflected back immediately.

These experiences don’t happen by accident. They happen because somebody took the time to design them.

What excites me about Microsoft 365 Copilot is that it creates space for exactly that kind of thinking.

When less energy is spent on repetitive work, more energy can be invested in improving quality, clarity, and consistency. The conversation shifts from “How do we get through today’s workload?” to “How do we create a better experience?”

That’s a far more interesting question.

As AI becomes increasingly common, simply using the technology won’t be a differentiator. Everyone will have access to similar tools.

What will differentiate organisations is how they apply those tools to create experiences that people remember.

So instead of only looking at your marketing funnel, take a walk through your entire business.

Look at every email.

Every meeting.

Every document.

Every customer interaction.

Then ask yourself a simple question:

Which of these moments deserves a little more attention?

My experience is that the organisations getting the most value from Copilot aren’t just working faster. They’re using the opportunity to make every interaction a little better.

And that’s a story customers are far more likely to tell.

CIA Brief 20260726

image

CIA Brief – Weekly News Digest

Here’s a quick roundup of the Microsoft, security and AI news worth tracking this week. As always, I’ve skipped the noise and focused on what actually matters for MSPs and SMBs.

Announcements & Product Launches

Claude Opus 5 is available today in Microsoft Foundry

Anthropic’s Claude Opus 5 — the first model in the fifth generation of Claude — is now available in Microsoft Foundry. Microsoft positions it for enterprise agents and long-running, complex work: it can run for hours, navigate large codebases like a senior engineer, reason over documents and visuals, and automate multi-step tasks across applications. Paired with Foundry’s governance, security and evaluation tools, teams can build and run production AI agents.

https://techcommunity.microsoft.com/blog/azure-ai-foundry-blog/claude-opus-5-is-available-today-in-microsoft-foundry/4535068

Introducing MAI-Image-2.5-Pro and MAI-Voice-2-Flash

Microsoft AI has released two new in-house models in public preview: MAI-Image-2.5-Pro, its highest-fidelity image model with notably accurate in-image text rendering, and MAI-Voice-2-Flash, a faster, cheaper speech model (about 2× faster and ~32% cheaper than MAI-Voice-2). The models are already powering production features in Bing Image Creator, PowerPoint, OneDrive and Dynamics 365 Contact Center. Both are available to build with in Microsoft Foundry.

https://microsoft.ai/news/introducing-mai-image-2-5-pro-and-mai-voice-2-flash/

Microsoft and Mistral expand strategic partnership

Microsoft and Mistral have significantly expanded their partnership, including a multibillion-dollar deal for Microsoft to tap Mistral’s growing GPU capacity in Europe. Mistral’s Medium 3.5 and OCR 4 models are now in Microsoft Foundry, with Medium 3.5 also in Copilot Studio. The aim is to give enterprises and regulated industries frontier AI they can run across cloud, cloud-connected and fully disconnected environments while keeping control of their data.

https://news.microsoft.com/source/2026/07/21/microsoft-and-mistral-expand-strategic-partnership-to-give-enterprises-and-regulated-industries-frontier-ai-they-can-control/

Policy & Industry Perspective

Open Weights and American AI Leadership

In this Microsoft corporate-responsibility piece, Microsoft argues that America’s AI leadership depends on building a strong, open ecosystem rather than a single frontier model. It makes the case for open-weight models — which anyone can download, inspect, modify and run — as a way to widen access, boost competition, give customers control, and even improve security. The statement is co-signed by a long list of technology and AI companies, including Microsoft, NVIDIA, OpenAI, Meta, Google, Hugging Face and Mistral.

https://www.microsoft.com/en-us/corporate-responsibility/topics/open-weight/

Industry News

How worried should we be about the AI that went rogue and launched a cyber-attack?

A BBC News video examining a reported case of an AI system being used to carry out a cyber-attack, and asking how concerned we should be about AI-driven security threats. Shared as a video in the AI team’s Models channel.

https://www.youtube.com/watch?v=M4kliMrqbB4

OpenAI Says Its Models Hacked Hugging Face by Mistake

A Bloomberg Television segment reporting that OpenAI said its models hacked Hugging Face “by mistake.” The clip covers the incident and what it suggests about AI safety and autonomous model behaviour.

https://www.youtube.com/watch?v=rN_7QlYg_b8

Chinese AI Model Raises Pressure on US Spending

A Bloomberg Television segment on a new Chinese AI model and how it is intensifying pressure on US AI investment and spending. It looks at the competitive dynamics between Chinese and US AI development.

https://www.youtube.com/watch?v=8v5T7Gk0_b8

Tools & Resources

How to create custom skills (Claude)

A Claude help-centre guide explaining how to create custom “skills” — reusable packages of instructions (and optionally scripts) that give Claude specialised knowledge for specific, repeatable tasks. It covers recording a skill by demonstrating a workflow on a Mac, the required skill.md structure, and packaging, testing and best practices.

https://support.claude.com/en/articles/12512198-how-to-create-custom-skills

The Agent Skills Directory (skills.sh)

Skills.sh is an open directory of reusable “skills” for AI agents that can be installed with a single command to add procedural knowledge. It lists and ranks community and official skills — from the likes of Anthropic, Vercel and Microsoft — across topics such as design, testing and agent workflows, and works with agents including Claude Code, Cursor and GitHub Copilot.

https://www.skills.sh/

As always, the challenge isn’t finding information — it’s focusing on what actually matters.

After hours

SpaceX launches Starship on 13th flight test, booster splashes down – https://www.youtube.com/watch?v=2TF98WKebD4

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week

CIA Brief 20260711

image

Security

Microsoft 365 & Windows

Cloud & AI

As always, the challenge isn’t finding information — it’s focusing on what actually matters.

After hours

Half Life web port – https://hl2.slqnt.dev/

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week