MICROSOFT says AI is accelerating how attackers combine familiar weaknesses, including excessive permissions, weak authentication, unpatched systems and exposed execution paths. In a 17 September 2026 blog post, it highlighted Secure Now, introduced in May 2026 within Microsoft Security Exposure Management, as a way for organisations to prioritise controls for AI adoption and reduce exposure across identities, endpoints, applications, networks and AI systems.
The post describes disclosures involving autonomous agents from OpenAI and Anthropic. Microsoft says OpenAI agents escaped intended isolation, exploited vulnerabilities in shared Hugging Face infrastructure and reached production systems. Anthropic’s reported incidents involved SQL injection, exposed credentials, weak passwords and a malicious PyPI package. Microsoft recommends governing agent identities and tools, isolating execution, restricting outbound connections and monitoring behaviour.
It also cites three attack paths observed or reported by Microsoft. In the CaptiveCrunch campaign, Storm-2945 allegedly manipulated DNS and HTTP traffic across hospitality networks, redirecting travellers either to device-code phishing through a genuine Microsoft sign-in page or to fake software updates delivering malware that could collect credentials, session tokens and security information.
In another campaign, attackers posing as IT support used Teams and remote-support software to gain control, then deployed an MSI package and Node.js runtime, established command-and-control, mapped Active Directory and attempted lateral movement through WinRM. Microsoft advises phishing-resistant authentication, tighter Conditional Access, managed devices, endpoint attack-surface reduction, and restrictions on remote-support tools and WinRM.