Two years ago a security agent took down the planet. This month the vendors want us to hire a whole team of them. I keep waiting for someone in the room to laugh.

Two years ago: the kernel was the product

On 19 July 2024, CrowdStrike pushed a Falcon content update. Channel File 291. An out-of-bounds read. About 8.5 million Windows machines blue-screened. Airlines, hospitals, banks, emergency services. CISA spent days telling people it was not a cyberattack while criminals used the outage as cover for phishing.[5][6]

Microsoft’s number was 8.5 million devices, less than one percent of Windows. That is a rounding error until those devices are the ones that board planes and run ERs.[6]

The irony was already obvious in 2024. The thing we installed to stop attackers became a single point of failure because it sat in the kernel and we could not delay the file. CrowdStrike published the RCA on 6 August 2024. By then the joke had a name.[6]

I said then what I still believe: if your security control can reboot the business without a change ticket, it is not a control. It is a dependency. Treat it like one.

One year ago: passwords were still winning

August 2025 Patch Tuesday was 107 CVEs. One publicly disclosed Kerberos zero-day. Thirteen Critical. NTLM still had a Critical elevation-of-privilege in the pile (CVE-2025-53778).[2]

Microsoft’s Digital Defense Report 2025 said 97 percent of identity attacks were password spray. Not some novel AI worm. Spray. The same stupid attack we have been briefing executives about since Azure AD was still called Azure AD.[7]

We spent a year talking about agentic everything. The attackers spent a year typing Welcome1! into the front door.

Six months ago: we could not tell the agents from the people

In March 2026, CSA published the survey I still quote in architecture reviews. 73 percent of orgs expected AI agents to become vital within a year. 68 percent could not clearly distinguish AI agent activity from human activity. 74 percent said agents often get more access than they need. 31 percent let agents run under a human’s identity. IAM owned the problem in 9 percent of shops.[4]

January’s Ignite recap made the product response plain. Entra grew a new account type for agents, a registry, blueprints, Conditional Access targeting agent risk. None of that was generally available magic. A lot of it was preview, Frontier program, licensing TBD.[8]

February’s news cycle was industrial control and “assume they get in.” Illumio and the ICS crowd were still arguing containment while the identity teams were still arguing what to name the non-human.[9]

So the picture in February and March was: we will put agents everywhere, we cannot attribute them, and we will give them someone else’s badge.

This month: we made the agents the SOC

July 30, Microsoft announced Project Perception. Red agents attack. Blue agents investigate. Green agents harden. Continuous loops. Ambient, autonomous security.[3]

August 4 they shipped Zero Trust for AI assessments, a DevSecOps pillar with 91 tasks, and an e-book about rebuilding controls for agentic systems.[11]

July 13 they said passkeys become the default in Entra on 1 September 2026, and Microsoft-provided SMS and voice die on 1 February 2027. That part I actually like. Password spray at 97 percent is a policy failure with a calendar now.[12][7]

August Patch Tuesday then dropped 415 CVEs, including an exploited WinSock zero-day and a tampering bug in the Windows container isolation filter driver. The patch pile quadrupled in one year. The kernel is still the product.[1][2]

The joke

Two years ago the security agent we did not govern crashed the world.

One year ago identity was still a password problem.

Six months ago we admitted we cannot tell the new non-humans from the humans, and we still handed them inherited access.

This month we asked those same non-humans to run the SOC, and we published a workshop so we can feel better about it.

I am not against agentic defense. I am against skipping the boring part. Give the agent its own identity. Least privilege that is not a copied user token. Logs that say which blueprint did the thing. A kill switch that does not require a USB stick and fifteen reboots.

If we cannot answer “who did that” for a Copilot Studio agent, we have no business letting a green agent close the ticket.

Passkeys by default is the one change in this stack that would have helped in 2025. Patch the NetScalers. Name the agents. Then we can talk about letting them hunt.


Sources

[1] https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-august-2026 — August 2026 Patch Tuesday CrowdStrike [2] https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-august-2025 — August 2025 Patch Tuesday CrowdStrike [3] https://www.microsoft.com/en-us/security/blog/2026/07/30/whats-new-in-microsoft-security-july-2026 — Microsoft Security July 2026 [4] https://cloudsecurityalliance.org/press-releases/2026/03/24/more-than-two-thirds-of-organizations-cannot-clearly-distinguish-ai-agent-from-human-actions — CSA AI agent identity survey March 2026 [5] https://en.wikipedia.org/wiki/2024_CrowdStrike-related_IT_outages — CrowdStrike outage Wikipedia [6] https://www.cisa.gov/news-events/alerts/2024/07/19/widespread-it-outage-due-crowdstrike-update — CISA CrowdStrike alert [7] https://www.microsoft.com/en-us/corporate-responsibility/topics/cybersecurity/reports/microsoft-digital-defense-report-2025 — MDDR 2025 [8] https://virtualizationreview.com/articles/2026/01/08/ai-agents-taking-over-the-world.aspx — Entra Agent ID Ignite recap [9] https://www.illumio.com/blog/top-cybersecurity-news-stories-from-february-2026 — Illumio February 2026 cyber news [11] https://www.microsoft.com/en-us/security/blog/2026/08/04/advance-zero-trust-for-ai-new-tools-and-guidance-to-secure-ai-agents-and-devsecops — Zero Trust for AI Aug 2026 [12] https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id — Entra passkeys default

Drafted at the Dark Pixel Tech desk.