Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Claude Cowork Activity Isn't Captured in Compliance Logs

Is your AI compliance up to par? Anthropic's deputy CISO reveals that Claude Cowork activity isn't captured in compliance logs. If you're in a regulated EMEA sector, DORA's ICT logging and the EU AI Act's obligations are here. Relying on a self-configured OTel stream isn't enough for formal audits. Stay informed about data boundaries and privacy reviews before enabling streams.

Ep. 83 - Anthropic's CISO Guide to Agentic AI: Your Next Insider Threat Is an AI Agent

An AI agent that drifts from your intent looks exactly like an insider attack: legitimate credentials, sanctioned tools, plausible actions, at machine speed. In this episode, we break down Anthropic's "Zero Risk Isn't the Job" CISO guide: a four-question review framework, seven vendor-neutral controls, and why egress allowlisting is the strongest defense against prompt injection. Plus: the Claude Opus 4.5 upgrade that had an incident-response agent recruit another agent, and why agentic AI needs continuous adversarial exposure validation.

The Authorization Trap: Why "No Evidence of Manipulation" Doesn't Mean "No Incident"

Ask AI to Choose a prompt Write a TLDR of this post Explain the security risk Summarize what CISOs should know Many conversations about AI agent risk over the past year start from the same unspoken assumption: something bad happened because someone or something manipulated the agent. A hidden instruction in a document, a poisoned prompt, an adversary steering the model toward an action it shouldn't take. That's a real category of risk, and it deserves the attention it's getting.

Agentic AI Security Platforms: What Agent Logs Miss

An agent’s logs are written by the agent. Every framework log, trace span and tool-call record that an agentic AI security platform ingests comes from the process being watched, or from a gateway that sees only what that process routes through it. When a trusted prompt coerces an agent into misusing a permission it already holds, the record shows a normal tool call, because from inside the process it was one. Running more analysis on that record returns the same answer faster.

Zero Trust for AI Agents: What to Verify When There Is No Session

The agent that worries you is authorized. It holds a service account you provisioned, calls tools you approved, and reaches destinations someone signed off on. Zero trust asks two questions at every decision point, who is this and what are they allowed to do, and an agent redirected by trusted input answers both correctly every time. For a person those questions fire at a session boundary, where context gets re-checked. An agent on Kubernetes has no such boundary.

Agentic AI Security Risks, Ranked by Recovery Cost

The board wants to know which AI agent risk to fund first, and a likelihood score cannot answer it. No incident survey gives base rates for agents on your architecture, and an agent can take a different path on the same input. What a CISO can estimate is what each risk would cost to recover from: the work to detect it, scope it, revoke the authority it used, and prove what happened. Ranked on that cost, unexpected code execution drops toward the bottom.

NIST AI Agent Authorization: Five Asks Mapped to Kubernetes

NIST has published no AI agent authorization standard, and nothing in its February 2026 draft gives an auditor a control to test. What the NCCoE did publish is more useful to a CISO with an audit on the calendar: five areas of interest that read like an assessor’s question list. Together they ask which agent acted, on whose behalf, under what authority, and with what record. A Kubernetes cluster has a primitive it can point to for each area.

Apono Partners with Databricks to Govern Privileged Access Across the Lakehouse

Databricks has become the data and AI platform of record for a large and growing share of the enterprise market. Unity Catalog gives teams unified governance over data assets, AI models, and agentic workflows, controlling what exists, who can use it, and what policies apply.

The 3 AM Incident Triage: A Tired Brain vs. The Truth

The alerts come in at 3 AM. You've been awake for a full day and into the night, and there are critical questions you have to answer: Is this our problem, or someone else’s? A routing change that went sideways or lateral movement? A misconfigured ACL or an intrusion in progress? The questions get answered as quickly as possible by disconnected dashboards and human-error-prone manual processes. Before anyone else is awake to check the work.