Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Ep. 83 - Anthropic's CISO Guide to Agentic AI: Your Next Insider Threat Is an AI Agent

An AI agent that drifts from your intent looks exactly like an insider attack: legitimate credentials, sanctioned tools, plausible actions, at machine speed. In this episode, we break down Anthropic's "Zero Risk Isn't the Job" CISO guide: a four-question review framework, seven vendor-neutral controls, and why egress allowlisting is the strongest defense against prompt injection. Plus: the Claude Opus 4.5 upgrade that had an incident-response agent recruit another agent, and why agentic AI needs continuous adversarial exposure validation.

Claude Cowork Activity Isn't Captured in Compliance Logs

Is your AI compliance up to par? Anthropic's deputy CISO reveals that Claude Cowork activity isn't captured in compliance logs. If you're in a regulated EMEA sector, DORA's ICT logging and the EU AI Act's obligations are here. Relying on a self-configured OTel stream isn't enough for formal audits. Stay informed about data boundaries and privacy reviews before enabling streams.

Research - From Square Root to /root: Escalating Privileges in Azure Containers with Python in Excel

Isolation is not the same thing as security. Ron Ben Yizhak from SafeBreach Labs presented this research at Black Hat USA and DEF CON: when Microsoft shipped Python in Excel, the code didn't run on a machine. It ran in an isolated container in Azure. So he asked the obvious question. How isolated is it, really? An isolated environment still has an attack surface. It just moves. See how Ron: If your teams are evaluating cloud-executed code features, this one is worth the full read—the methodology matters as much as the findings.

Escalated Privileges in Azure Containers with Python in Excel

A math function in Excel became a path to root in Microsoft's cloud. SafeBreach Labs researcher Ron Ben Yizhak reverse-engineered the isolated Azure containers behind Microsoft's Python in Excel feature—and found the "isolated" part didn't fully hold. Cloud isolation claims are a trust boundary. Trust boundaries get tested. What he found: Both issues were responsibly disclosed to Microsoft and patched between March and June 2026, and the research debuted at DEF CON 34.

Your CFO Just Left You a Voice Note. It Wasn't Her.

A voice note from your CFO on WhatsApp. Her cadence, her urgency—and a reference to a confidential acquisition discussed in a real meeting last Tuesday. North Korea's Blue Noroff builds these backwards: compromise a junior employee's calendar or inbox first, then train a voice model on the stolen context. By the time anyone thinks to verify, the emergency transfer is already sitting in an offshore account.

Ep. 79 - BeaverTail and InvisibleFerret: The Malware That Rewrites Itself for Every Target

North Korea has stopped writing bad phishing emails. In Part 2 of our DPRK deep dive, Tova Dvorin and Adrian Culley break down how the Reconnaissance General Bureau and Bureau 121 weaponized AI in 2026: Blue Noroff cloning a CFO's voice to authorize emergency liquidity transfers, real-time face swaps passing DevOps job interviews, and Lazarus using LLMs to polymorph BeaverTail and InvisibleFerret for every single target.