Crestvale Newsroom

Databricks puts AI agent tools under strict controls

6 min · 20. Mai 2026
Episode Databricks puts AI agent tools under strict controls Cover

Beschreibung

Databricks is pushing governance down to the tool layer, creating enforceable controls on what AI agents can actually do inside production systems. This shift matters because most real incidents come from over-permissioned tools, not model behavior. The episode explains how this new control plane works and why it changes the risk profile for firms deploying autonomous agents. For professional service leaders, the message is clear. AI is entering governed production use, and the firms that prepare their data, identity, and access layers will move faster with fewer surprises. Those who ignore the tool layer will struggle with preventable incidents. We also cover OneStream's finance-focused agentic layer, identity gaps in machine accounts, and a supply-chain warning from a CISA credential leak. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

Kommentare

0

Sei die erste Person, die kommentiert

Melde dich jetzt an und werde Teil der Crestvale Newsroom-Community!

Loslegen

2 Monate für 1 €

Dann 4,99 € / Monat · Jederzeit kündbar.

  • Podcasts nur bei Podimo
  • 20 Stunden Hörbücher / Monat
  • Alle kostenlosen Podcasts

Alle Folgen

142 Folgen

Episode CISA orders Ivanti Sentry patch by Sunday Cover

CISA orders Ivanti Sentry patch by Sunday

CISA just enforced a seventy two hour patch deadline for actively exploited infrastructure, and that single move signals a broader shift in how fast security teams are expected to operate. This episode breaks down what that means in practice, from Ivanti Sentry exposure to the growing expectation that internet-facing systems must be treated as compromised almost immediately. It also looks at how attackers are accelerating their own timelines, with zero-day exploitation in PeopleSoft leading directly to extortion, and npm-based worms stealing cloud and AI credentials before detection tools can respond. We also cover Google's legal push against AI-driven smishing networks and what it signals about the future of platform-led defense. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

13. Juni 20266 min
Episode ServiceNow bug exposed customer instance data online Cover

ServiceNow bug exposed customer instance data online

A ServiceNow vulnerability exposed how quickly SaaS platforms can become part of your attack surface, while new federal guidance is shrinking vulnerability response windows to just three days. This episode breaks down what the ServiceNow incident means in practice, why CISA's seventy two hour remediation expectation is a major shift, and how AI agents are quietly expanding identity risk inside most organizations. The common thread is speed and visibility. Teams are being forced to make faster decisions with less margin for error, while managing identities and data they often cannot fully see. We also cover Cyera's major funding round and what it signals about data security becoming the control layer for AI, along with key updates from Microsoft, Fortinet, and others. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

11. Juni 20266 min
Episode Anthropic adds mandatory 30-day traffic retention Cover

Anthropic adds mandatory 30-day traffic retention

Frontier AI access is starting to look like a gated system, and the price is visibility. Anthropic's latest model release makes thirty day data retention a requirement, signaling a broader shift in how advanced AI will be governed and consumed. For security and IT leaders, this is not just a policy change. It directly affects how AI can be used in sensitive workflows, what data is exposed to vendors, and how much control teams retain. At the same time, Apple is pushing automated password rotation, and CISA is redefining how vulnerability prioritization should work, both pointing toward more automation and more selective control. We also cover DTEX's push into intent level monitoring, along with key updates from Check Point, Google, Dataminr, Elastic, and JPMorgan. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

10. Juni 20265 min
Episode Check Point VPN flaw bypasses passwords in IKEv1 Cover

Check Point VPN flaw bypasses passwords in IKEv1

Today's episode focuses on two failures that point to the same root issue: identity controls breaking under outdated assumptions. A Check Point VPN flaw shows how legacy configurations like IKEv1 can silently become open doors, while Meta's AI-powered recovery flow demonstrates how automation can bypass core verification entirely. For security and IT leaders, the takeaway is direct. Identity is no longer confined to login systems. Any workflow that can modify access or user attributes is now part of your attack surface. That includes AI agents, support tooling, and recovery processes. At the same time, configuration debt is proving just as dangerous as unpatched software. We also cover new data on AI governance gaps, a major healthcare-related breach, MFA bypass tactics, and a critical Linux privilege escalation flaw. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

9. Juni 20265 min