Security & Threat Intelligence

The Watch

The Signal

Anthropic sues the Pentagon over its supply-chain risk designation.

Continuity plans are built for outages: bounded wait, status page, SLA credit. A federal control action has none of those properties. Temporary export controls in June already slowed the vendor's revenue, and that was the mild version. If Claude sits in your code review or alert enrichment path, the scenario to plan for is prohibition, not degradation.

In Play

  1. Your Model Vendor's Availability Is a Federal Decision

    Morning Brew reports the Pentagon has designated Anthropic's products a supply-chain risk, and Anthropic is suing to overturn that determination. In June 2026 the administration temporarily export-controlled its most powerful models, alarming customers and slowing revenue growth. If a Claude model sits in your code review, ticket triage, or alert enrichment path, plan for access being prohibited rather than degraded — no SLA credit covers a federal control action.

    Ask Clarity
    Try
  2. Exploit Generation Priced at $3.61

    Per Computerworld, Microsoft's AI security lead says it is "time to scrap outdated best practices" because finding a vulnerability and generating a targeted exploit now costs 21 minutes and $3.61. No methodology, sample set, or working definition of "vulnerability" was published, and the vendor sells the remedy. Discount it tenfold and a three-hour, $36 exploit cycle still invalidates a 30-day patch SLA on anything internet-facing.

    Ask Clarity
    Try
  3. Agent Execution Landed Inside Your Trusted Tiers

    AMD is positioning EPYC server CPUs for agentic workloads — tool calls, code sandboxing, API orchestration — which puts agent execution on general-purpose hosts inside existing trust boundaries, per TLDR Hardware. Google is shipping system-level agentic tools on Pixel 11, below the layer where MDM app controls can see them. Pointer reports Brex now counts coding agents alongside hundreds of engineers in preview-environment capacity planning. The exposed tier is the host and the phone, not the GPU.

    Ask Clarity
    Try
  4. A Surveillance Vendor Published Your Insider-Search Baseline

    Under bipartisan accusations that police illegally misused its license-plate data, Flock Safety cut retention from 30 days to 7 and will auto-lock users showing abnormal search activity, per Morning Brew. That pairing — retention minimization plus anomaly detection aimed at the operator, not the outsider — is a published baseline for insider misuse of legitimate access. Your SIEM, eDiscovery, and customer data platforms allow broad sensitive-record search with no equivalent lockout.

    Ask Clarity
    Try
  5. Memory and HBM Scarcity Becomes a Provenance Problem

    North American data center vacancy is 1%, per Computerworld, which voids the "recover in an alternate facility" line sitting in most ransomware and DR plans. Memory inflation is also pushing endpoint refreshes toward less RAM than a full agent stack needs, and toward refurbished or lease-returned devices whose firmware nobody has attested. TLDR Hardware reports an HBM shortage deep enough that Nvidia is testing Rubin Ultra configurations as low as 192 GB, which drives buyers toward brokers.

    Ask Clarity
    Try

Deep Dives

Your Model Provider's Availability Now Sits With an Agency You Don't Contract With

Three separate levers moved outside your program this cycle: a contested federal designation, a revocable capability-linked approval regime, and the quiet loss of vendor-ownership data.

Prohibition Behaves Nothing Like an Outage

Continuity plans model the vendor outage. The API returns 503, the wait is bounded, service resumes, a credit arrives. A federal control action has none of those properties. There is no remediation timeline, and no status page publishes an ETA. There is no contractual remedy either. June 2026: temporary export controls, per Morning Brew, alarmed customers and measurably slowed revenue growth. The mechanism worked. The administration will use it again. Where a model sits in a production path, meaning code review, ticket triage, alert enrichment, support summarization, a 30-day control action is a Sev-1 with an indefinite RTO, and the incident commander has no vendor to escalate to.

The Same Revocable-Approval Pattern Appeared in Vehicle Safety

NHTSA granted Zoox the first commercial FMVSS exemption governed by "Operational Authorizations", per TLDR Hardware. Those are revocable, capability-linked permissions spanning eight federal safety standards. Fixed compliance is replaced by approval that can be withdrawn whenever capability is called into question. For operators of cyber-physical products, that rewrites incident economics. A security event stops being a fine and becomes an authorization-withdrawal event that halts revenue. The IR plan then needs a regulator-notification track and an authorization-evidence retention path, not only a breach-counsel call tree. Expect this template for AI systems generally.

And the Data Used to Unmask Vendor Owners Is Switched Off

Morning Brew also reports the repeal of the rule requiring US companies to report beneficial ownership. That was the primary source third-party risk teams used to establish who actually controls a vendor entity. Nothing in the control set will alarm. Sanctions screening and foreign-control diligence degrade silently while continuing to emit clean reports, and shell intermediaries reselling into a software supply chain get materially harder to see. Auditors will still test the control as documented.

All three items share one mechanic. The switch that determines whether a dependency keeps working, or whether a diligence control keeps returning true, is now held by someone who will never open a ticket.

TriggerWho holds the switchWhat it breaksCompensating control
Supply-chain designation or export controlFederal agency with no customer relationshipModel access; federal-adjacent contract exposureSecond provider behind an LLM gateway; prohibition tabletop
Revocable operational authorizationSector regulatorContinued operation of cyber-physical productsRegulator-notification track in IR; authorization evidence retained
Beneficial-ownership repealNo one — the source is simply goneSanctions screening; foreign-control diligenceCommercial ownership data; contractual owner attestation; supplier re-screen

The Window Where Vendor Governance Is Weakest

Morning Brew reports a fall 2026 listing targeted at a $2T+ valuation. That is a reported target, roughly double a ~$1T private mark, not an executable market price. Reported alongside it: a $6B acquisition of Decart aimed at cutting training costs and moving toward in-house chip design. In DPA terms, the physical and logical infrastructure processing those prompts is about to change, and subprocessor drift usually arrives without notice. The alternative is no steadier. OpenAI's chief revenue officer is departing under a year in amid pre-IPO churn, so the escalation path used mid-incident is being rebuilt there too. Add the reported 2.5x price gap between Anthropic's Fable and comparable OpenAI models and the engineering response is predictable: personal API keys and direct-to-provider calls that carry no DPA, no retention terms, and no egress logging.

Most continuity plans model vendor outage. None of them model vendor prohibition, and one agency decision is all it takes.

What to do

  1. Run a 'vendor prohibited' tabletop within 30 days covering federal designation or export control of your primary model provider, with a named second provider behind the gateway and a failover validated against your eval suite in under 24 hours.

  2. Amend AI vendor DPAs this quarter to require advance notice of subprocessor and material control-environment changes with a right to suspend processing, and calendar a Q4 terms diff review.

  3. Re-screen your top 50 suppliers against commercial ownership data by quarter end and add contractual ultimate-beneficial-owner attestation at onboarding to replace the repealed federal registry.

Discount the $3.61 Claim, Then Rewrite the Patch SLA Anyway

The figure is unmethodologized vendor marketing, and its conclusion survives a tenfold haircut — which is exactly why it belongs in front of the risk committee labeled as directional.

What the Figure Actually Is

The source is Microsoft's own AI security lead, per Computerworld. That is the party running the largest attack surface in most estates and selling the remedy for it. There is no published methodology and no sample set. No working definition of "vulnerability" either. Statistics in that condition should not reach a board unqualified, because they anchor consolidation and spend decisions that outlive three budget cycles. Cite it as vendor-sourced. It should not appear in a deck as a measured fact.

Then Apply the Haircut and Watch the Conclusion Survive

Cut the claim by an order of magnitude. A three-hour, $36 exploit cycle still destroys a 30-day patch SLA on anything internet-facing or KEV-listed. The number can be marketing and the operating implication can still be correct. The wrong response is a faster patch race against automation, because you cannot win a speed contest against a machine. The right response makes patch speed matter less:

  1. Exposure reduction. Shrink the internet-facing footprint until the fast exploit cycle has fewer targets to aim at. It is the only move that reduces the number of races that have to be run.
  2. Virtual patching. WAF and IPS rules that buy the window change management actually needs, documented as the compensating control for every asset that cannot meet the compressed SLA.
  3. Autonomous containment. EDR auto-isolation and playbook-driven token revocation. Human triage structurally cannot match machine-tempo offense, and this is the one point where the vendor argument is unarguable.

The Same Tempo Problem Is Already Inside the Dev Plane

Pointer supplies the half the vendor framing omits. Agent-driven engineering has pushed deploy loops under five minutes, and coding-agent invocation volume decouples from headcount entirely. The envelope of legitimate activity in the dev plane has widened by an order of magnitude. Any detection baseline that blends human and agent behavior will alert-storm or go quiet. The two accounts converge on one point: human review speed is now the binding constraint on both offense and internal change. They diverge on budget. The vendor claim implies buying machine-speed defense. The engineering evidence says the baselines and gates already owned and staffed get repaired first.

How to Carry It to the Risk Committee

The defensible version puts the revised SLA and the caveat in the same sentence: sub-24-hour targets for KEV-listed and internet-facing assets, driven by a directional vendor claim rather than an independently verified one, with documented compensating controls wherever the window cannot compress. The artifact almost nobody keeps is a written register of every SDLC control weakened in the name of agent throughput, each entry carrying its rationale and its compensating control. Pointer's framing is the right one: the classic gates for change management, review, and testing belong in place as guardrails rather than discarded. The register is what separates a post-mortem from a blame assignment when something lands badly.

The exploit-economics number is unverifiable marketing, and a thirty-day patch SLA on internet-facing assets is indefensible either way.

What to do

  1. Re-underwrite vulnerability-management SLAs this quarter to a sub-24-hour target for KEV-listed and internet-facing assets, with a documented compensating control recorded for every asset whose window cannot compress.

  2. Enable EDR auto-isolation and automated token revocation for a defined severity class within 30 days so containment does not wait on analyst triage.

  3. Split dev-plane detection baselines into separate human and agent profiles this sprint, modeling volume, timing, repository breadth, and egress destinations independently.

Agent Execution Landed on Your Trusted Hosts, Phones, and Dev Clusters

Two silicon roadmaps and one platform case study describe the same migration, and not one of the three frames it as an identity or isolation problem.

The Chain Is Boring, Which Is Why It Will Work

The chain runs from an injected instruction through an over-permissioned tool, a sandbox sharing a kernel with the orchestrator, and egress to an attacker-controlled endpoint. No step requires a model exploit. Every step runs on a conventional server with conventional credentials and conventional network reachability. Most AI threat models written in the last eighteen months point at the model and the GPU. The code that resolves a tool call, executes the sandboxed payload, and issues the outbound request lives one tier down, on the general-purpose fleet. A silicon vendor building a server line around this workload is market confirmation that the pattern is permanent, not a pilot.

Detection consequence

Tool invocations are almost never logged as authentication events, and agent egress routinely bypasses the inspecting proxy. Until both are fixed, a prompt-injection-driven lateral move looks like ordinary application traffic from a trusted host.


The Enrolled Phone Became an Agent Host

Google concedes the Pixel 11's hardware gains are incremental; the differentiation is software, per TLDR Hardware: system-level agentic tools, real-time multimodal processing, and proactive context awareness on the Tensor G6, with the Pro Fold at $1,900. An OS-level process holding screen, notification, and app-state context sits below MDM app controls, DLP, and CASB visibility. The governance question is narrow: may a system agent read work-profile data, and where is that data processed? The Android Enterprise policy answer is cheaper before the refresh wave enrolls than the exception debate afterward, which costs multiples more. The data-protection assessment needs the on-device versus cloud boundary written down either way.


Test Isolation Stopped Being a Network Boundary

Pointer's economics: duplicating 800+ microservices per preview environment ran roughly $2M a year with 30-60 minute deploys; the replacement runs only the services under test against a shared baseline, routing requests to the right version. Those figures are vendor-supplied from a paid placement with no disclosed methodology — treat the numbers as marketing and the architecture as intelligence. Under duplication, isolation was enforceable with network policy. Under request-level routing it becomes an application-layer decision based on propagated request context. Any service that drops that context falls back silently to the shared baseline, and if the context is attacker-settable, isolation is bypassable by header manipulation. The unasked question in the ROI meeting is the data classification of that baseline. Anything production-derived means an undocumented data path across a compliance boundary. The routing mechanism is inferred from the described pattern rather than stated — validate against vendor documentation before escalating.

And the harness is the next marketplace

Anthropic's Claude Code Workflows make agent harnesses dynamically created, shareable, and reusable. That is the GitHub Actions marketplace problem with prompt injection stapled on: a useful executable artifact pulled into thousands of privileged execution contexts, unsigned and with no provenance check in the pipeline. A harness that directs an agent to fetch and act on external content while holding tool-execution privileges converts injection into remote code execution with the CI token.

TierNew exposureTypical detection gap
Host orchestrationTool calls and code sandboxing on trusted general-purpose serversTool invocations not logged as auth events; agent egress skips the proxy
On-device agentsOS-level process with screen and app-state context on BYOD hardwareSits beneath MDM app controls, DLP, and CASB
Preview clustersIsolation enforced by request routing against a shared baselineDesign review skipped; compliance scope never re-diagrammed
Shared harnessesUnsigned executable scaffolding distributed peer-to-peerNo software-composition scanning, provenance, or code review
The agentic attack surface arrived as a product launch and a cost-savings slide. It will reach your incident queue long before it reaches a CVE.

What to do

  1. Publish an on-device AI agent policy for managed and BYOD Android before the Pixel 11 refresh wave enrolls, stating explicitly whether system-level agentic tools may access work-profile data, and enforce it in Android Enterprise.

  2. Require a security design review of any request-isolated preview-environment project before rollout, answering baseline data classification, whether routing context is attacker-settable, what cluster privileges the vendor control plane needs, and whether SOC 2 or PCI scope changes.

  3. Instrument every agent tool invocation as a privileged authentication event this sprint, with credentials scoped per tool rather than per agent, per-agent egress allowlists, and sandboxes on a separate trust boundary from the orchestration host.

The bottom line

Nothing that moved your exposure arrived through a security review. It was decided in a courtroom, a procurement queue, a platform-engineering sprint, and a vendor's crisis meeting — none of which files tickets with you. These controls did not fail because your team missed something; they failed because someone outside your reporting line pulled a lever you never saw. Claim intake rights this week over the three functions that quietly rewrite your attack surface — procurement, platform engineering, and vendor management — with a written design-review trigger the moment one of their decisions crosses a trust boundary.