AI security is the same security, just faster - going Claude crazy without going off the rails @VMwareTanzu
AI security is the same security, just faster - going Claude crazy without going off the rails  @VMwareTanzu
Uploaded March 2026 | Updated September 2026, 1 day ago
What happens when a security practitioner goes all-in on Claude Code? David Zendzian gave Claude root access to his broken vSphere cluster, went out on his boat, and came back to a fixed environment. The AI found an expired beta WCP key buried in an internal LDAP repository that was invisible from outside the system - something that would have taken a human days of log-diving to find.

This is part two of an ongoing conversation about AI and security. David built a local home lab with an Nvidia Blackwell GPU for private models, then discovered what Claude’s Opus model could do with real infrastructure operations - not just coding, but diagnosing, remediating, and automating platform work.

The conversation covers the practical security questions that come up when AI agents have real access to real systems: How do you establish a baseline for AI reliability when humans already cause outages? What does containment actually buy you when sandboxes still leak DNS? Why are MCP servers a useful trust boundary - and why trusted registries for MCP servers and skills are inevitable? How do you teach hundreds of NIST controls to an agent that will actually follow them consistently?

Interested in a platform that can help you with enterprise-y excellent? Just TryTanzu.ai

Tanzu Catsup is a weekly conversation about platform engineering, cloud-native operations, and building software in large organizations. We follow the work wherever it actually leads.

Check us out Fridays at 10am US Eastern/4pm Amsterdam time!

Index:

00:00 Back for Part Two
00:42 Going Claude Crazy
01:39 Home Lab Local Models
03:02 Claude Fixes the Cluster
04:42 Ops and Platform Use Cases
06:07 Remote Control and Sessions
08:22 Security Baselines and Risk
13:18 Enterprise Scale Failure Modes
15:34 Guardrails and Governance
21:26 Containment and Sandboxes
27:23 Security Optimism and Guardrails
31:19 Efficiency and Disaster Readiness
32:41 AI Security Basics Repeat
34:06 Teaching Rules to Agents
35:32 Red vs Blue AI Arms
38:31 Deterministic Guardrails MCP
43:04 Inbox Automation Limits
45:44 Trusted MCP Registries
48:01 DIY Apps Need Testing
51:49 Consistency DRY Control Points
57:29 Velocity and Wrap Up

#AISecurity #ClaudeCode #PlatformEngineering #MCPServers #EnterpriseAI #Guardrails #Sandboxing #DevSecOps #AgenticAI #SecurityOperations #vSphere #NISTCompliance #TrustedRegistries #AIOps
AI security is the same security, just faster - going Claude crazy without going off the railsWhen no one uses your platformAI Turns 100,000 Employees Into 400,000 - And Things Will BreakSecurity auditing with AITales from Production - Debugging LLMs and GenAI Apps on VMware Tanzu PlatformLocking down platforms for AI - what default secure takes away on purposeAI Agents with Tanzu Platform: A Path to ProductionWhy not both - build vs buy when AI is the one spending the tokensRun private cloud GenAI with the Tanzu GenAI TileGive the AI boundaries or it buries youData Lakehouse –  VMware Tanzu FundamentalsHow to use AI for more than just programming
VMware Tanzu |

AI security is the same security, just faster - going Claude crazy without going off the rails

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER