Databricks - Experts & Thought Leaders

Latest Databricks news & announcements

Databricks Acquires Panther: AI SOC Revolution

Databricks, the Data and AI company, today announces intent to acquire Panther, a pioneer AI SOC platform. The acquisition will advance the company’s vision for the security lakehouse, a new category of security software that is disrupting legacy SIEM with an agentic approach. Together, Databricks and Panther will help organizations detect more threats, investigate every alert, and fight AI-driven attacks with AI. Trusted by leading security teams — including Anthropic — Panther has proven it can defend the most demanding, AI-native environments. Panther is the third security acquisition announced by Databricks, strengthening its AI security product team and deepening its investment in security. AI-native environments AI-driven attacks are evolving faster than human-led defences can keep up. Attackers now use AI agents to find new vulnerabilities and attack paths across cloud, SaaS, and AI systems. Meanwhile, SIEMs are held back by high costs, limited data, and manual, labor-intensive workflows. As a result, most organizations analyze only a fraction of their security data—leaving them blind to many of the new agent-driven attacks in their environments. Today's SOC workflows make this worse, because they're still largely manual: teams hand-manage data ingestion, hand-write detection rules, and investigate every alert by hand. With legacy tools, SOC teams simply can't keep pace with new threats. Panther closes the gap by replacing costly, closed SIEM stacks with agentic SOC workflows—so defenders can investigate every alert and disrupt attacks at the speed and scale of AI. Security lakehouse vision “Legacy SIEM was never designed for AI,” said Ali Ghodsi, Co founder and CEO of Databricks. “Databricks, which has the trust of 70% of the Fortune 500 in data and AI, is doubling down on Lakewatch and our security lakehouse vision. With Panther, we enhance and expand our ability to analyze all data and automate SOC workflows. Together, we can offer the best platform to help defend the world against agentic attacks.” “We are thrilled to join Databricks and help accelerate the security lakehouse vision,” said Jack Naglieri, Founder and CEO of Panther. “The SOC is at an inflection point: AI is changing how attacks are launched and defenders can now finally keep pace with them. Together with Databricks, we can arm defenders with sophisticated agents that scale detection, investigation, and response.” AI-driven attackers "Building frontier AI requires security operations that are programmable and deeply integrated with the way modern engineering teams work,” said Tim Nguyen, Head of Defense at Anthropic. “Panther has helped us bring a software engineering approach to detection and response, giving our team the flexibility to adapt quickly as our environment evolves." Earlier this year, Databricks introduced Lakewatch, its security lakehouse designed to help organizations defend against increasingly sophisticated AI-driven attackers. Lakewatch unifies security, IT, and business data into a single, governed lakehouse for agentic detection and response, enabling customers to ingest, retain, and analyze unprecedented volumes of unstructured data while reducing total cost of ownership. Cloud native security operations Adding Panther accelerates Databricks’ security lakehouse vision in several key ways: Agentic workflows designed for SOC: Lakewatch and Panther embed AI agents directly into core SOC workflows so they can automatically triage alerts, gather context, and propose next steps. Broad, high-fidelity data coverage: 100+ pre-built, deeply parsed integrations across critical cloud infrastructure, identity providers, endpoints, networks, and SaaS applications, delivering immediate, out-of-the-box ingestion without the complex mapping required by legacy SIEMs. Top security team: The Panther team of engineers and former SOC analysts brings deep experience in open source and cloud native security operations. Founded by the leader of the open source StreamAlert project originally created at Airbnb, Panther has grown into a cloud native SIEM and AI SOC platform built on detection as code and security data lakes. The acquisition of Panther builds on Databricks’ recent security investments, including its acquisitions of Antimatter and SiftD.ai. Hear more this week at Data + AI Summit in San Francisco. The proposed acquisition is subject to customary closing conditions, including any required regulatory clearances.

Databricks Launches Lakewatch SIEM For AI Security

Databricks, the Data and AI company, announced Lakewatch, a new open, agentic SIEM (Security Information and Event Management) designed to help organizations defend against increasingly sophisticated agent attackers.  Lakewatch unifies security, IT, and business data into a single, governed environment for AI detection and response. With open formats and an open ecosystem, Lakewatch enables customers to ingest, retain and analyze unprecedented volumes of multi-modal data, while slashing costs and eliminating vendor lock-in. Security teams gain complete visibility across the enterprise and can deploy defensive security agents to automate threat detection and response at massive scale. Lakewatch is now available in Private Preview. Defending at machine speed AI threats are evolving at a speed and complexity that goes beyond human-led defenses. Attackers can now deploy agents to continuously scan systems, discover vulnerabilities, and execute coordinated attacks at machine speed. Defenders remain constrained by incomplete data, manual workflows, and siloed architectures. High ingestion costs force them to discard up to 75% of their data. This creates a dangerous asymmetry: attackers use AI agents to attack anywhere, while defenders see only a fraction of their own data and are limited by how fast their teams can react. Lakewatch closes this gap by enabling organizations to unify all their data in open formats so they can analyze years of data cost-effectively without moving or duplicating it. This includes multi-modal data like video and audio to identify social engineering, insider threats, and anomaly detection. With Lakewatch, swarms of AI agents automate detection, triage, and threat hunting to meet machine-speed attackers with machine-speed defense. “Security teams can no longer rely on manual workflows to outpace AI-driven attacks,” said Ali Ghodsi, Co-Founder and CEO of Databricks. “With Lakewatch, we are giving enterprises a new open data architecture and agentic capabilities to replace stagnating SIEM tools. Defenders must have even better visibility and speed than today’s agent attackers.” Open, Agentic SIEM for enterprise speed and scale Lakewatch is designed to deliver agentic security atop the scale of an open security lakehouse. Key features include: Agentic Triage and Investigation: Build, optimize, and deploy custom security agents with Agent Bricks to handle complex workflows end-to-end. Agents parse and enrich telemetry across hundreds of formats to reduce Mean Time to Detect & Respond (MTTD/R), while remaining inside the secure, governed environment where data already lives. Automated Security Intelligence: Integrated with Genie, Lakewatch automates triage, plans multi-step approaches, and helps enterprises reduce alert fatigue, leaving more time for analysts to focus on high-impact threats. Open Ecosystem: Unify all structured and unstructured security data on one open, cloud-agnostic platform that integrates with any tool to identify social engineering, insider threats, and anomaly detection. Databricks’ new Open Security Lakehouse Ecosystem is a fast-growing group of leading security vendors and delivery partners, including Anvilogic, Arctic Wolf, Cribl, Obsidian, Okta, Palo Alto Networks, 1Password, Panther, Proofpoint, Rearc, Slack, TrendAI, Wiz (now part of Google Cloud), and Zscaler. Detection-as-Code: Manage detections as code with automated testing and deployment to ensure defense is always version-controlled and verified. Governance and Compliance at Scale: Enable compliance and consistent policy enforcement with Unity Catalog. Access cost-effective, long-term retention out of the box, helping global enterprises meet rigorous new mandates such as NIS2 and DORA. Enterprise organizations use Lakewatch to unify their data and detect threats faster with AI. Lakewatch customers include industry leaders like Adobe and Dropbox. “As the volume of security data grows, organizations need new ways to analyze and act on that information quickly and at scale,” said Karthik Venkatesan, Security Engineering Lead at Adobe. “Databricks provides the foundation needed to move from data-driven to AI-driven approaches for security operations, and Lakewatch is an important step toward bringing security intelligence closer to where data already lives.” Deepening partnership with Anthropic Building on the success of the two companies’ existing strategic partnership, Databricks and Anthropic are deepening their collaboration to deliver agentic security operations. Anthropic Claude models help power Lakewatch, using Claude's advanced reasoning capabilities to correlate signals across security, IT, and business data to surface threats faster. Anthropic also uses Databricks for its own security lakehouse to gain complete visibility across its security and business data and detect threats earlier. Expanding security leadership with Antimatter and SiftD.ai acquisitions To advance its open, agentic SIEM approach, Databricks is announcing the acquisitions of both Antimatter and SiftD.ai. Antimatter was founded by UC Berkeley security researchers who laid the foundation for provably secure authentication and authorization for AI agents. SiftD.ai, founded by the creator of Splunk’s Search Processing Language (SPL) and lead architects of Splunk's search stack, will bring deep expertise in large-scale detection engineering and modern threat analytics. Availability Lakewatch is now available in Private Preview. 

HiddenLayer Announces The Public Launch Of Their MLSec Platform And Its Design Partner Program

HiddenLayer, a pioneer in cybersecurity products dedicated to protecting artificial intelligence and machine learning technologies, announces the public launch of the HiddenLayer MLSec Platform and its design partner program. The first-of-its-kind AI cybersecurity platform empowers security operations and data science teams to protect their AI investments against adversarial machine learning attacks. The platform is comprised of the company’s flagship product HiddenLayer MLDR, Model Scanner, and Security Audit Reporting. Most destructive development HiddenLayer is seeking early design partners looking to fulfill their cybersecurity needs as they increase their investments in AI while helping shape the future of a safer AI world. Price Waterhouse Cooper predicts that AI could contribute up to $15.7 trillion to the global economy by 2030 with 85% of business leaders thinking AI will significantly change the way they do business in the next five years. HiddenLayer is seeking early design partners looking to fulfill their cybersecurity needs Adversarial Machine Learning attacks are the newest and most destructive development of the threat landscape, targeting their most advanced and important technology. An evolution of traditional cybersecurity threats like malware, ransomware, phishing, spam, and data breaches that modern environments are not prepared to defend against. Tom Bonner, HiddenLayer’s Senior Director of Adversarial ML Research, explains how companies can safeguard AI with HiddenLayer MLDR in the SAI team’s recent blog. Machine learning models “Organizations of every industry are investing heavily into AI to take advantage of its many benefits,” said Howard Levenson, AI/ML Industry Advisor. “The HiddenLayer MLSec Platform bridges the knowledge gap between security and data science teams and provides easy-to-use products that defend against adversarial abuse.” “The rapid adoption of AI/ML introduces a new attack surface for threat actors to exploit, so we need the tools and knowledge to be able to shed light into the areas our machine learning models are most vulnerable to attack,” said Malcolm Harkins, Chief Security & Trust Officer at Epiphany Systems. Sensitive training data The HiddenLayer team consists of subject matter experts in the domain of artificial intelligence" “The HiddenLayer team consists of subject matter experts in the domain of artificial intelligence and cybersecurity. They have developed products that allow our Security Operations teams to stay ahead of the new threats in AI.” The answer to this strong demand for AI/ML cybersecurity, HiddenLayer MLDR uses a patent-pending ML-based approach to analyze Machine Learning Model events in real-time to identify malicious activity without requiring any access to the organization’s ML models or sensitive training data. HiddenLayer has partnered with organizations in the AI/ML space including Databricks, NVIDIA, and MITRE to accelerate the adoption of ML Security across multiple industries.