The images in this article were generated with artificial intelligence. How we publish
Anthropic is testing the arrival of Claude Cowork a mobile, an interesting extension of its agentic desktop-oriented mode that allows you to run and monitor long tasks of the assistant directly from the phone. If you don't know Cowork, it works as a layer that brings continuous running capabilities - previously seen in Claude Code for developers - to the work of documentation, file handling and day-to-day reporting; you can see the filtered catches in X and Claude's general description on Anthropic's website in https: / / www.anthropic.com / claude.
The images provided suggest that the mobile experience will act above all as a remote control for the tasks that run on your computer: start, direct and review progress from your phone, while heavy work continues to run on the PC and continues in the background even if you close the application. This retains the Cowork architecture, in which the agent access the files you decide to share and operates locally on the host team.

In practical terms, this approach can be very useful: long-term tasks, analysis of directories to clean space, compilations that take hours or generation of automated documents and spreadsheets are cases in which telecontrol from mobile facilitates supervision without having to be left next to the computer. In similar tests, users have detected that Cowork explored local partitions and found files that consumed much of the storage, helping solve compilation failures and space bottle necks.
However, moving control to a mobile device changes the risk profile. Running an agent with access to local files and persistence in the background increases the attack surface from endpoint: a committed mobile could send control commands; a vulnerability in the app or in the communication layer could allow unauthorized orders; and the fact that the work continues after closing the app raises questions about credentials, persistent tokens and traceability. In addition, local execution reduces certain cloud risks but makes the job the critical point to protect.

To mitigate these risks I recommend concrete measures: limit Cowork's access to only necessary folders and avoid sharing full units; run Cowork on isolated environments (virtual machines or containers) when handling sensitive data; apply access controls and strong authentication for mobile connection (MFA, session limits and tokens); monitor telemetry and outgoing traffic with EDR / IDS and record the actions of the audit agent. Security operations should add Cowork to the list of managed assets and create specific rules in ICES / EDR to detect atypical behaviors.
For safety equipment and product managers it is key to require safety guarantees by design: encrypted and authenticated channels, signature of binaries, least privileged granules policies, attestation mechanisms that link the mobile session to host equipment and unchanging activity records. It is also recommended that integration be subject to break and attack simulation to validate that controls detect and block abuse - a good practical starting point is in the technical whitepaper of Picus on attack simulation Here. which helps to check detection rules in ICES and EDR.
In short, the arrival of Cowork on the mobile promises to improve productivity by allowing long tasks to be controlled from anywhere, but it carries new risks that should be managed before it is adopted on a scale. The practical recommendation is to pilot the function in controlled environments, update security policies and endpoint, and demand that suppliers clear about permits, persistence of credentials and audit before they deploy it in production.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...