Cyber + AI + Community

Cyber + AI + Community, Issue 1

August 10, 2026

Do you agree that AI, cyber experience, and community are crucial components of the ongoing reinvention of cyber security? If so, stick around. Let us know what you would like to learn about.

We launched CAC, the Cyber + AI + Community newsletter, to share the research we are doing at DeepTempo into attacks and attackers, and into the technologies that, used wisely, are starting to make it ever harder to be an attacker. We also update everyone on progress with Vigil and the community more broadly. What is this MCP 2.0 thing everyone is talking about, and more.

This is our first newsletter and your feedback is crucial for refining it. Thank you for reading and sharing.

Cyber research: Branch61G

Branch61G is our weekly read on what actually hit, written from the grass rather than the broadcast booth.

Teachings from the thickets

Josiah Lashley · August 11

Four separate incidents in seven days, and the same shape underneath all of them. SonicWall's SMA1000 gateway moved from zero day to ransomware KEV, with Volexity tracing the earliest compromise to weeks before public disclosure. Progress Kemp LoadMaster landed in KEV after mass probing, CVSS 9.6, with telemetry counting 792 exploitation attempts from 65 IPs across 18 countries. Head Mare turned unpatched TrueConf servers into trojanized update points, so anyone who joined a meeting pulled a poisoned installer. And an unauthenticated Metabase SQLi, CVSS 10.0, was used to steal customer data from live instances.

Josiah's through-line is worth really thinking about: the enterprise edge is where trust is thickest and visibility is thinnest. A VPN appliance is supposed to terminate sessions. A load balancer is supposed to farm traffic. When the box doing the attacker's work is the box everything trusts, what happens?

Read here

The B61G series runs weekly. Earlier bangers: Week 2 and Week 1.

AI research

Three posts from our team on the most crucial part of building a detection model: the data.

Training a Model on Data Your Adversary Refuses to Give You

Mayank Kumar · August 6

Building the LogLM model was challenging; feeding it and evolving with better data over time may be even more challenging. Mayank draws on the data engine playbook from autonomous driving, Tesla's shadow-mode fleet and Waymo's closed-loop simulator, and walks through the five-stage flywheel behind LogLM: discover, process, simulate, evaluate, feed back.

The place the analogy breaks is perhaps the most interesting part. Tesla's data source is cooperative. Drivers want to drive well, so every mile generates an honest signal. Our subject actively works to not generate data, blends into benign traffic on purpose, and changes behavior the moment it is detected. Autonomous driving mines edge cases from a willing world. We manufacture ours from an unwilling one.

Read here

Failures or Failsafe? A Perspective from the Arena of AI Detection Evals

Jack Murphy · August 10

What happens when a strong model posts a terrible score?

On a customer eval spanning more than 150 malware variants, LogLM appeared to miss most of the malicious traffic. The handful it did catch showed a strange signature: single packets registering zero bytes. That thread unravelled the whole result. Packet header data had never made it into the logs, and roughly 62 percent of the malicious labels turned out to be wrong.

The same pattern emerged on public data. LogLM's embeddings surfaced simultaneous benign and malicious labels on the same attacker IP in NF-ToN-IoT, and an entire SlowLoris DDoS labeled benign in SIMARGL2021. Jack demonstrates that a model able to separate behaviors can double as a detector of bad data, and that detection failures can become useful signals.

Read here

Building the Evaluation Factory Behind LogLM: TempoRange

Christian Moran · August 6

TempoRange is a segmented enterprise (corporate AD, OT/ICS, IoT, management networks) running a continuous benign baseline alongside three attack engines: scripted kill chains across MITRE ATT&CK with exact labels, a detonation range running live malware under layered egress containment, and an ARTEMIS range built on Stanford's autonomous red team agent, dropped in with no script and left to improvise at machine speed.

The payoff Christian points at: when a new technique is published, it can be reproduced in the range and run against the model inside the same news cycle. This enables us to confirm to our clients whether their LogLM is indeed seeing the attack everyone is talking about. A useful read for anyone thinking through AI based ranges and data quality.

Read here

Open source: Vigil

Vigil is the leading open source AI SOC, Apache 2.0, built in the open by the community. If you have read or scanned this far, take a second and check out the site or the repository. Your feedback and support is crucial for Vigil to achieve the critical mass it needs.

Shipping Fast, Breaking Less: A Vigil SOC Summer Update

John Van Lowe · August 5

The repo is moving at its highest pace ever, the core is refactored and spec-aligned, and MCP's 2026-07-28 release addressed what was our biggest pre-1.0 risk.

Read here

What Does an Optimized Agent Harness Look Like in Security?

Sam Armstrong, CISSP · July 28

A task-shaped patching harness plus a single validation-feedback round improved a local PatchEval result by roughly 25 percentage points, with model costs held low. Especially worth reading if you are trying to work out how much of agent performance is the model and how much is the scaffolding around it, which is crucial to understand in cyber ops with agentic AI and in other use cases as well.

Read here

These projects are open to contributions, including bugs, issues, and other feedback, via GitHub or the Vigil Discord: github.com/Vigil-SOC/vigil and socbench.org.

Next issue

We started CAC because we do not see newsletters today that bridge deep AI and deep cyber, with a focus on crucial technologies and techniques. Cyber must move faster and with more intelligence than attackers, who have transformed themselves with AI.

In the next issue we plan on notes from AI in Cyber Alliance meet-ups, more from Branch61G, more deep AI, and whatever else you tell us you want covered. Tell us what you would like to see, and subscribe if you would like these every other week.

See the threats your tools can’t.

DeepTempo’s LogLM works with your existing stack to uncover evolving threats that traditional systems overlook — without adding complexity or replacing what already works.