Cyber + AI + Community

Cyber + AI + Community, Issue 3

October 6, 2026

Do you agree that deep cyber experience, practical AI engineering, and an active open community are crucial to staying ahead of modern attackers? This is edition 3 of CAC, our Cyber, AI and Community newsletter. Please send us any feedback, and share this with colleagues if you find it valuable.

A malicious OT actor found without signature matching

On September 16 we announced the results of a joint operational validation with the Technology Advancement Center (TAC), a nonprofit cyber security institute established by the National Security Agency. On TAC's WS3 water-plant range, LogLM identified the source of an attack with no signature, no device rule, and no model fine-tuning written for that endpoint. TAC independently confirmed the endpoint as the rogue HMI behind a simulated flow valve fluctuating against the benign controller.

The analysis ran locally on packet captures, passively, with no learning period on the plant. LogLM read Modbus reads and writes as semantic events and scored sequences against typical behavior and known attack patterns. Findings went to Vigil, where analysts inspected each one next to the underlying flows and register operations. Everything ran on premises.

Read here

Cyber research: Branch61G

AI research

One post this issue, on where a new class of model fits in detection.

Jev might help your detection engineering. It won't do your detecting.

Evan Powell · September 26

TypeSafe AI's Jev is a System One model: state in, typed and calibrated decisions out in 70 to 500 milliseconds. Evan agrees with the taxonomy and argues about where it belongs. Waymo and Stripe both run the same pattern in production: an encoder pretrained on native signal, small classifiers on its embeddings, and reasoning models held back for the slow, rare cases. Stripe's card-testing detection went from 59% to 97% that way. LogLM applies the pattern to security telemetry, inside your environment, and detects at 99% zero-shot with 1% or fewer false positives and no baselining period.

The cost math matters too. The open source jev-ids project packs about 1,800 tokens into each flow request, roughly $74 per million verdicts. At a billion flow records a day that is about $74,000 a day, around $27 million a year, before identity and endpoint data. Jev fits downstream of detection (triage, ATT&CK tagging, routing, guardrails) and still needs a harness with humans in and on the loop. That is Vigil.

Read here

Open source: Vigil

Vigil is the leading open source AI SOC, Apache 2.0, built in the open by the community.

VigilSOC 0.6.0 Is Live: Contract Stability, Fixed Helm Deployments, and the Path to 1.0

John Van Lowe · September 24

0.6.0 freezes the /api/v1 contract and 17 core MCP tools, both enforced by CI drift tests, so downstream consumers and third-party harnesses can depend on them. It adds closed-loop threat hunting started from the console with full hunt replay, shadow adjudication that scores agent judgment against real findings without operational risk, daily known-answer probes, and episodic memory keyed by MITRE ATT&CK technique. Atomic Red Team tests are now first class, agent skills ship as standard SKILL.md directories, and every agent action is hash-chained into a tamper-evident ledger. Fresh container images also fix the 0.5.0 Helm permission problems.

Read here

Yet Another Software Factory (and Why We Built Ours the Way We Did)

Sam Armstrong · September 14

Everyone is building a software factory. This is the one used to develop Vigil, the opinions baked into it, and what has surprised the team so far.

Read here

Upcoming events

Vigil 1.0 sneak peek, Thursday October 8, 2 to 3 PM CDT, online. A preview of Vigil 1.0.0, recently added features, and a few use case demos. Register

Agents Hunting Agents: Open Source + AI approaches, Monday October 19, 10:30 AM to 3:30 PM PDT, Silicon Valley AI Hub, Menlo Park. An agent swarm is making moves. Is it an attack, or just doing its job? Work in teams with mentoring from AI and cyber leaders on telling malicious agent behavior from legitimate activity, using Vigil. Register

AI Cyber Alliance meetups. Austin: October 13, November 10, December 8. Bay Area: November 19 and December 15 at Snowflake's Silicon Valley AI Hub. Boston, DC, and Seattle dates to be announced. Calendar . Want to host or speak? Start at ai-cyber-alliance.org .

GitHub: github.com/Vigil-SOC/vigil. Project: vigilsoc.org . Benchmarks: SOCBench .

Next issue

In the next issue, look for Vigil 1.0 and what it means for teams running agents in production, how the Intelligent Defense Platform tells agentic activity from attackers, and recaps from Agents Hunting Agents. Tell us what you would like to see covered, and subscribe if you would like to receive updates as we publish additional CAC releases.

See the threats your tools can't.

LogLM works with your existing stack to uncover the evolving threats traditional systems overlook. Vigil, the open source AI SOC, turns those findings into action. No added complexity, nothing replaced.