Do you agree that deep cyber experience, practical AI engineering, and an active open community are crucial to staying ahead of modern attackers? This is edition 3 of CAC, our Cyber, AI and Community newsletter. Please send us any feedback, and share this with colleagues if you find it valuable.
A malicious OT actor found without signature matching
On September 16 we announced the results of a joint operational validation with the Technology Advancement Center (TAC), a nonprofit cyber security institute established by the National Security Agency. On TAC's WS3 water-plant range, LogLM identified the source of an attack with no signature, no device rule, and no model fine-tuning written for that endpoint. TAC independently confirmed the endpoint as the rogue HMI behind a simulated flow valve fluctuating against the benign controller.
The analysis ran locally on packet captures, passively, with no learning period on the plant. LogLM read Modbus reads and writes as semantic events and scored sequences against typical behavior and known attack patterns. Findings went to Vigil, where analysts inspected each one next to the underlying flows and register operations. Everything ran on premises.
