The War of AIs in Cyberspace: Agentic SIEMs as a New Attack Surface

SOCs are evolving toward agentic architectures where multiple AIs handle triage, investigation, correlation, and response. The decision system itself becomes the target. We argue for capability monotonicity (Lock-Monotone/TGMC) as an architectural invariant that contains a compromised reasoning layer.

June 18, 2026 · 11 min · 2335 words · aleph-beth

The Agentic SOC — and the Attacks Against Defensive AI Agents

Two linked shifts: the SOC moves from a human craft model to an automated agentic one — and those same defensive agents become a new attack surface. The defense you deploy is also the breach you open.

June 10, 2026 · 14 min · 2953 words · aleph-beth