The War of AIs in Cyberspace: Agentic SIEMs as a New Attack Surface

SOCs are evolving toward agentic architectures where multiple AIs handle triage, investigation, correlation, and response. The decision system itself becomes the target. We argue for capability monotonicity (Lock-Monotone/TGMC) as an architectural invariant that contains a compromised reasoning layer.

June 18, 2026 · 11 min · 2335 words · aleph-beth

How LLMs Work: From the LSTM to the Transformer

Three interactive diagrams to see, step by step, how a sentence flows through a recurrent network (LSTM), a convolutional network (CNN), and finally a Transformer — the architecture every modern LLM is built on. Plus why the mechanics matter for security.

June 12, 2026 · 7 min · 1474 words · aleph-beth