
TL;DR
🚀 AI Threat Hunt Agent: Autonomous hunting across years of data finally answers what did we miss.
🤖 Rogue Agent On Demand: Watch the first end-to-end autonomous AI breach, step by step.
🔬 Cyber Defense Benchmark: A local LLM ties Luna at 52, then finds 10.6% of an attack.
📘 Phishing Ebook: Follow one phishing alert from raw evidence to closed incident.
🎉 Anthony Dumont: Meet our new SVP of Sales for the Americas and EMEA.
📰 Industry Buzz: Five August stories — an RMM supply-chain hit, Cl0p, and two perfect 10s.

Simbian Launches the AI Threat Hunt Agent, Completing the SecOps Loop
Every security leader lives with the same question after an incident closes: what did we miss? The AI Threat Hunt Agent answers it, writing its own hypotheses, testing them, and digging out threats already sitting in your environment across SIEM, EDR, cloud and data lakes, over years of data no analyst could read. It closes the loop: SOC covers the present, Pentest the future, Threat Hunt the past.

Rogue Agent: GPT Hacked Hugging Face by Itself — Now On Demand
Thousands of autonomous actions. Zero humans. One weekend to full lateral movement. Sumedh Barde and Alankrit Chona walk the whole chain, from poisoned dataset to self-migrating C2 swarm. Then the twist: Hugging Face’s own frontier model refused to read real attack payloads. Your guardrails can bench your best analyst.
Watch the session on demand here.

Qwen 3.8 27B: The Local LLM That Costs More and Finds Less
Alibaba’s Qwen 3.8 27B is a real milestone: Apache 2.0, 17 GB at four bits, running on a card you can buy. It scores 52 on the Artificial Analysis Intelligence Index, matching hosted GPT-5.6 Luna. We scored it on defense instead. On Simbian’s Cyber Defense Benchmark it reconstructs 10.6% of the attack chain to Luna’s 15.7%, at $0.24 a hunt against $0.08. Bought to cut the inference bill, it triples it.

New Ebook: Inside a Phishing Investigation
AI-assisted phishing now clicks at 54%, and your analysts still burn 27.5 minutes hand-working a single alert. The ebook follows one alert from raw evidence to closed incident: every observable pulled, enriched through Context Lake™ with your SOPs and asset criticality, then investigated recursively instead of parked. It scores its own verdict too, tied to the MITRE ATT&CK technique it answers.

Welcome Anthony Dumont, SVP of Sales for the Americas and EMEA
Anthony brings more than a decade in cybersecurity. Most recently he led Sales for the Americas at CloudBees, where the team grew top-line revenue more than 50% while reaching profitability, a pairing anyone who has carried a number knows is rare. Before that, 12 years at PTC. He owns sales strategy and field execution across both regions, and we’re hiring.

1. One RMM Flaw, Ransomware Across Every Downstream Client: Microsoft says China-linked Storm-1175 is deploying StormEncryptor ransomware through CVE-2026-18577 in N-able’s N-central, the console thousands of MSPs use to manage client endpoints. Huntress found more than half of reachable cloud servers still unpatched. One provider breached cascades into dozens. Source
2. Cl0p Claims Mass Data Theft From Nearly 50 Companies: Cl0p posted claims against Philips, Shell, Fiserv, GE and dozens more, reportedly through flaws in PTC Windchill and FlexPLM. Philips contained an attempted compromise; the others are investigating. The group doesn’t pick companies. It picks a zero-day. Source
3. Metabase Zero-Day (CVSS 10.0) Hands Over Admin With No Login: Attackers exploited an unauthenticated SQL injection in Metabase as a zero-day, taking full admin access — enough to steal credentials for every connected database. Framework told customers their names, addresses, phone numbers and login IPs were accessed. Source
4. A CVSS 10.0 Entra ID Flaw Was Exploited in the Wild: Microsoft disclosed CVE-2026-69836, a deserialization bug allowing unauthenticated remote code execution in Entra ID. It says the fix is fully deployed and needs nothing from you. A perfect-10 RCE in the identity layer still belongs in your risk register. Source
5. CISA Gives Federal Agencies Three Days on a Windows IKE RCE: CVE-2026-33824 lets an unauthenticated attacker run code by sending crafted packets to UDP 500 or 4500 on any supported Windows release. Microsoft patched it in April. CISA added it to KEV in August and gave agencies three days. Source
