AI MUG May 2026 Recap: Agentic SOC Ops, ICLR Insights, and Production Edge Deployments
It was a busy first Wednesday with numerous community events taking place at the same time but we still had a great turnout for our May 2026 AI MUG meetup! We had several speakers and covered autonomous cyber defense, deployments on edge with CloudFlare, and some of the latest theoretical breakthroughs in recursive self-improvement fresh out of Rio.
For those who missed it, or for attendees looking to revisit the resources shared, here is a complete breakdown of the presentations and links from our latest gathering.
π‘οΈ Agentic SOC Operations for Blue and Red Teamsβ
Presented by John Van Loweβ
Security Operations are undergoing a massive paradigm shift. As John summarized perfectly: "Red and blue teams are becoming agents." The traditional work that used to require a human sitting at a keyboardβrecon, exploit, triage, and responseβis now shifting directly to Python and Markdown playbooks. The next decade of cyber security is an automated battle of agent versus agent.
John mapped out the core operational lifecycle into a 6-step capability axis and detailed six groundbreaking open-source tools actively defining this new frontier:
[01 RECON] ββ> [02 EXPLOIT] ββ> [03 TRIAGE] ββ> [04 INVESTIGATE] ββ> [05 RESPOND] ββ> [06 REPORT]
ββββββ RED TEAM AGENTS ββββββ βββββββββββββββββββββββ BLUE TEAM AGENTS βββββββββββββββββββββββ
π΅ The Blue Team Agents: Speed & Guardrailsβ
On the defensive side, the focus is alert triage at machine speed, automated CTI enrichment, and MITRE ATT&CK mapping. For Blue teams, human-in-the-loop (HITL) architecture remains a feature on purpose to gate high-risk containment actions.
- Vigil (github.com/Vigil-SOC/vigil): An Apache 2.0, MCP-native open-source AI SOC. It utilizes plain Markdown playbooks and highly readable Python code to coordinate 12 specialized agents (such as Triage, Hunter, and Responder) while integrating natively with over 30+ MCP servers (Splunk, CrowdStrike, VT, Jira).
- Agentic SOC Platform (github.com/FunnyWolf/agentic-soc-platform): A turnkey, SIEM-native platform leveraging LangGraph and Dify templates. It ingests production alerts via webhooks and Redis Streams from SIEMs (Splunk/ELK) into a customizable Incident Response platform (SIRP) with absolute confidence-gated analyst approvals.
- SamiGPT / AI-SOC-Agent (github.com/M507/AI-SOC-Agent): Showcased originally at Black Hat 2025, this tool acts as an MCP server that exposes multi-tier SOC capabilities (routing workflows dynamically from
soc1_triagetosoc2_analysisand up to final escalations) directly to standard MCP clients.
π΄ The Red Team Agents: Absolute Autonomyβ
For offensive operations, absolute autonomy is the primary goal rather than an enterprise risk. These tools trust their own sandboxed execution loops to systematically break down attack surfaces without requiring human feedback.
- PentAGI (github.com/vxcontrol/pentagi): A fully autonomous penetration testing framework running on Go and Python. Agents break goals down into sub-tasks and execute terminal/browser actions to chain 20+ professional tools (nmap, metasploit, sqlmap), logging real-time telemetry to a Neo4j knowledge graph.
- RedAmon (github.com/samugit83/redamon): A modular, containerized Docker pipeline mapping infrastructure surfaces by fanning out parallel recon agents (subfinder, amass, fuzzers) and directly piping findings into exploitation loops for privilege escalation and subnet pivoting.
- Decepticon (github.com/PurpleAILAB/Decepticon): An orchestrator layer built on LangGraph and MCP running inside a Kali Linux container. It runs multi-agent operations through the kill chain and records complete sessions into shareable JSON logs so the community can pull request and share offensive methodology as data.
The Convergenceβ
John closed with a fascinating forecast: we are rapidly moving to a state where blue agents autonomously process and mitigate live telemetry streams generated by unattended red agents in real time. The ultimate question is no longer "Will agents replace human security analysts?" but rather: "Whose agents are faster, and what does the human in the middle do?"
π§π· ICLR Highlights & The State of Recursive Self-Improvementβ
Presented by Julian Gβ
Fresh off a plane from Rio de Janeiro, Julian G brought the best of the International Conference on Learning Representations (ICLR 2026) directly to our community. Julian curated a brilliant meta-analysis of the conference, focusing specifically on the rapidly evolving field of recursive self-improvement.
Julian highlighted how the AI research community is moving past static post-training (like standard RLHF) toward systems that can autonomously generate their own training data, critique their own reasoning, and modify their underlying architectures or prompting loops to achieve exponential capability gains. The velocity of research in this specific domain is staggering, and Julian's synthesis provided a foundational framework for understanding where LLM autonomy is heading over the next 6 to 12 months.
π From Research to Reality: ClaudeFlare & Production Edge Deploymentsβ
Presented by Jordannβ
Bridging the gap between theory and cloud execution, Jordann took the stage to detail his latest architecture built entirely on top of Cloudflareβs global edge network. He unveiled ClaudeFlareβan open-source framework focused on local-first orchestration promoted seamlessly to serverless edge infrastructure.
You can explore Jordann's active deployment hub here: π Organized AI Hub
Jordann broke down the system architecture into four architectural core pillars:
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β CLAUDEFLARE ARCHITECTURE β
βββββββββββββββββββββββββββββββββββββ¬βββββββββββββββββββββββββββββββββββββ€
β 1. EPHEMERAL CF WORKERS β 2. AUTO-DOCS ON CF PAGES β
β Task Arrives β Worker Spins Up β Code Ships β Manifest Inspected β
β Executes β Self-Deletes β Claude Generates HTML β
β Zero Billing at Idle β Instantly Deploys to CF Pages β
βββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββ€
β 3. CLAWBOX CONTROL PLANE β 4. AGENT CLIENT PROTOCOL (ACP) β
β Local-First Tauri v2 App β Standardized Wire Format (JSON-RPC)β
β Orchestrate, Tail, & Skill-Edit β Interoperable Across Editors β
β Promote to Edge via Wrangler β Zed Β· VSCode Β· acpx Client Sync β
βββββββββββββββββββββββββββββββββββββ΄βββββββββββββββββββββββββββββββββββββ
The Architecture Breakdown:β
- Disposable Ephemeral Workers: Unlike persistent agent servers, workers in ClaudeFlare act as single-use "task envelopes." A centralized
flair-dispatchergateway ingests events, looks up the task manifest in KV, and dispatches to specific Cloudflare Queues (FLAIR_DOC_QUEUE,FLAIR_SPAWN_QUEUE). Workers hydrate context from KV/D1, complete exactly one job, emit outputs to an R2 bucket or outbound queue, and scale to zero instantly. - Autonomous Documentation via CF Pages: Every individual project layer carries a
flair.layer.jsonmanifest. Upon running awrangler deploy, a specializedworker-doc-genworker triggers automatically. It passes the manifest layer metrics to Claude Sonnet to generate an HTML architecture guide and publishes it immediately to Cloudflare Pages at predictable*.organizedai.vipsubdomains, meaning docs are always mathematically in sync with production code. - The ExoClaw Tailscale Bridge: Because Cloudflare Workers cannot inherently traverse a secure Tailscale mesh, Jordann introduced an
exoclaw-bridgeworker. This functions as an authenticated public-to-private proxy, authorizing workflows via unique Codex tokens and routing internal inference calls securely to private multi-modal infrastructure (OpenClawand localGemma 3clusters) without exposing explicit API keys to the public edge.
Closing the Loopβ
In a fantastic display of the collaborative spirit that defines AI MUG, Julian's theoretical deep-dive on self-improvement sparked immediate engineering action. In response to Julian's presentation, Jordann compiled and shared an extensive practical guide detailing how these exact ephemeral Cloudflare primitivesβKV state stores, decoupled queues, and iterative LLM evaluationsβcan be wired together to build robust, self-correcting agent loops: π Organized AI Self-Improving Guide
π€ Community Notes & Next Stepsβ
A huge thank you to John, Julian, and Jordann for their presentations, and to everyone who attended and made it an engaging experience.
We are planning our June meetup. If you have a project, a research paper synthesis, or a deployment war story you want to share with the group, reach out via Discord or join our office hours to grab a speaking slot!
*See you at the next meetup!