The first public demo of Morpheus 2, September 16
An AI analyst that’s confidently wrong is worse than no analyst at all. It feels like decision support, and you act on it.
This summer showed what that looks like at scale. Roughly 1,200 AI agents coordinated an attack on production infrastructure and breached Hugging Face, testing thousands of attack paths at machine speed; the path that worked was buried among the ones that didn’t. OpenAI, Hugging Face, METR and Redwood Research all investigated, and a single conclusion runs through their published findings: the monitoring largely worked. Alerts fired. What failed was the verdict once they did.
On September 16 we’re running a one-hour session on exactly that: how to make sure the verdict you act on is a verdict you can trust, plus the first public demo of Morpheus 2, built for it. Register here.
Why this is now every SOC manager’s problem
Your team already can’t clear the queue. AI is the only way to keep pace with an attacker who tries a path, discards it, and tries the next faster than any analyst can follow. But the technology being sold to you as the answer is the same technology that just narrated its way through a breach. So the question is how much of its work you can check, because the more of an AI’s work you can check, the more work you can give it. A verdict your team can verify in seconds is a verdict they can act on. A verdict they can’t verify gets re-investigated, and there goes the time the AI was supposed to save.
Filip Stojkovski’s 2026 AI SOC Core Components puts it precisely: correlating signals is half the job; re-scoring their severity is the other half. Both victims did half and missed the other.

What you’ll see on the 16th
Phil will run four things live during the demo:
- Every finding graded: confirmed, inferred, or gap. Your analysts see what’s proven, what’s the AI’s judgment, and what’s missing. A confident-but-wrong verdict has nowhere to hide.
- Evidence while the alert is open. Every verdict traced to its source in real time, so “what did it do, and why” is answered during the alert, not in a forensic reconstruction weeks later.
- Plain-language interrogation across your stack. Ask “have we seen this IP anywhere else in the last 30 days?” and get a live answer. No query syntax, no four consoles.
- Response only inside guardrails you set. The AI drafts the playbook from its own investigation. You approve it. It runs exactly that, every step logged before it fires.
That’s the decision quality layer. Morpheus 2 is the first agentic SOC platform built around it: investigation on every alert, up to 95% in under two minutes, findings graded, evidence attached, response inside your guardrails.
Register for September 16. Can’t make the hour? Register anyway and we’ll send the recording.
Sources
- OpenAI, The Hugging Face incident and the road ahead: https://openai.com/index/hugging-face-incident-and-the-road-ahead/
- METR & Redwood Research, independent investigation: https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/
- Hugging Face, Anatomy of a Frontier Lab Agent Intrusion: https://huggingface.co/blog/agent-intrusion-technical-timeline
- Filip Stojkovski, AI SOC Core Components, 2026 Edition: https://www.cybersec-automation.com/p/ai-soc-core-components-2026-edition

