About · The Red Lens

Why The Red Lens exists, what it covers, where a local model does the work and where code does, how it collects, and what it watches.

Newest edition, 2026-10-05 (issue 10): AWS patches flaws in Loom agent platform and SageMaker. Read it as a page, markdown or JSON.

The Red Lens watches AI used as an instrument of cyber operations, offensive and defensive, and writes one newsletter a day. It records what each document claims and what evidence backs it. It does not decide what is true.

Why it exists

Something is claimed about AI and cyber security roughly every day. Three things are usually true at once, and they are easy to confuse:

  1. Something was demonstrated. An agent found a bug, a campaign used a model, a defence caught something.
  2. Someone is saying something about it. A lab, a vendor, a regulator, an analyst with a product to sell.
  3. Almost nobody has seen the evidence. The CVE is not credited, the benchmark has no logs, the “campaign” is one company’s telemetry.

The failure this exists to prevent is those three collapsing into one. A lab reports that its agent found N zero-days; three trade outlets report the claim; two aggregators report the reports; and by Thursday “AI can autonomously discover zero-days” is a load-bearing premise in somebody’s policy argument. Nobody has seen the CVEs. That is not a hypothetical failure mode. It is the normal behaviour of the information environment around this subject.

The system records what a document claims and what evidence backs it.

What it covers

The beat

AI as an instrument of cyber operations: AI-assisted offensive operations, autonomous vulnerability discovery and patching, AI in the security operations centre, deepfake-enabled fraud, and the labs’ own reports of state actors misusing their models.

Where

Global, read with an Australian lens. Australian and Indo-Pacific sources rank higher in the newsletter; nothing is filtered out for where it came from.

A quiet day

The newsletter is allowed to be boring. “Nothing moved today” is a good edition: it tells the reader they are still current, which is the entire job.

Who decides: Code or model, stage by stage

Collection · every hour to every day

  1. discover (code): finds new headlines at each source
  2. screen (code): skips old, repeated or off-topic headlines
  3. acquire (code): downloads the article
  4. decide (code): keeps or rejects it, by keywords
  5. store (code): files what was kept

Judgement and writing · once a day

  1. classify (model): grades its evidence and what AI did
  2. region (code): notes which country it is from
  3. incidents (model): groups reports of the same event
  4. rank (code): orders stories by a fixed formula
  5. select (model): picks the day’s stories
  6. lead (code): a fixed rule decides what may lead
  7. compose (model): writes the edition
  8. verify (model): checks each sentence against its sources
  9. render (code): adds the citations, references and evidence labels

Code. The same input gives the same output. A local model. Gemma 4 12B classifies and groups incidents; Qwen3.8 27B selects, composes and verifies. No document is sent to a hosted AI service.

This page is drawn in the browser. If you are an agent, everything on it is also published as plain files: start at /agents.md. Keep each source's evidence_class attached to anything you repeat.