6 Sources
[1]
Cisco's open-weight bug busters take on Google and OpenAI
Who needs expensive frontier models to find software vulns? Cisco has just released two open-weight models that specialize in finding known bugs in existing codebases. The models, Antares-350M and Antares-1B, are part of Cisco's new Antares family of security small language models (SLMs), and are
[2]
Cisco's AI shrinks haystacks to help security teams hunt needles
Cisco is betting that enterprises will see value in having AI quickly identify the handful of files worthy of investigation by human software vulnerability researchers. Cisco has revealed a family of open-weight AI models called Antares that, it said, can help security teams isolate potentially
[3]
Cisco's tiny open-weight AI hunts bugs, beating Gemini
The networking giant's Antares models run on your own machines and, it claims, localise vulnerabilities faster and cheaper than frontier systems. It is gating access, and withholding its strongest model, because a bug-finder is also a bug-exploiter. Cisco's new Antares models are small enough to
[4]
Introducing Antares: Highly Efficient Open Weight AI Models for Vulnerability Localization
Collaborator(s): Supriti Vijay, Aman Priyanshu, Didier Chapoteau, Arthur Goldblatt, Kimia Majd, Fraser Burch, Jianliang He, Baturay Saglam, Takahiro Matsumoto, Zhuoran Yang Today, Cisco is introducing Antares, a family of security small language models (SLMs) purpose-built for one of the hardest,
[5]
Cisco bets on small AI for cybersecurity
Why it matters: The models could give companies a cheaper way to repeatedly search large codebases for vulnerabilities without sending sensitive source code to an outside AI provider. Driving the news: Cisco debuted a new family of small language models, called Antares, that are specifically
[6]
Cisco releases Antares, open-weight small models for locating code vulnerabilities
Cisco Systems Inc. today introduced Antares, a family of small language models built to pinpoint where known security vulnerabilities sit inside a codebase, and released the first two as open-weight downloads on Hugging Face. The models come from Cisco Foundation AI, the company's research and
Share
Copy Link
Cisco unveiled Antares, a family of small language models designed for vulnerability detection that outperform Google Gemini and rival OpenAI GPT systems. The open-weight AI models run locally, scan 500 repositories in 15 minutes for less than $1, and keep proprietary code on-premises. Cisco is gating access due to dual-use risks, as tools that find bugs can also help attackers exploit them.
Cisco has released two open-weight AI models that specialize in vulnerability detection, challenging the notion that only expensive frontier systems can effectively hunt software bugs
1
. The Cisco Antares family includes Antares-350M and Antares-1B, both now available on Hugging Face to vetted users1
. These small language models are purpose-built to pinpoint where known vulnerabilities exist within a codebase, addressing one of the most time-consuming and expensive problems in security4
.
Source: SiliconANGLE
The networking giant's approach represents a quiet rebuke to the frontier-model arms race. "You really don't need a private jet to go to your corner store," DJ Sampath, Cisco's senior vice president and general manager of AI software and platform, told Axios . The models are designed to run locally, meaning proprietary code never leaves the organization's machines, unlike cloud-based systems that send code to external servers for processing
1
. This local deployment capability enables security analysis in environments with strict privacy or compliance requirements1
.Cisco claims that Antares-1B outperforms Google Gemini 3 Pro and matches Z.ai's GLM-5.2 on its new benchmark for vulnerability localization
1
. The unreleased Antares-3B model reportedly surpasses both GLM-5.2 and OpenAI GPT-5.5 at finding vulnerabilities1
. The real advantage appears in speed and cost-effective operation. Amin Karbasi, Cisco's vice president and chief AI scientist, revealed that Antares scans 500 software repositories in 15 minutes for less than $1, whereas frontier models take five hours and cost between $100 to $1501
.This efficiency matters for organizations that need to repeatedly search large codebases as software changes . Running large AI models across an organization's codebase can become expensive when defenders must rescan repositories continuously . The compact size of these AI-powered security tools makes AI-driven cybersecurity accessible to universities, public sector institutions, and smaller security teams that may have lacked resources to use token-intensive AI models
4
.What sets Cisco Antares apart is its fundamental architecture. "Antares is inherently not a chatbot. It is an investigator. It is a search engine," Karbasi explained
1
. The models were trained using learned search strategies that allow them to search, reflect, revise their approach, and backtrack when a path proves unproductive4
. Rather than detecting a specific CVE or generating a patch, these models search a codebase using only a Common Weakness Enumeration description and return the files most likely to contain that class of vulnerability2
.
Source: The Register
"Its purpose is to reduce a large codebase to a focused set of files that a security professional or a downstream security workflow should investigate," Cisco AI researcher Supriti Vijay explained
2
. The goal centers on reducing fatigue and workload by helping security teams triage an issue earlier and focus investigation on the most relevant parts of the codebase2
. Karbasi likened the nimble approach to a bicycle weaving past a truck on a busy London street3
.Related Stories
Cisco is carefully controlling who can access these open-weight AI models due to dual-use risks. A tool that finds flaws can also help attackers exploit them
3
. The company is vetting access to ensure cybersecurity defenders, not adversaries, gain access to the tools . Cisco is working with academic and nonprofit organizations, as well as smaller and public organizations' security teams, to ensure appropriate access1
. The company also worked with U.S. government agencies on the models' safety and release .The 3-billion-parameter Antares-3B model will not receive a public release
1
. Instead, Cisco plans to integrate it into its own security products while completely gating access to ensure responsible release to communities that need it1
. Reza Shokri, Associate Professor of Computer Science at the National University of Singapore, noted that AI agents now "write more of the code, and are growing capable of exploiting it"4
.Cisco's release extends beyond just the models themselves. By combining open-weight AI models with Antares, open specifications with Foundry Security Spec, secure coding guidance with CodeGuard, and a new benchmark, Cisco aims to define practical, trustworthy AI tools that help cybersecurity professionals
4
. The company is also exploring an industry consortium to expand its work on open AI security tools . This follows similar moves by other companies—Capital One recently open-sourced VulnHunter, an agentic AI security tool that reviews source code from an attacker's perspective . Amin Saberi, Professor at Stanford University, emphasized that "advanced AI-based detection has largely belonged to organizations with frontier-scale budgets," but Antares changes that equation by delivering near-frontier accuracy at a fraction of the cost4
. For organizations watching this space, the key question becomes whether small, specialized models can democratize AI-driven security capabilities while maintaining the triage efficiency needed to detect vulnerabilities in codebases at scale.Summarized by
Navi
[1]
[3]
02 Jun 2026•Technology
23 Mar 2026•Technology

21 Feb 2025•Technology

1
Technology

2
Technology

3
Policy and Regulation
