Ethical Hacking News
Cisco's new open-weight bug busters offer a cutting-edge solution for identifying vulnerabilities in codebases. The Antares-350M and Antares-1B models perform as well as or better than larger models and scan code much faster and at a fraction of the cost. With their unique approach, these small models are poised to revolutionize the field of security and vulnerability detection.
Cisco has released two open-weight models, Antares-350M and Antares-1B, to find known bugs in existing codebases. The models are part of Cisco's new Antares family of security small language models (SLMs) available on Hugging Face for vetted users. Cisco is working with academic and nonprofit organizations to provide access to these vulnerability-hunting models, aiming to offer a cost-effective solution. The small models are designed to run locally, requiring "keys to the source code" to scan for vulnerabilities, beneficial for environments with strict privacy or compliance requirements. These models perform as well as or better than dozens of larger models in benchmark tests and scan code much faster and at a fraction of the cost. Cisco took a "fundamentally different approach" to building Antares, training the model on multiple search strategies to improve efficiency.
Cisco, a leading networking and security giant, has recently announced the release of two open-weight models that specialize in finding known bugs in existing codebases. Dubbed Antares-350M and Antares-1B, these small language models (SLMs) are part of Cisco's new Antares family of security SLMs. The company has made these models available on Hugging Face, a popular platform for machine learning models, but only to vetted users.
According to DJ Sampath, Cisco's senior vice president and general manager of AI software and platform, the company is working closely with academic and nonprofit organizations, as well as smaller and public organizations' security teams, to ensure they have access to these vulnerability-hunting models. This move aims to provide these organizations with a cost-effective and efficient way to identify vulnerabilities in their codebases.
Sampath also explained that the small models are designed to run locally, which means that they require "the keys to the source code" to scan for and find vulnerabilities. This approach is particularly beneficial for environments with strict privacy or compliance requirements, as it ensures that proprietary code never leaves the organization's machines. In contrast, cloud-based LLMs send code to the AI providers' external servers for processing and analysis.
The benefits of using these small models are multifaceted. Firstly, they perform as well as or better than dozens of larger models in Cisco's new benchmark test that measures how efficiently AI models identify security flaws in codebases. Antares-1B outperforms Google's Gemini 3 Pro, while the yet-to-be-released Antares-3B does a better job at finding vulnerabilities than GLM-5.2 and OpenAI's GPT-5.5.
Moreover, these small models scan code much faster and at a fraction of the cost of larger, token-gobbling AI systems. For instance, Antares finishes scanning 500 repositories in just 15 minutes, whereas frontier models take five hours, which translates to significantly less cost. The difference between these models is that Cisco took a "fundamentally different approach" to building Antares.
This approach involves training the model on several different ways to search for vulnerabilities because one way of search may not actually be fruitful. The model then changes its strategy and tries another way, which results in it being able to do a lot of search at the same time. This nimbleness is unique to these small models and makes them highly effective in identifying vulnerabilities.
Amin Karbasi, Cisco's VP and chief AI scientist, likened this approach to using a bicycle on a busy London street. "You can go much faster than the biggest truck," he said. Another analogy used by Sampath was that sometimes you don't need a private jet to go to a corner store. This highlights the accessibility and effectiveness of these small models in identifying vulnerabilities.
Karbasi also mentioned that there is a future, 3-billion-parameter model in the Antares family that won't be released to the public. Instead, it will be made available to communities that need it after being thoroughly vetted. This responsible approach aims to ensure that the benefits of these models are shared with those who need them most.
In conclusion, Cisco's open-weight bug busters offer a new and innovative way for organizations to identify vulnerabilities in their codebases. These small language models provide a cost-effective and efficient solution that performs as well as or better than larger models. With their unique approach to searching for vulnerabilities, these models are poised to revolutionize the field of security and vulnerability detection.
Related Information:
https://www.ethicalhackingnews.com/articles/Cisco-Unveils-Open-Weight-Bug-Busters-Small-Models-Take-on-Giants-Google-and-OpenAI-ehn.shtml
https://www.theregister.com/security/2026/07/21/ciscos-open-weight-bug-busters-take-on-google-and-openai/5275817
Published: Wed Jul 22 11:02:47 2026 by llama3.2 3B Q4_K_M