{"id":705212,"date":"2026-07-22T12:33:14","date_gmt":"2026-07-22T12:33:14","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/705212\/"},"modified":"2026-07-22T12:33:14","modified_gmt":"2026-07-22T12:33:14","slug":"ciscos-open-weight-bug-busters-take-on-google-and-openai","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/705212\/","title":{"rendered":"Cisco&#8217;s open-weight bug busters take on Google and OpenAI"},"content":{"rendered":"<p class=\"kicker \" style=\"\">Security<\/p>\n<p class=\"subtitle \" style=\"\">Don&#8217;t call them chatbots<\/p>\n<p>Who needs expensive frontier models to find software vulns? Cisco has just released two open-weight models that specialize in finding known bugs in existing codebases. The models, Antares-350M and Antares-1B, are part of Cisco\u2019s new Antares family of security small language models (SLMs), and are now <a href=\"https:\/\/huggingface.co\/collections\/fdtn-ai\/antares\" rel=\"nofollow noopener\" target=\"_blank\">available on Hugging Face<\/a> &#8211; but only to vetted users.<\/p>\n<p>\u201cWe\u2019re making sure we\u2019re gating that and appropriately granting access,\u201d DJ Sampath, Cisco&#8217;s senior vice president and general manager of AI software and platform, told The Register.<\/p>\n<p>The company is working with academic and nonprofit organizations, as well as smaller and public organizations\u2019 security teams, to ensure they have access to the vulnerability-hunting models.<\/p>\n<p>Plus, because both are small models designed to run locally, \u201cyou also need the keys to the source code\u201d to scan for and find vulnerabilities, Sampath said. \u201cThis means an attacker is going to be able to exploit an endpoint or a service that you have.\u201d <\/p>\n<p>It also means that proprietary code never leaves the organization\u2019s machines, compared to cloud-based LLMs that send code to the AI providers\u2019 external servers for processing and analysis. This enables security analysis in environments with strict privacy or compliance requirements, according to the networking and security giant.<\/p>\n<p>And yes, it&#8217;s named after the massive red super-giant star. <\/p>\n<p>\u201cIt&#8217;s almost 1,000 times bigger than the sun, even though the sun dominates the sky, and that is the analogy that we&#8217;re using here for vulnerability detection and localization,\u201d Cisco VP and chief AI scientist Amin Karbasi told The Register. \u201cThe impact of vulnerabilities in your codebase is huge, but it might be only a single file or a few lines of code in a million lines of code.\u201d<\/p>\n<p>A future, 3-billion-parameter model in the Antares family won\u2019t be released to the public, Karbasi added. \u201cWe are completely gating the 3B model to make sure that we responsibly release it to communities that need it,\u201d he said.<\/p>\n<p>Small yet mighty<\/p>\n<p>Cisco claims that its models perform as well as or better than dozens of larger models in its <a href=\"https:\/\/blogs.cisco.com\/ai\/introducing-antares-the-most-efficient-open-weight-ai-models-for-vulnerability-localization\" rel=\"nofollow noopener\" target=\"_blank\">new benchmark test<\/a> that measures how efficiently AI models identify security flaws in codebases. Antares-1B outperforms Google\u2019s Gemini 3 Pro and is comparable to Z.ai&#8217;s GLM-5.2, we\u2019re told, while the yet-to-be-released Antares-3B does a better job at finding vulnerabilities than GLM-5.2 and OpenAI\u2019s GPT-5.5.<\/p>\n<p>Plus, we\u2019re told that the small models scan code much faster and at a fraction of the cost of larger, token-gobbling AI systems.<\/p>\n<p>\u201cIf you look at the performance, in terms of the time it takes to finish 500 repositories, Antares finishes the entire cohort of repositories in 15 minutes, whereas frontier models take five hours,\u201d Karbasi said, adding that this translates to significantly less cost.\u00a0<\/p>\n<p>\u201cIt takes like less than $1 whereas frontier models are above $100 into $150 of cost,\u201d he added.<\/p>\n<p>The difference, Karbasi explained, is that Cisco took a \u201cfundamentally different approach\u201d to building Antares.<\/p>\n<p>            Sometimes you don&#8217;t need a private jet to go to a corner store<\/p>\n<p>\u201cThese models have been trained in a very different way,\u201d he said. \u201cAntares is inherently not a chatbot. It is an investigator. It is a search engine. It has to find a very specific thing that might be a needle in a haystack, and it goes and finds that.\u201d<\/p>\n<p>This required training the model on several different ways to search for vulnerabilities \u201cbecause one way of search may not actually be fruitful, then it has to change its strategy, do it another way, and then do it another way,\u201d Karbasi said. \u201cBecause it is very nimble and it\u2019s very small, it can actually do a lot of search at the same time, which is very different from bigger models.\u201d<\/p>\n<p>Karbasi likened it to a bicycle on a busy London street: \u201cYou can go much faster than the biggest truck.\u201d<\/p>\n<p>Or, to use Sampath\u2019s favorite analogy for the benefits of using a small, security-focused model to find bugs in code: \u201cSometimes you don&#8217;t need a private jet to go to a corner store, right?\u201d\u00ae<\/p>\n","protected":false},"excerpt":{"rendered":"Security Don&#8217;t call them chatbots Who needs expensive frontier models to find software vulns? Cisco has just released&hellip;\n","protected":false},"author":2,"featured_media":705213,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[554,733,4308,86,56,54,55],"class_list":["post-705212","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-technology","tag-uk","tag-united-kingdom","tag-unitedkingdom"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/705212","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=705212"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/705212\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/705213"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=705212"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=705212"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=705212"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}