[Photo: Google Gemini]

[DigitalToday reporter Chi-gyu Hwang (황치규)] Competition is heating up over security-focused AI models aimed at finding software vulnerabilities and helping solve problems. As malicious hackers actively use AI in cyber attacks, the industry’s push toward AI-based security is gaining pace.

According to the related industry, major AI companies such as Anthropic and OpenAI are being joined by enterprise heavyweights including Google, Cisco and Microsoft in a race to build security-focused AI models.

Anthropic offers Mithos5, and OpenAI has recently been providing Sol, the top model in its GPT-5.6 series, tailored for cybersecurity.

Google also unveiled Gemini 3.5 Flash Cyber, a security-focused model, as it introduced three new Gemini models in July highlighting price and efficiency.

Gemini 3.5 Flash Cyber is a model that detects and patches software vulnerabilities. At first, only governments and trusted partners can use it in a limited-access pilot. Google highlighted that Gemini 3.5 Flash Cyber is cheaper per token than larger models.

Around the same time as Google, Cisco unveiled Antares, a family of small language model products that filters files in code repositories that are highly likely to contain known security vulnerabilities. Cisco distributed Antares-350M and Antares-1B on Hugging Face as open-weights by publishing the weights, and plans to release a larger model, Antares-3B.

According to the company, Antares was developed by Cisco Foundation AI, Cisco’s security-focused AI research and engineering organization. It is focused on narrowing down where vulnerabilities are by linking public vulnerability databases, security advisories and Common Weakness Enumeration information to specific files in code repositories.

Based on vulnerability descriptions, Antares searches for related code patterns and candidate files, changes its path as it incorporates clues, and presents rankings of the most likely files. The output also includes the final exploration path.

All Antares models can run locally. Security teams can analyze in their own environments without sending sensitive source code to the cloud. Cisco views it as suitable for universities, the public sector, non-profit organizations and small security teams that lack budgets for commercial models.

Microsoft on July 28 unveiled MAI-Cyber-1-Flash, an AI model specialized for cybersecurity. According to the company, MAI-Cyber-1-Flash is designed to find hard-to-detect vulnerabilities in complex codebases. It will be embedded in Microsoft MDASH, a platform for identifying and fixing software vulnerabilities. Microsoft emphasized that, based on existing AI cybersecurity benchmarks, MAI-Cyber-1-Flash outperforms rival models in performance and cost efficiency.

Startups are also accelerating their moves toward security-focused models. According to SiliconANGLE, Cogent Security on July 28 unveiled VR-1, a frontier reasoning model that finds and proves real internal attack paths in enterprises.

The model was trained to identify attack paths in live enterprise environments that pass through cloud infrastructure, identity systems and internal tools, and to verify them through actual execution.

According to the company, VR-1 proved twice as many attack paths as other frontier models on Cogent’s benchmark, IntrusionBench. Costs were about a quarter of the level.

The performance figures were measured in an environment that the agent infiltrated without being provided any information. The comparators were Kimi K3, Claude Opus 4.8 and GLM-5.2.

Cogent said real intrusions are far more complex than detecting a single code vulnerability. It explained that intrusions may be possible by linking weaknesses that can each look minor, such as small flaws in publicly exposed services or accounts with more privileges than necessary. The company emphasized that VR-1 supports connecting these vulnerabilities like an attacker and can also verify whether proposed fixes eliminated the risk or moved it elsewhere.

Cogent AI Harness, introduced alongside VR-1, provides environment information, limited tools and policy enforcement functions for both open-weights and closed models. All actions are validated under customer policies.

To use VR-1, users must pass screening for the Cogent Frontier Access Program. Cogent, founded in 2025, is staffed by research and operations personnel from Google DeepMind, Abnormal AI and Coinbase. It provides AI agents that investigate vulnerabilities, deliver them to responsible teams and then verify whether fixes were applied.

Keyword

#Anthropic #OpenAI #Google #Cisco #Microsoft
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.