{"id":8846,"date":"2026-07-22T16:47:24","date_gmt":"2026-07-22T16:47:24","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=8846"},"modified":"2026-07-22T16:47:24","modified_gmt":"2026-07-22T16:47:24","slug":"ciscos-new-ai-model-tells-code-reviewers-where-to-look-for-vulnerabilities","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=8846","title":{"rendered":"Cisco\u2019s new AI model tells code reviewers where to look for vulnerabilities"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Cisco has revealed a family of open-weight AI models called Antares that, it said, can help security teams isolate potentially vulnerable parts of a software repository before deeper investigation begins.<\/p>\n<p class=\"wp-block-paragraph\">Rather than detecting a specific CVE or generating a patch, these models search a codebase using only a Common Weakness Enumeration (CWE) description and return the files most likely to contain that class of vulnerability.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIts purpose is to reduce a large codebase to a focused set of files that a security professional or a downstream security workflow should investigate,\u201d Cisco\u2019s AI researcher <a href=\"https:\/\/www.linkedin.com\/in\/supriti-vijay\/\" target=\"_blank\" rel=\"noopener\">Supriti Vijay<\/a> said via email. \u201cThe goal is not to replace a security engineer\u2019s judgement or send them on a wild-goose chase, but to reduce fatigue and workload by helping them triage an issue earlier and focus their investigation on the most relevant parts of the codebase.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The Antares family consists of models with 350 million, 1 billion, and 3 billion parameters trained specifically for repository-scale vulnerability localization.<\/p>\n<p class=\"wp-block-paragraph\">The company said its largest model approaches the performance of GPT-5.5 on its internal vulnerability localization (Vloc) benchmark while remaining small enough for low-cost local deployment.<\/p>\n<h2 class=\"wp-block-heading\">A search assistant, not a vulnerability detector<\/h2>\n<p class=\"wp-block-paragraph\">Cisco is careful to define what Antares is, and what it is not.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAntares outputs a ranked list of source files likely to contain a relevant vulnerability, along with the terminal exploration trace that led to that result,\u201d Cisco Foundation AI Chief Scientist <a href=\"https:\/\/www.linkedin.com\/in\/amin-karbasi-5025335\/\" target=\"_blank\" rel=\"noopener\">Amin Karbasi<\/a> wrote in a blog post, adding that the models are not meant to replace the broader application security toolchain: Human analysts or downstream security tools will still be needed to confirm exploitability, <a href=\"https:\/\/www.infoworld.com\/article\/4200083\/gitlab-previews-auto-remediation-of-vulnerable-dependencies.html\">identify vulnerable lines of code<\/a>, assess severity and generate fixes.<\/p>\n<p class=\"wp-block-paragraph\">Antares differs from conventional static analysis platforms such as Semgrep or CodeQL, which primarily rely on predefined rules or queries. Cisco instead describes Antares as an evidence-driven exploration agent that adapts its search as it traverses the repository.<\/p>\n<p class=\"wp-block-paragraph\">Cisco\u2019s argument is that large repositories often contain thousands of files, making manual reviews exhaustive and unrealistic. By reducing the search space to a manageable shortlist, the company hopes to reduce investigation fatigue without replacing human judgement.<\/p>\n<h2 class=\"wp-block-heading\">Claims of specialization over scale<\/h2>\n<p class=\"wp-block-paragraph\">Cisco is also making a statement about how cybersecurity models should evolve.<\/p>\n<p class=\"wp-block-paragraph\">Instead of pursuing larger foundational models, Cisco argued that specialized, task-trained models can outperform much larger open-weight alternatives for vulnerability localization. In its evaluation Antares-3B, the largest model intended for single-GPU deployments, produced results comparable to GPT-5.5 while outperforming several substantially larger open models by Google, OpenAI and Meta.<\/p>\n<p class=\"wp-block-paragraph\">The family also includes Antares-350M for resource-constrained environments and Antares-1B for laptops and workstations, which Cisco has made available as open-weight models on Hugging Face.<\/p>\n<p class=\"wp-block-paragraph\">The command line interface (CLI) on the models supports targeted CWE investigations, repository-wide scans, SARIF output and local inference, which Cisco said enables organizations to keep proprietary code inside their own trust boundary.<\/p>\n<p class=\"wp-block-paragraph\">However, because Antares identifies candidate files rather than confirmed vulnerabilities, organizations will still need to understand how often such repository-wide searches should be run, how much they improve existing triage workflows, and whether the reduction in investigation effort ultimately translates into measurable security or cost benefits.<\/p>\n<p class=\"wp-block-paragraph\"><em>This article first appeared on <a href=\"https:\/\/www.infoworld.com\/article\/4200143\/ciscos-new-ai-model-tells-code-reviewers-where-to-look-for-vulnerabilities.html\">InfoWorld<\/a>.<\/em><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Cisco has revealed a family of open-weight AI models called Antares that, it said, can help security teams isolate potentially vulnerable parts of a software repository before deeper investigation begins. Rather than detecting a specific CVE or generating a patch, these models search a codebase using only a Common Weakness Enumeration (CWE) description and return [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":8847,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-8846","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8846"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8846"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8846\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/8847"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8846"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8846"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8846"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}