Security
Cisco's Small Cyber Models Put AI Bug Hunting Closer To The Codebase
Cisco's open-source Antares models are aimed at software bug hunting, adding to a push to put compact AI systems inside security workflows rather than reserve them for large general assistants.
By Leo W ·

Cisco has open-sourced two compact models for bug hunting, Antares-350M and Antares-1B, according to Axios. The release arrives as security teams are trying to decide where AI belongs in the code-review process. The useful question is not whether a model can produce a clever vulnerability explanation. It is whether it can help engineers find the few issues worth investigating without adding another stream of noisy alerts.
Small models are a deliberate choice. Security review often happens repeatedly across repositories and pull requests. A compact system can be cheaper to run, easier to place near existing tooling and more realistic for teams that cannot send every code change to a premium hosted model. That does not make it safe by default. It makes the operational tradeoff clearer.
Axios also reported that Capital One recently open-sourced VulnHunter, an agentic tool intended to review source code from an attacker's perspective. The pattern is worth watching. Security vendors and large technology users are beginning to treat AI-assisted review as a toolchain problem: models, context retrieval, static analysis, validation and a human engineer who can decide whether a finding is real.
The developer-tools test is straightforward. A useful security model has to fit the workflow. It should point to the code path, explain the suspected condition, carry enough context for a reviewer to reproduce it and avoid suggesting a patch that introduces a different problem. An assistant that only writes a plausible warning is not doing the expensive part of the work.
NIST has argued for continuous monitoring and update models for AI security systems. That is relevant here because code and dependencies do not stand still. A model review may catch a pattern today and miss a new library behavior tomorrow. Teams will need evaluation sets, feedback loops and clear ownership for keeping an AI reviewer useful after its first deployment.
Open sourcing the models changes the security posture in two directions. Developers can inspect, adapt and run them locally. That may help teams with strict source-code controls. It also means the original vendor cannot rely on a hosted access layer to limit every use. The relevant safeguard moves outward to the organization that integrates the model and decides what it can touch.
Cisco's release will matter if it helps teams close the gap between a vulnerability signal and a verified engineering task. That is a narrow ambition, but it is the right one. Security AI earns trust when it reduces the time spent chasing dead ends and gives the person on call a better place to start.
Topics: Cisco, Antares, security, open source