{"id":16496,"date":"2026-07-22T16:51:57","date_gmt":"2026-07-22T16:51:57","guid":{"rendered":"https:\/\/newestek.com\/?p=16496"},"modified":"2026-07-22T16:51:57","modified_gmt":"2026-07-22T16:51:57","slug":"ciscos-new-ai-model-tells-code-reviewers-where-to-look-for-vulnerabilities","status":"publish","type":"post","link":"https:\/\/newestek.com\/?p=16496","title":{"rendered":"Cisco\u2019s new AI model tells code reviewers where to look for vulnerabilities"},"content":{"rendered":"<div>\n<div id=\"remove_no_follow\">\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<section class=\"wp-block-bigbite-multi-title\">\n<div class=\"container\"><\/div>\n<\/section>\n<p class=\"wp-block-paragraph\">Cisco has revealed a family of open-weight AI models called Antares that, it said, can help security teams isolate potentially vulnerable parts of a software repository before deeper investigation begins.<\/p>\n<p class=\"wp-block-paragraph\">Rather than detecting a specific CVE or generating a patch, these models search a codebase using only a Common Weakness Enumeration (CWE) description and return the files most likely to contain that class of vulnerability.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIts purpose is to reduce a large codebase to a focused set of files that a security professional or a downstream security workflow should investigate,\u201d Cisco\u2019s AI researcher <a href=\"https:\/\/www.linkedin.com\/in\/supriti-vijay\/\" target=\"_blank\" rel=\"noreferrer noopener\">Supriti Vijay<\/a> said via email. \u201cThe goal is not to replace a security engineer\u2019s judgement or send them on a wild-goose chase, but to reduce fatigue and workload by helping them triage an issue earlier and focus their investigation on the most relevant parts of the codebase.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The Antares family consists of models with 350 million, 1 billion, and 3 billion parameters trained specifically for repository-scale vulnerability localization.<\/p>\n<p class=\"wp-block-paragraph\">The company said its largest model approaches the performance of GPT-5.5 on its internal vulnerability localization (Vloc) benchmark while remaining small enough for low-cost local deployment.<\/p>\n<h2 class=\"wp-block-heading\" id=\"a-search-assistant-not-a-vulnerability-detector\">A search assistant, not a vulnerability detector<\/h2>\n<p class=\"wp-block-paragraph\">Cisco is careful to define what Antares is, and what it is not.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAntares outputs a ranked list of source files likely to contain a relevant vulnerability, along with the terminal exploration trace that led to that result,\u201d Cisco Foundation AI Chief Scientist <a href=\"https:\/\/www.linkedin.com\/in\/amin-karbasi-5025335\/\" target=\"_blank\" rel=\"noreferrer noopener\">Amin Karbasi<\/a> wrote in a blog post, adding that the models are not meant to replace the broader application security toolchain: Human analysts or downstream security tools will still be needed to confirm exploitability, <a href=\"https:\/\/www.infoworld.com\/article\/4200083\/gitlab-previews-auto-remediation-of-vulnerable-dependencies.html\">identify vulnerable lines of code<\/a>, assess severity and generate fixes.<\/p>\n<p class=\"wp-block-paragraph\">Antares differs from conventional static analysis platforms such as Semgrep or CodeQL, which primarily rely on predefined rules or queries. Cisco instead describes Antares as an evidence-driven exploration agent that adapts its search as it traverses the repository.<\/p>\n<p class=\"wp-block-paragraph\">Cisco\u2019s argument is that large repositories often contain thousands of files, making manual reviews exhaustive and unrealistic. By reducing the search space to a manageable shortlist, the company hopes to reduce investigation fatigue without replacing human judgement.<\/p>\n<h2 class=\"wp-block-heading\" id=\"claims-of-specialization-over-scale\">Claims of specialization over scale<\/h2>\n<p class=\"wp-block-paragraph\">Cisco is also making a statement about how cybersecurity models should evolve.<\/p>\n<p class=\"wp-block-paragraph\">Instead of pursuing larger foundational models, Cisco argued that specialized, task-trained models can outperform much larger open-weight alternatives for vulnerability localization. In its evaluation Antares-3B, the largest model intended for single-GPU deployments, produced results comparable to GPT-5.5 while outperforming several substantially larger open models by Google, OpenAI and Meta.<\/p>\n<p class=\"wp-block-paragraph\">The family also includes Antares-350M for resource-constrained environments and Antares-1B for laptops and workstations, which Cisco has made available as open-weight models on Hugging Face.<\/p>\n<p class=\"wp-block-paragraph\">The command line interface (CLI) on the models supports targeted CWE investigations, repository-wide scans, SARIF output and local inference, which Cisco said enables organizations to keep proprietary code inside their own trust boundary.<\/p>\n<p class=\"wp-block-paragraph\">However, because Antares identifies candidate files rather than confirmed vulnerabilities, organizations will still need to understand how often such repository-wide searches should be run, how much they improve existing triage workflows, and whether the reduction in investigation effort ultimately translates into measurable security or cost benefits.<\/p>\n<p class=\"wp-block-paragraph\"><em>This article first appeared on <a href=\"https:\/\/www.infoworld.com\/article\/4200143\/ciscos-new-ai-model-tells-code-reviewers-where-to-look-for-vulnerabilities.html\">InfoWorld<\/a>.<\/em><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cisco has revealed a family of open-weight AI models called Antares that, it said, can help security teams isolate potentially vulnerable parts of a software repository before deeper investigation begins. Rather than detecting a specific CVE or generating a patch, these models search a codebase using only a Common Weakness Enumeration (CWE) description and return the files most likely to contain that class of vulnerability&#8230;. <\/p>\n<p class=\"more\"><a class=\"more-link\" href=\"https:\/\/newestek.com\/?p=16496\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-16496","post","type-post","status-publish","format-standard","hentry","category-uncategorized","is-cat-link-borders-light is-cat-link-rounded"],"_links":{"self":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16496","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16496"}],"version-history":[{"count":0,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16496\/revisions"}],"wp:attachment":[{"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16496"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16496"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16496"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}