
What happened
Cisco introduced Antares, a family of small language models (SLMs) designed to pinpoint where known vulnerabilities exist in codebases. Two models—Antares-350M and Antares-1B—are now available as open-weight models on Hugging Face. Benchmark testing shows these models outperform many larger closed- and open-weight models at a fraction of the cost.
Why it matters
Vulnerability localization is expensive and time-consuming, especially for organizations with constrained security resources like universities, nonprofits, and public-sector teams. Antares models are compact enough to run locally, eliminating the need to send sensitive source code to the cloud, and they work fast enough to integrate into continuous integration workflows where code is checked before it lands.
What to watch
Antares-3B is coming soon. The models are available now on Hugging Face, alongside a new Vulnerability Localization Benchmark (a 500-task benchmark) and technical documentation. Cisco is also advancing a broader ecosystem through Foundry Security Spec (open specifications for agentic security systems) and CodeGuard (secure coding rules for AI agents).
Summaries like this, in your inbox every morning.
Vulnerability localization has long been a bottleneck in security operations—time-intensive work that demands expertise and often requires organizations to move sensitive code outside their environment. General-purpose AI models, while capable at broad code reasoning, were not designed for the specific task of finding known vulnerabilities within a repository. Antares addresses this gap by building on research from Cisco's Foundation AI team showing that compact models can learn useful search strategies through iterative exploration rather than relying solely on model scale.
The release of Antares alongside a new Vulnerability Localization Benchmark signals a shift toward specialized, measurable AI security tools. By publishing open-weight models and a benchmark, Cisco creates a shared standard against which future work can be evaluated—moving away from proprietary, closed-loop AI security products toward an ecosystem smaller teams and resource-constrained institutions can adopt. This is particularly significant for universities, nonprofits, and public-sector organizations that have historically lacked the budget for token-intensive AI services but maintain critical software that requires ongoing vulnerability management.
Cisco frames Antares as one piece of a broader effort to mature AI-assisted security. Foundry Security Spec provides an open blueprint for building agentic security systems with clear governance; CodeGuard contributes reusable secure coding rules; and Antares adds the compact models and benchmark needed to make vulnerability localization practical and measurable. The connective theme is shifting AI in security from one-off demos toward deployable systems practitioners can evaluate, govern, and improve.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
On September 18, 2026, four paid subscribers filed Buist et al

OpenAI launched Astra, which reportedly uses "recurrent depth" to make reasoning more efficient by not spellin…

A researcher at a Chinese frontier lab, who has read the Three Body Problem series since high school and grasp…

China's spy agency chief warned last week that AI's hacking abilities could jeopardize national security, and…

A former AI safety group organizer listed common mistakes in clubs

The NYT editorial board ran "Humanity Has Avoided Apocalypse Before
