Cisco has launched Antares-350M and Antares-1B, two cyber-focused small language models built to identify vulnerable files in source-code repositories from vulnerability descriptions. The company said the open-weight models will be released on Hugging Face and are designed to run locally, allowing security teams to analyze sensitive codebases without sending source code to cloud-hosted frontier models. Cisco positioned Antares for repository-level vulnerability localization, advisory triage, static-analysis augmentation, and shift-left security workflows in CI/CD pipelines.
Cisco said Antares mimics a human investigator by tracing relevant code patterns, reviewing candidate files, and narrowing findings as new evidence emerges. In its announcement and related reporting, Cisco claimed the models can perform repository analysis at a fraction of the compute cost of larger general-purpose models, citing a 500-entry evaluation completed in 15 minutes on a single GPU for less than $1. Cisco also said Antares outperformed several OpenAI and Google models on vulnerability-finding benchmarks, though reporting noted it did not exceed OpenAI's premium GPT-5.5 (xhigh) and that Anthropic's Claude Opus 4.6 scored higher in a Cisco technical report.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Cisco said the Antares family also includes a 3B parameter model and described support for local inference, repository-wide scans, targeted CWE investigations, and SARIF output. The company positioned these features as enabling low-cost deployment while keeping proprietary code within an organization's trust boundary.
Cisco Foundation AI released a 500-entry Vulnerability Localization Benchmark to evaluate repository-level vulnerability localization across unfamiliar codebases and CWE-linked vulnerability patterns. Cisco said the benchmark showed Antares performing faster and at lower cost than larger competing models while supporting human-led triage.
Cisco announced the Antares family of open-weight small language models for repository-level vulnerability localization, including Antares-350M and Antares-1B. The company positioned them as efficient models for codebase analysis and said they would be released on Hugging Face.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcesecurityweek.com
Open sourceitpro.com
Open sourceblogs.cisco.com
Open sourcetheregister.com
Open sourcesdxcentral.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.