LIVE · cybersecurity feed
Live wire
vulnerability

Cisco Launches Low-Cost AI Models for Source Code Security

The open-weight Antares models are designed to pinpoint known vulnerabilities in codebases faster and at a fraction of the cost of larger AI models. The post Cisco Launches Low-Cost AI Models for Source Code Security appeared first on SecurityWeek.

zeroday.news · 11d ago

Cisco has reportedly introduced a new suite of artificial intelligence models, named Antares, specifically engineered to enhance source code security by identifying known vulnerabilities. These models are described as open-weight, indicating a potential for broader accessibility and community-driven development or inspection, and are positioned as a cost-effective alternative to larger, more resource-intensive AI solutions currently available.

The Antares models are designed with a primary objective of accelerating the detection of established security flaws within software codebases. This capability is critical in modern software development lifecycles, where the rapid pace of development often necessitates automated tools to maintain security hygiene. By focusing on known vulnerabilities, the models likely leverage extensive datasets of previously identified weaknesses, common exploit patterns, and established security best practices to train their detection algorithms.

The "open-weight" designation for the Antares models suggests that Cisco may be making the model parameters and architecture publicly available, or at least accessible to a wider audience than proprietary, closed-source models. This approach can foster transparency, allow security researchers to scrutinize the models for biases or limitations, and potentially enable custom fine-tuning for specific organizational needs. It also aligns with a growing trend in the AI community towards democratizing access to advanced models.

A key reported advantage of the Antares models is their low cost, both in terms of operational expense and potentially in acquisition or licensing. This cost efficiency is particularly relevant for organizations with budget constraints or those looking to scale their security analysis capabilities without significant investment in high-end AI infrastructure. Larger AI models often demand substantial computational resources for training and inference, leading to higher operational costs, which the Antares models aim to mitigate.

The target application for these models is source code security, a domain that encompasses static application security testing (SAST) and potentially aspects of software composition analysis (SCA). SAST tools analyze source code without executing it, looking for patterns indicative of vulnerabilities such as SQL injection, cross-site scripting (XSS), buffer overflows, and insecure cryptographic practices. The Antares models would likely integrate into development pipelines to provide continuous security feedback.

Typical mitigation guidance for issues identified by such tools involves developers reviewing the flagged code, understanding the nature of the vulnerability, and implementing corrective measures. This often includes sanitizing inputs, validating data, using secure coding patterns, and updating vulnerable third-party libraries. The effectiveness of these models depends on their accuracy in identifying true positives while minimizing false positives, which can otherwise lead to developer fatigue.

This development reflects an ongoing industry trend towards integrating AI and machine learning into cybersecurity operations to automate and enhance threat detection and vulnerability management. As software complexity continues to grow and the volume of code increases, AI-powered tools are becoming indispensable for maintaining a proactive security posture, enabling organizations to identify and remediate weaknesses earlier in the development lifecycle.

vulnerabilityai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]

breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.