The open-weight Antares models are designed to pinpoint known vulnerabilities in codebases faster and at a fraction of the cost of larger AI models. The post Cisco Launches Low-Cost AI Models for Source Code Security appeared first on SecurityWeek.

Cisco has reportedly introduced a new suite of artificial intelligence models, named Antares, specifically engineered to enhance source code security by identifying known vulnerabilities. These models are described as open-weight, indicating a potential for broader accessibility and community-driven development or inspection, and are positioned as a cost-effective alternative to larger, more resource-intensive AI solutions currently available.
The Antares models are designed with a primary objective of accelerating the detection of established security flaws within software codebases. This capability is critical in modern software development lifecycles, where the rapid pace of development often necessitates automated tools to maintain security hygiene. By focusing on known vulnerabilities, the models likely leverage extensive datasets of previously identified weaknesses, common exploit patterns, and established security best practices to train their detection algorithms.
The "open-weight" designation for the Antares models suggests that Cisco may be making the model parameters and architecture publicly available, or at least accessible to a wider audience than proprietary, closed-source models. This approach can foster transparency, allow security researchers to scrutinize the models for biases or limitations, and potentially enable custom fine-tuning for specific organizational needs. It also aligns with a growing trend in the AI community towards democratizing access to advanced models.
A key reported advantage of the Antares models is their low cost, both in terms of operational expense and potentially in acquisition or licensing. This cost efficiency is particularly relevant for organizations with budget constraints or those looking to scale their security analysis capabilities without significant investment in high-end AI infrastructure. Larger AI models often demand substantial computational resources for training and inference, leading to higher operational costs, which the Antares models aim to mitigate.
The target application for these models is source code security, a domain that encompasses static application security testing (SAST) and potentially aspects of software composition analysis (SCA). SAST tools analyze source code without executing it, looking for patterns indicative of vulnerabilities such as SQL injection, cross-site scripting (XSS), buffer overflows, and insecure cryptographic practices. The Antares models would likely integrate into development pipelines to provide continuous security feedback.
Typical mitigation guidance for issues identified by such tools involves developers reviewing the flagged code, understanding the nature of the vulnerability, and implementing corrective measures. This often includes sanitizing inputs, validating data, using secure coding patterns, and updating vulnerable third-party libraries. The effectiveness of these models depends on their accuracy in identifying true positives while minimizing false positives, which can otherwise lead to developer fatigue.
This development reflects an ongoing industry trend towards integrating AI and machine learning into cybersecurity operations to automate and enhance threat detection and vulnerability management. As software complexity continues to grow and the volume of code increases, AI-powered tools are becoming indispensable for maintaining a proactive security posture, enabling organizations to identify and remediate weaknesses earlier in the development lifecycle.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.