Cisco 2026-07-22
Product Launch Impact: Major Conf: 85%

Cisco Launches Antares Open-Weight AI Models for Vulnerability Localization, Outperforming GPT-5.5 at 1/100 Cost

Summary

Cisco unveils Antares, an open-weight AI model series for vulnerability localization. Antares-1B beats Google Gemini 3 Pro, Antares-3B approaches GPT-5.5, yet completes 500 tasks in 15 minutes at $1 cost vs 5 hours and $100-150 for GPT-5.5, revolutionizing the economics of security scanning.

Key Takeaways

On July 22, 2026, Cisco Foundation AI released the Antares series of open-weight AI models for vulnerability localization. Models include Antares-350M and Antares-1B (open-weight on Hugging Face), and Antares-3B (Cisco internal, integrated into security products). The models search codebases, read candidate files, backtrack, and output ranked lists of most likely vulnerable files.

In the Vulnerability Localization Benchmark (500 tasks), Antares-1B beat Google Gemini 3 Pro, and Antares-3B surpassed Z.ai GLM-5.2 and approached OpenAI GPT-5.5. Speed: Antares completed 500 repos in 15 minutes vs GPT-5.5's 5 hours (20x faster). Cost: Antares at $1 vs GPT-5.5's $100-150 (100-150x cheaper).

Cisco trains the model to 'search, not chat', like a bike navigating London traffic. Open-weight enables local deployment, fitting CI/CD pipelines. Use cases include regulated industries, universities, small security teams. Cisco controls access to prevent misuse. Antares does not replace full security platforms, still requires dependency analysis, secret scanning, etc.

Why It Matters

On the surface, Cisco's Antares democratizes security AI, but it's a defensive move against Palo Alto Networks and CrowdStrike in AI security. By open-sourcing the model, Cisco aims to set a standard for vulnerability localization, funneling users into its security ecosystem (e.g., Cisco SecureX). However, Antares is limited to known CWEs, lacks zero-day detection, and may be biased toward certain programming languages. The low inference cost masks the need for Cisco's infrastructure and approval for deployment, creating vendor lock-in. While fast, the model's context window and retrieval accuracy may degrade on large codebases, where general models like GPT-5.5 still excel. The access control undermines true openness.

PRO Decision

【Vendors】Competitors like Palo Alto Networks and CrowdStrike should highlight Antares' limitations: known CWE only, language bias, and access control undermining openness. They can launch their own open models with broader detection and no vendor gatekeeping.

【Enterprises】CIOs should conduct zero-trust audits: verify Antares' performance on their codebases, especially for unknown vulnerabilities and multi-language support. Do not assume low cost translates to low total cost; consider hidden dependencies on Cisco infrastructure. Demand independent benchmarks and training data transparency.

【Investors】Recognize Cisco's pivot to AI security software, but Antares' open-source nature may commoditize vulnerability scanning, pressuring margins of pure-play security vendors. Cisco's strategy relies on integration lock-in; monitor whether it drives hardware or subscription sales.

Source: 36氪
View Original →

Get 3-5 key AI infrastructure signals weekly →

💬 Comments (0)