Cisco releases open-weight models for security vulnerability detection

Cisco's open-weight security models offer enterprises an alternative to proprietary tools from Google and OpenAI for finding software vulnerabilities.

Abstract illustration of layered security analysis
AI-generated illustration · Sylvaris

Specialized security models

Cisco released open-weight AI models designed specifically for identifying security vulnerabilities in software code. The models compete directly with offerings from Google and OpenAI in the code security space.

Unlike general-purpose coding assistants, these models focus exclusively on vulnerability detection and security analysis. The open-weight approach allows enterprises to deploy the models on their own infrastructure without sending code to external services.

Enterprise deployment options

The open-weight designation means the model weights are publicly available, but the training data and process remain proprietary. This gives organizations the ability to run the models locally while maintaining code confidentiality.

Cisco positions these tools as alternatives to cloud-based security scanning services. Organizations concerned about sending proprietary code to third-party APIs can now perform vulnerability analysis on premises.

Competitive landscape

Google recently launched Gemini Cyber variants focused on security tasks, while OpenAI offers security-focused features through ChatGPT Enterprise. Cisco's entry adds a third major option for organizations seeking AI-powered vulnerability detection.

The competition reflects growing enterprise demand for automated security tooling. Code analysis remains a time-intensive task that AI models can accelerate, though human review remains necessary for validation.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.