{"id":49757,"date":"2026-07-23T14:36:19","date_gmt":"2026-07-23T12:36:19","guid":{"rendered":"https:\/\/www.cloudmagazin.com\/2026\/07\/23\/antares-open-weight-slms-find-cve-files\/"},"modified":"2026-07-23T14:47:33","modified_gmt":"2026-07-23T12:47:33","slug":"antares-open-weight-slms-find-cve-files","status":"publish","type":"post","link":"https:\/\/www.cloudmagazin.com\/en\/2026\/07\/23\/antares-open-weight-slms-find-cve-files\/","title":{"rendered":"Antares: Open-Weight SLMs Find CVE Files"},"content":{"rendered":"<p><strong>Cisco Foundation AI introduces two open-weight Security-SLMs, tackling a tight, costly task: Vulnerability Localization. From advisory and codebase, they aim to identify the likely source files-locally, small enough for your own GPU setup and measurable against a new 500-Task-Benchmark.<\/strong><\/p>\n<h2>Key Takeaways<\/h2>\n<div style=\"background:#f8fbfd;border:1px solid rgba(11,183,253,0.28);border-radius:8px;padding:22px 26px;margin:16px 0 34px;box-shadow:0 1px 0 rgba(11,183,253,0.08),0 2px 8px rgba(0,0,0,0.03);\">\n<ul style=\"margin:0;padding-left:20px;line-height:1.75;color:#1a2733;\">\n<li style=\"margin-bottom:10px;\"><strong>Task instead of General-purpose LLM.<\/strong> Antares-350M and Antares-1B locate known vulnerabilities in the repository. They do not patch and do not replace SAST or SCA.<\/li>\n<li style=\"margin-bottom:10px;\"><strong>Open-weight, Apache 2.0, locally.<\/strong> Weights on Hugging Face (fdtn-ai\/antares). Code must not go to the cloud &#8211; relevant for regulated pipelines and Air-Gapped teams.<\/li>\n<li><strong>Own metric: VLoc Bench.<\/strong> 500 agent-based tasks. Antares-1B achieves File F1 0.209 and, according to the Model Card, clearly outperforms much larger models; 500 tasks in about 13 minutes on an H100.<\/li>\n<\/ul>\n<\/div>\n<p style=\"margin:28px 0 8px;\"><span style=\"display:inline-block;background:#e8f7fc;color:#004a59;padding:4px 10px;border-radius:4px;font-weight:700;text-transform:uppercase;font-size:0.72em;letter-spacing:0.14em;margin-right:14px;\">Related:<\/span><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/07\/21\/hugging-face-hacked-the-breach-started-with-a-dataset-loader\/\" style=\"color:#333;text-decoration:underline;\">Hugging Face hacked: The entry was a dataset loader<\/a>&nbsp;&nbsp;<span style=\"color:#ccc;\">\/<\/span>&nbsp;&nbsp;<a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/07\/22\/nginx-vulnerability-ingress-and-gateway-compelled-to-patch\/\" style=\"color:#333;text-decoration:underline;\">NGINX vulnerability: Ingress and gateway under patch pressure<\/a><\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Why Localization Is the Expensive Part<\/h2>\n<p>The advisory is out, the CVE is clear &#8211; and then the costly work begins: Finding the files in a foreign or grown repository where the vulnerability lies. Analysts navigate naming conventions, call\u2011paths and candidate lists. Static analysis helps, but often produces noise. General\u2011purpose coding models can read code, but they are not optimized for security triage or terminal navigation in large code trees.<\/p>\n<p>Antares precisely addresses this middle ground. Cisco describes the models as security SLMs that iterate like a human investigator: starting from a vulnerability description, searching, reading files, switching strategies, backing up, narrowing down. The result is a ranked list of likely source files plus an exploration trace. This is material for the reviewer and remains deliberately under expert control.<\/p>\n<p>For cloud and platform teams, this is the difference between \u201cwe have an LLM in the chat\u201d and \u201cwe have a gate in the pipeline that shortens the costly first hour of triage.\u201d Localization sits before the patch. Whoever saves time and tokens here can scale advisory waves and agent\u2011generated code more effectively.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Antares-350M and 1B: Small, Specialized, Measurable<\/h2>\n<p>Live are two open-weight models: Antares-350M and Antares-1B, licensed under Apache 2.0 on Hugging Face. Antares-3B is announced. The base is IBM Granite 4.0 with a two-stage training pipeline. The Model Card for Antares-1B cites File F1 0.209 on the Vulnerability Localization Benchmark and lists comparisons with much larger systems &#8211; including GLM-5.2, Gemini 3 Pro, GPT-5 Mini and Qwen3.5-122B. The full 500-Task sweep runs in the evaluation setup in about 13 minutes on an H100 with 16 parallel workers.<\/p>\n<p>Industry reports dissect the cost side: Help Net Security and SecurityWeek cite order\u2011of\u2011magnitude savings of up to 172\u00d7 cheaper than GPT-5.5 and roughly 15\u00d7 cheaper than GLM-5.2 on the same benchmark. Cisco itself stresses in its blog \u201cfraction of the cost\u201d and shows in Figure 2 markedly lower estimated costs and runtimes. For editorial framing the direction is clear &#8211; a specialized SLM beats a frontier all\u2011rounder on this single task. Always verify multipliers against the Model Card and paper before they enter the budget deck.<\/p>\n<p>Amin Karbasi, VP and Chief AI Scientist at Cisco Foundation AI, frames the release thus: The security community needs accessible building blocks for repository\u2011level defense. That\u2019s exactly why it\u2019s open\u2011weight and small enough for local inference.<\/p>\n<div style=\"background:#004a59;border:1px solid rgba(11,183,253,0.4);border-radius:10px;padding:34px 26px;margin:36px 0;text-align:center;box-shadow:0 0 24px rgba(11,183,253,0.08);\">\n<div style=\"font-family:'SF Mono','Monaco','Consolas',monospace;font-size:11px;color:#0bb7fd;letter-spacing:0.14em;text-transform:uppercase;margin-bottom:10px;\">\/\/ Metric<\/div>\n<div style=\"font-size:48px;font-weight:700;color:#fff;letter-spacing:-0.03em;line-height:1;\">500 Tasks<\/div>\n<div style=\"font-size:14px;color:rgba(255,255,255,0.85);margin:12px auto 0;max-width:460px;line-height:1.5;\">VLoc Bench: agentic Vulnerability-Localization across unknown codebases and CWE patterns &#8211; the metric against which Antares is measured.<\/div>\n<div style=\"font-size:12px;color:#0bb7fd;margin-top:12px;\">\/\/ Source: Cisco Foundation AI \/ VLoc Bench, July 2026<\/div>\n<\/div>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">VLoc Bench: why SWE-Bench isn\u2019t enough here<\/h2>\n<p>Cisco didn\u2019t build the benchmark out of mere marketing enthusiasm. General coding benchmarks such as SWE-Bench (Software Engineering Benchmark) measure issue resolution and patch finding-not whether an agent, using a Common Weakness Enumeration (CWE) description or advisory, identifies vulnerable files. CodeScout gets closer (terminal agents, code search), but it targets software\u2011engineering tasks rather than security localization.<\/p>\n<p>VLoc Bench demands both simultaneous navigation through foreign repositories and detection of vulnerability patterns for specific Common Weakness Enumeration (CWE) categories. 500 tasks, agentic. This is the benchmark against which Cisco Antares pits itself against larger closed\u2011 and open\u2011weight models-and the lever that enables teams to compare their own harnesses.<\/p>\n<p>Practically, this means for Application Security (AppSec) and Platform Engineering: when you introduce Antares or a competitor, you measure localization quality and cost per advisory-not chat Elo. Without this intersection, \u201cAI in security tooling\u201d remains just a demo slide.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Running locally: Data residency as a feature<\/h2>\n<p>The cloud angle isn\u2019t a clich\u00e9 here. Many security teams aren\u2019t permitted to ship proprietary code to external inference APIs. Compact open\u2011weight models that run on\u2011prem or within their own VPC shift the release dynamics: advisory triage and CI checks stay behind the organization\u2019s trust boundary.<\/p>\n<p>Cisco explicitly targets Antares at universities, public\u2011sector bodies and smaller teams that can\u2019t afford frontier token budgets. Voices from academia in the blog (NUS, Stanford) stress the same point: security shouldn\u2019t be a luxury good and small models are fast enough to gate agent output before merging.<\/p>\n<p>Boundaries stay strict: Antares doesn\u2019t replace dependency scanning or secret detection, DAST, container checks or threat modeling. It narrows the costly file\u2011search. The human and the rest of the toolchain remain in the loop &#8211; that\u2019s how Cisco describes it.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">What Cloud and Platform Teams Should Verify Now<\/h2>\n<p>If you take Antares seriously, you build a measurable slot in the pipeline:<\/p>\n<ul style=\"line-height:1.75;color:#1a2733;\">\n<li style=\"margin-bottom:8px;\"><strong>Use-Case trimming:<\/strong> Only Localization (Advisory \u2192 File-Rank). No mixing of expectations with auto-remediation.<\/li>\n<li style=\"margin-bottom:8px;\"><strong>Deployment location:<\/strong> On-prem \/ private GPU vs. Managed Endpoint. Compliance and code residency take precedence over accuracy debates.<\/li>\n<li style=\"margin-bottom:8px;\"><strong>CI gate design:<\/strong> For high-severity advisory files ranked, use them as a review queue, store traces, enforce human-in-the-loop.<\/li>\n<li style=\"margin-bottom:8px;\"><strong>Internal benchmark:<\/strong> 20-50 of our own historical CVEs as a gold set. File F1 and time\/cost against status quo (manual + SAST).<\/li>\n<li style=\"margin-bottom:8px;\"><strong>Supply chain of weights:<\/strong> Verify HF (Hugging Face) models (signatures, hashes, internal mirrors). The HF (Hugging Face) dataset loader incident shows: pipeline inputs are an attack surface.<\/li>\n<\/ul>\n<p>Similarly, it pays to look at Cisco&#8217;s broader package: Foundry Security Spec (Harness and Guardrails for agentic Security), CodeGuard (Secure-Coding rules for coding agents) and the open VLoc-Benchmark. Antares is the Localization building block &#8211; not the whole lock.<\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<details>\n<summary><strong>What exactly is Antares?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">A family of security SLMs from the Cisco Foundation AI for vulnerability localization: given vulnerability description and codebase, output ranked source files plus exploration trace. Open-weight currently: 350M and 1B (Apache 2.0), 3B announced.<\/p>\n<\/details>\n<details>\n<summary><strong>Does Antares replace Static Application Security Testing (SAST) or Software Composition Analysis (SCA)?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">No. Cisco positions it as accelerating costly file triage. Dependency analyses, secret scanning, DAST and expert review remain necessary.<\/p>\n<\/details>\n<details>\n<summary><strong>Why open-weight and small?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Local inference keeps code within your own environment, lowering costs and making it realistic for teams without frontier-budget resources. Specialization on localization should still deliver strong performance even with a small number of parameters.<\/p>\n<\/details>\n<details>\n<summary><strong>What does VLoc Bench measure?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">500 agentic tasks: models navigate unknown repositories and should find files that match CWE-\/Vulnerability-Patterns. This is tighter and more security-specific than SWE-Bench.<\/p>\n<\/details>\n<details>\n<summary><strong>Where are the models?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">On Hugging Face under the collection fdtn-ai\/antares (e.g., antares-350m, antares-1b). The benchmark and paper are linked via Cisco Foundation AI.<\/p>\n<\/details>\n<h2>Editor&#8217;s Picks<\/h2>\n<ul style=\"list-style:none;margin:0 0 8px;padding:0;\">\n<li style=\"padding:10px 0;border-bottom:1px solid #eee;\"><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/07\/21\/hugging-face-hacked-the-breach-started-with-a-dataset-loader\/\" style=\"color:#1a1a1a;text-decoration:none;\">Hugging Face hacked: The entry was a dataset loader<\/a><\/li>\n<li style=\"padding:10px 0;border-bottom:1px solid #eee;\"><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/07\/18\/the-cheap-model-that-is-hampering-ai-development\/\" style=\"color:#1a1a1a;text-decoration:none;\">The cheap model that holds back AI development<\/a><\/li>\n<li style=\"padding:10px 0;\"><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/07\/22\/nginx-vulnerability-ingress-and-gateway-compelled-to-patch\/\" style=\"color:#1a1a1a;text-decoration:none;\">NGINX flaw: Ingress and gateway under patch compulsion<\/a><\/li>\n<\/ul>\n<div style=\"margin:40px 0 24px 0;\">\n<p style=\"margin:44px 0 12px;font-size:0.72em;font-weight:700;text-transform:uppercase;letter-spacing:0.18em;color:#666;\">More from the MBF Media Network<\/p>\n<div style=\"padding:14px 18px;border-left:3px solid #202528;background:#fafafa;margin-bottom:6px;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#202528;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">mybusinessfuture<\/div>\n<p><a href=\"https:\/\/mybusinessfuture.com\/bechtle-docs-kreditworkflow-posteingang-banken\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">When the credit workflow gets stuck at the inbox<\/a>\n<\/div>\n<div style=\"padding:14px 18px;border-left:3px solid #d65663;background:#fafafa;margin-bottom:6px;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#d65663;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">digital-chiefs<\/div>\n<p><a href=\"https:\/\/www.digital-chiefs.de\/verwaiste-zugaenge-die-stille-cyber-luecke\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">Abandoned access: the silent cyber gap<\/a>\n<\/div>\n<div style=\"padding:14px 18px;border-left:3px solid #69d8ed;background:#fafafa;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#69d8ed;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">securitytoday<\/div>\n<p><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/07\/22\/mitre-edr-test-100-prozent-kein-freifahrtschein\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">MITRE-EDR Test: 100 percent is no free ride<\/a>\n<\/div>\n<\/div>\n<p style=\"text-align:right;color:#868e96;font-size:0.75em;margin-top:40px;\"><em>Image source: AI-generated (July 2026)<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"Antares 350M\/1B: open-weight SLMs locate CVE files in the repo. Local, Apache 2.0, VLoc Bench &#8211; file-triage without cloud obligation.","protected":false},"author":31,"featured_media":49735,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/07\/cisco-antares-open-weight-vulnerability-localization-cover-hero-1.jpg","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/07\/cisco-antares-open-weight-vulnerability-localization-cover-hero-1.jpg","_yoast_wpseo_twitter-image-id":0,"pre_headline":"","bildquelle":"","teasertext":"","language":"de","_evm_translation_lang":"en","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[924,921],"tags":[],"industry":[],"class_list":["post-49757","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-artificial-intelligence","category-news"],"evm_reading_time_minutes":7,"wpml_language":"en","wpml_translation_of":49694,"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.9 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Antares: Open-Weight SLMs Find CVE Files - cloudmagazin<\/title>\n<meta name=\"description\" content=\"Cisco Antares 350M\/1B: open-weight Security SLMs for vulnerability localization. VLoc Bench 500 Tasks, local, Apache 2.0 - what cloud teams check.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/07\/23\/antares-open-weight-slms-find-cve-files\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Antares: Open-Weight SLMs Find CVE Files - cloudmagazin\" \/>\n<meta property=\"og:description\" content=\"Cisco Antares 350M\/1B: open-weight Security SLMs for vulnerability localization. VLoc Bench 500 Tasks, local, Apache 2.0 - what cloud teams check.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.cloudmagazin.com\/en\/2026\/07\/23\/antares-open-weight-slms-find-cve-files\/\" \/>\n<meta property=\"og:site_name\" content=\"cloudmagazin\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/cloudmagazincom\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-23T12:36:19+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-23T12:47:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/07\/cisco-antares-open-weight-vulnerability-localization-cover-hero-1.jpg\" \/>\n<meta name=\"author\" content=\"Alec Chizhik\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/07\/cisco-antares-open-weight-vulnerability-localization-cover-hero-1.jpg\" \/>\n<meta name=\"twitter:creator\" content=\"@cloudmagazin\" \/>\n<meta name=\"twitter:site\" content=\"@cloudmagazin\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alec Chizhik\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"NewsArticle\",\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/2026\\\/07\\\/23\\\/antares-open-weight-slms-find-cve-files\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/2026\\\/07\\\/23\\\/antares-open-weight-slms-find-cve-files\\\/\"},\"author\":{\"name\":\"Alec Chizhik\",\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/#\\\/schema\\\/person\\\/ce38baaa19a580268aedce096597eb3c\"},\"headline\":\"Antares: Open-Weight SLMs Find CVE Files\",\"datePublished\":\"2026-07-23T12:36:19+00:00\",\"dateModified\":\"2026-07-23T12:47:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/2026\\\/07\\\/23\\\/antares-open-weight-slms-find-cve-files\\\/\"},\"wordCount\":1265,\"publisher\":{\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/2026\\\/07\\\/23\\\/antares-open-weight-slms-find-cve-files\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.cloudmagazin.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/cisco-antares-open-weight-vulnerability-localization-cover-hero-1.jpg\",\"articleSection\":[\"Artificial Intelligence\",\"News\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/2026\\\/07\\\/23\\\/antares-open-weight-slms-find-cve-files\\\/\",\"url\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/2026\\\/07\\\/23\\\/antares-open-weight-slms-find-cve-files\\\/\",\"name\":\"Antares: Open-Weight SLMs Find CVE Files - cloudmagazin\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/2026\\\/07\\\/23\\\/antares-open-weight-slms-find-cve-files\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/2026\\\/07\\\/23\\\/antares-open-weight-slms-find-cve-files\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.cloudmagazin.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/cisco-antares-open-weight-vulnerability-localization-cover-hero-1.jpg\",\"datePublished\":\"2026-07-23T12:36:19+00:00\",\"dateModified\":\"2026-07-23T12:47:33+00:00\",\"description\":\"Cisco Antares 350M\\\/1B: open-weight Security SLMs for vulnerability localization. VLoc Bench 500 Tasks, local, Apache 2.0 - what cloud teams check.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/2026\\\/07\\\/23\\\/antares-open-weight-slms-find-cve-files\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/2026\\\/07\\\/23\\\/antares-open-weight-slms-find-cve-files\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/2026\\\/07\\\/23\\\/antares-open-weight-slms-find-cve-files\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.cloudmagazin.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/cisco-antares-open-weight-vulnerability-localization-cover-hero-1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.cloudmagazin.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/cisco-antares-open-weight-vulnerability-localization-cover-hero-1.jpg\",\"width\":1792,\"height\":1024,\"caption\":\"GENAU EINE ikonische Objekt-Metapher: ein schlankes lokales Sicherheits-Prisma aus Cyan und Dunkel-Tinte, das einen Code-Repo-Stapel durchle\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/2026\\\/07\\\/23\\\/antares-open-weight-slms-find-cve-files\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/home\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Antares: Open-Weight SLMs Find CVE Files\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/\",\"name\":\"cloudmagazin\",\"description\":\"Inspiration f\u00fcr Businessentscheider\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/#organization\",\"name\":\"cloudmagazin\",\"url\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.cloudmagazin.com\\\/wp-content\\\/uploads\\\/2020\\\/04\\\/cloudmagazin-logo-klein_menu.jpg\",\"contentUrl\":\"https:\\\/\\\/www.cloudmagazin.com\\\/wp-content\\\/uploads\\\/2020\\\/04\\\/cloudmagazin-logo-klein_menu.jpg\",\"width\":150,\"height\":150,\"caption\":\"cloudmagazin\"},\"image\":{\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/cloudmagazincom\\\/\",\"https:\\\/\\\/x.com\\\/cloudmagazin\",\"https:\\\/\\\/www.linkedin.com\\\/showcase\\\/cloudmagazin\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/#\\\/schema\\\/person\\\/ce38baaa19a580268aedce096597eb3c\",\"name\":\"Alec Chizhik\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/alec-chizhik.jpg\",\"url\":\"https:\\\/\\\/www.cloudmagazin.com\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/alec-chizhik.jpg\",\"contentUrl\":\"https:\\\/\\\/www.cloudmagazin.com\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/alec-chizhik.jpg\",\"caption\":\"Alec Chizhik\"},\"description\":\"Alec is the Chief Digital Officer at Evernine and writes about cloud architectures, IT security, and digital operations practices.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/alecchizhik\\\/\"],\"url\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/author\\\/alec\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Antares: Open-Weight SLMs Find CVE Files - cloudmagazin","description":"Cisco Antares 350M\/1B: open-weight Security SLMs for vulnerability localization. VLoc Bench 500 Tasks, local, Apache 2.0 - what cloud teams check.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.cloudmagazin.com\/en\/2026\/07\/23\/antares-open-weight-slms-find-cve-files\/","og_locale":"en_US","og_type":"article","og_title":"Antares: Open-Weight SLMs Find CVE Files - cloudmagazin","og_description":"Cisco Antares 350M\/1B: open-weight Security SLMs for vulnerability localization. VLoc Bench 500 Tasks, local, Apache 2.0 - what cloud teams check.","og_url":"https:\/\/www.cloudmagazin.com\/en\/2026\/07\/23\/antares-open-weight-slms-find-cve-files\/","og_site_name":"cloudmagazin","article_publisher":"https:\/\/www.facebook.com\/cloudmagazincom\/","article_published_time":"2026-07-23T12:36:19+00:00","article_modified_time":"2026-07-23T12:47:33+00:00","og_image":[{"url":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/07\/cisco-antares-open-weight-vulnerability-localization-cover-hero-1.jpg","type":"","width":"","height":""}],"author":"Alec Chizhik","twitter_card":"summary_large_image","twitter_image":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/07\/cisco-antares-open-weight-vulnerability-localization-cover-hero-1.jpg","twitter_creator":"@cloudmagazin","twitter_site":"@cloudmagazin","twitter_misc":{"Written by":"Alec Chizhik","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/07\/23\/antares-open-weight-slms-find-cve-files\/#article","isPartOf":{"@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/07\/23\/antares-open-weight-slms-find-cve-files\/"},"author":{"name":"Alec Chizhik","@id":"https:\/\/www.cloudmagazin.com\/en\/#\/schema\/person\/ce38baaa19a580268aedce096597eb3c"},"headline":"Antares: Open-Weight SLMs Find CVE Files","datePublished":"2026-07-23T12:36:19+00:00","dateModified":"2026-07-23T12:47:33+00:00","mainEntityOfPage":{"@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/07\/23\/antares-open-weight-slms-find-cve-files\/"},"wordCount":1265,"publisher":{"@id":"https:\/\/www.cloudmagazin.com\/en\/#organization"},"image":{"@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/07\/23\/antares-open-weight-slms-find-cve-files\/#primaryimage"},"thumbnailUrl":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/07\/cisco-antares-open-weight-vulnerability-localization-cover-hero-1.jpg","articleSection":["Artificial Intelligence","News"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/07\/23\/antares-open-weight-slms-find-cve-files\/","url":"https:\/\/www.cloudmagazin.com\/en\/2026\/07\/23\/antares-open-weight-slms-find-cve-files\/","name":"Antares: Open-Weight SLMs Find CVE Files - cloudmagazin","isPartOf":{"@id":"https:\/\/www.cloudmagazin.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/07\/23\/antares-open-weight-slms-find-cve-files\/#primaryimage"},"image":{"@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/07\/23\/antares-open-weight-slms-find-cve-files\/#primaryimage"},"thumbnailUrl":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/07\/cisco-antares-open-weight-vulnerability-localization-cover-hero-1.jpg","datePublished":"2026-07-23T12:36:19+00:00","dateModified":"2026-07-23T12:47:33+00:00","description":"Cisco Antares 350M\/1B: open-weight Security SLMs for vulnerability localization. VLoc Bench 500 Tasks, local, Apache 2.0 - what cloud teams check.","breadcrumb":{"@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/07\/23\/antares-open-weight-slms-find-cve-files\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.cloudmagazin.com\/en\/2026\/07\/23\/antares-open-weight-slms-find-cve-files\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/07\/23\/antares-open-weight-slms-find-cve-files\/#primaryimage","url":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/07\/cisco-antares-open-weight-vulnerability-localization-cover-hero-1.jpg","contentUrl":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/07\/cisco-antares-open-weight-vulnerability-localization-cover-hero-1.jpg","width":1792,"height":1024,"caption":"GENAU EINE ikonische Objekt-Metapher: ein schlankes lokales Sicherheits-Prisma aus Cyan und Dunkel-Tinte, das einen Code-Repo-Stapel durchle"},{"@type":"BreadcrumbList","@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/07\/23\/antares-open-weight-slms-find-cve-files\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.cloudmagazin.com\/en\/home\/"},{"@type":"ListItem","position":2,"name":"Antares: Open-Weight SLMs Find CVE Files"}]},{"@type":"WebSite","@id":"https:\/\/www.cloudmagazin.com\/en\/#website","url":"https:\/\/www.cloudmagazin.com\/en\/","name":"cloudmagazin","description":"Inspiration f\u00fcr Businessentscheider","publisher":{"@id":"https:\/\/www.cloudmagazin.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.cloudmagazin.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.cloudmagazin.com\/en\/#organization","name":"cloudmagazin","url":"https:\/\/www.cloudmagazin.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cloudmagazin.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2020\/04\/cloudmagazin-logo-klein_menu.jpg","contentUrl":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2020\/04\/cloudmagazin-logo-klein_menu.jpg","width":150,"height":150,"caption":"cloudmagazin"},"image":{"@id":"https:\/\/www.cloudmagazin.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/cloudmagazincom\/","https:\/\/x.com\/cloudmagazin","https:\/\/www.linkedin.com\/showcase\/cloudmagazin\/"]},{"@type":"Person","@id":"https:\/\/www.cloudmagazin.com\/en\/#\/schema\/person\/ce38baaa19a580268aedce096597eb3c","name":"Alec Chizhik","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/03\/alec-chizhik.jpg","url":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/03\/alec-chizhik.jpg","contentUrl":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/03\/alec-chizhik.jpg","caption":"Alec Chizhik"},"description":"Alec is the Chief Digital Officer at Evernine and writes about cloud architectures, IT security, and digital operations practices.","sameAs":["https:\/\/www.linkedin.com\/in\/alecchizhik\/"],"url":"https:\/\/www.cloudmagazin.com\/en\/author\/alec\/"}]}},"_links":{"self":[{"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/posts\/49757","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/users\/31"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/comments?post=49757"}],"version-history":[{"count":1,"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/posts\/49757\/revisions"}],"predecessor-version":[{"id":49759,"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/posts\/49757\/revisions\/49759"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/media\/49735"}],"wp:attachment":[{"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/media?parent=49757"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/categories?post=49757"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/tags?post=49757"},{"taxonomy":"industry","embeddable":true,"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/industry?post=49757"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}