What happened
Cisco Foundation AI released (July 21-22, 2026) Antares-350M and Antares-1B, open-weight small language models on Hugging Face that pinpoint which source files in a large codebase likely contain a known vulnerability given a CWE/advisory description, running locally without sending code to the cloud; Cisco also introduced the VLoc Bench evaluation set and claims Antares outperforms larger closed/open models at a fraction of the cost (500 repos in 15 min for <$1 vs. hours/$100+ for frontier models).
Why it matters
A credible OSS release demonstrating specialized small models can beat frontier LLMs on a concrete security-triage task while preserving code confidentiality — relevant to AppSec teams under compute/privacy constraints and a counter to frontier-model-arms-race narrative.
Applicability
AppSec/vulnerability-management teams, especially regulated or resource-constrained orgs (public sector, universities), should evaluate Antares for on-prem triage pipelines.