An open-weights security model trained on real, paid-out vulnerabilities is out
First seen on X 3 days ago@cantinasecurity ♥ 1,439
Security firm Cantina, with Yeta Labs, released apex-flash-1 as an open-weights model. It is a reinforcement-learning post-train of GLM-5.3-Flash built for focused investigations: reading code, using tools, pursuing an exploit and verifying its effect on a running target. It was trained on 150 tasks drawn from 50 vulnerabilities that Cantina found and was paid for, 72% of them involving authorization, identity or scope.
It solved 66.7% of a 60-task holdout at about $2.38 per run. Cantina also released a variant with fewer refusals, arguing that locking cyber capabilities inside closed models mostly handcuffs corporate defenders rather than attackers.