Cantina unveils open‑weight model for vulnerability research
Open‑Weight Model for Security Research
Cantina announced the release of apex‑flash‑1, an open‑weights model fine‑tuned for cybersecurity tasks.
The model is a reinforcement‑learning fine‑tune of GLM‑5.3‑Flash and contains 321 billion parameters.
Apex‑flash‑1 is hosted on Hugging Face and can be downloaded by anyone interested in security‑oriented AI.
Cantina recommends running the model through an agent harness such as Codex, rather than offering its own hosted endpoint.
In a reply on X, co‑founder Harikrishnan “Hari” Mulackal said “the company does not yet offer hosted, token‑priced access.”
The announcement was made in an October 4 post that also included a short video demonstration posted on X.
Mulackal provided a link to the original X status: https://x.com/hrkrshnn/status/2106545457027793177.
Performance and Cost Claims
Cantina’s model card reports that apex‑flash‑1 completed 40 of 60 evaluation tasks, a 66.7 % pass rate.
For comparison, Claude Opus 5 High achieved 43 of 60 tasks, while the untuned GLM‑5.3‑Flash solved 36 of 60.
Cantina estimated the cost of evaluating the 60 tasks at $2.38 for apex‑flash‑1, $74.68 for Claude, and $4.56 for the base GLM model.
These figures are based on Cantina’s internal calculations and a small, company‑designed test set.
The evaluation used isolated environments and verifiers that checked the final state of each target after an exploit attempt.
Cantina recommends Codex as the harness for running apex‑flash‑1 in production‑like software and protocol environments.
While the pass rate suggests the model can read code, use tools, and verify exploit effects, the results have not been validated by an independent benchmark.
Business Context and Future Outlook
Mulackal frames security work as an economics problem, arguing that organizations must identify and verify more vulnerabilities while reducing per‑investigation costs.
He notes that Cantina has earned $1 million in bug bounties and leads HackerOne’s US business leaderboard for 2026.
These performance claims are self‑reported and have not been independently audited.
Cantina processes trillions of tokens each month through its security harnesses, though the company provides no breakdown of cost, customer base, or outcomes.
The open‑weight release allows external developers to inspect the model directly, shifting inference cost to whoever runs the model.
Cantina’s broader thesis remains to own the full stack, including evaluations, real‑world security data, agent harnesses, and post‑training inference.
Mulackal criticizes public cyber‑security benchmarks as poor proxies for actual customer work, claiming that known‑vulnerability datasets diverge from flaws in everyday applications.
Instead, Cantina built its own evaluation suite around offensive and defensive tasks it believes are closer to real‑world client needs.
This internal focus may provide more relevant metrics for the company, but it also limits the ability of outsiders to compare its claims against industry standards.
The release of apex‑flash‑1 therefore represents both a technical contribution to the security‑AI community and a strategic bet that a specialized, open‑weight model can deliver cost‑effective vulnerability research.
Why This Matters: By making a large, security‑focused model openly available, Cantina enables researchers to test a lower‑cost alternative to hosted general‑purpose models for vulnerability discovery.This digest was compiled from:
Share this digest
People Also Read
- OpenAI confirms GPT‑6.1 Sol Ultrafast will arrive soon, but pricing and date remain unclear
OpenAI confirms its GPT‑6.1 Sol Ultrafast speed tier is imminent but provides no price or exact launch date.
- Cotool builds configurable AI agents to automate repetitive security investigations
Cotool builds configurable AI agents to automate repetitive security investigations, letting teams reuse analyst expertise while retaining control and auditability.
- TUT Forum Urges Immediate AI Rollout Amid 62.8% Youth Joblessness
South Africa’s youth unemployment crisis spurs TUT’s Institute for the Future of Work to demand swift AI implementation and coordinated skills development.
Share your thoughts
Reactions, corrections, or insights — all welcome.
