AI news ·
Cantina Security and Yeta Labs release apex-flash-1, an open-weights model for security research
Cantina Security released apex-flash-1, an open-weights AI model fine-tuned on 50 real vulnerabilities that scored 66.7% on unseen exploits at $2.38 per run versus Claude Opus 5 High's 71.7% at $74.68.

Cantina Security and Yeta Labs released apex-flash-1 today, an open-weights AI model fine-tuned on real, disclosed vulnerabilities. The release directly challenges the industry assumption that restricting AI cyber capabilities through proprietary models keeps attackers at bay, arguing instead that these restrictions primarily handcuff corporate defenders.
"Attackers do not respect acceptable-use policies, enterprise procurement rules, data residency requirements, or third-party risk controls," the researchers said. "They can run open models locally, modify them, remove safeguards, and build systems around capabilities that already exist. Defenders are the ones operating under the strictest constraints, and that creates an asymmetric form of safety."
The model, built on GLM-5.3-Flash, was trained using GRPO reinforcement learning on 150 tasks derived from 50 real vulnerability cases. The team also released an "abliterated" variant for researchers who want full control over the model's behavior in their own security workflows.
How the training environments were built
The training data pipeline started with vulnerabilities the team discovered through reviews, scans, and investigations of software and protocols. Each finding was then reconstructed inside a production-like Docker Compose environment-complete with an application, database, workers, and storage-seeded with realistic synthetic data. The team introduced the validated bug, tuned the exploit difficulty, and let the agent investigate.
Tasks were split across three difficulty views. Guided whitebox gave the agent full source code and detailed vulnerability guidance. Focused whitebox provided source code but only limited direction toward a subsystem. Focused blackbox offered no source code, only limited direction and access to the running target. The agent still had to execute a working exploit in every case.
The vulnerability mix skewed heavily toward authorization failures. Authorization, identity, and scope binding bugs made up 72% of the training cases. Accounting and numerical precision flaws accounted for 18%, with time validation, business logic, and SSRF bugs filling the remainder.
Calibrating difficulty for smaller models
The team designed apex-flash-1 as a worker model meant to be orchestrated by a larger system that assigns it focused security tasks. Training a smaller model on challenges it almost never solves provides little useful GRPO signal, so difficulty was calibrated to the model's current capability while preserving the investigation and exploit work.
This constraint shaped the training method. The team used rank-256 LoRA across all experts and routers, combined with full-parameter updates to 16 experts selected by activation. Updating all parameters across all experts caused the model to collapse. "We suspect the small RL dataset led to misattributed gradients in experts not suited to the agentic workload," the researchers said.
Task prompt wording proved critical. Naming a function or pointing to a subsystem could dramatically change solve rates. The team built an independent verifier outside the agent sandbox that checked whether the objective was met through the intended route, assigning a binary success or failure reward. Cases where passing trajectories bypassed the target bug were flagged, repaired, and rechecked.
Performance and cost against frontier models
On a held-out evaluation of 60 unseen tasks, apex-flash-1 achieved a 66.7% pass rate (40 of 60 tasks) at an estimated run cost of $2.38. The base GLM-5.3-Flash model scored 60.0% (36 tasks) at $4.56. Claude Opus 5 High scored 71.7% (43 tasks) at $74.68.
The cost gap is central to the team's argument. "That balance of performance and cost matters if we want capable security agents to become cheap enough to scale to every company, not just the few that can afford frontier-model economics," they said. The model is the first in a series the team has post-trained, ranging from roughly 27B parameters up to 1T, that they believe moves the Pareto frontier for real-world cyber tasks.
For professionals working in cybersecurity, building these skills with AI-driven tools is becoming essential. Courses in AI Security Analytics can help analysts understand how models like apex-flash-1 fit into defensive workflows.
Why this matters for legal professionals
The release of open-weights security models trained on real vulnerabilities raises immediate questions about dual-use technology governance. If a model can find and exploit authorization flaws in production systems, legal teams must assess whether existing acceptable-use policies, software licensing terms, and procurement contracts adequately address the risk-or whether they create liability by restricting defensive teams while offering no barrier to attackers.
The researchers frame this as a replay of the vulnerability disclosure debates from the late 1990s. Tools like Nmap and Metasploit were once controversial. They became infrastructure. The legal question now is whether restricting access to AI security models through API policies and usage restrictions constitutes reasonable risk management, or whether it creates a paper shield that exposes companies to liability when attackers use the same capabilities without constraint.