FrontierThe story, in brief

Can an Open Model Do Security Research? Cantina’s apex-flash-1 Solves 40 of 60 Held-Out Bug Tasks

40 of 60. That's how many vulnerability-discovery tasks Cantina's open-weight apex-flash-1 solved — a reinforcement-learned model built specifically for security research, now available on Hugging Face under MIT.

Illustration of a transparent lens revealing connected networks across layers of paper.
Exploring the next frontier of AI research.AI illustration by KeyNews
The KeyNews take

Why it matters

An open-weights model fine-tuned for vulnerability research hits a meaningful capability threshold and ships deployable weights. For security teams and red teams, this trades frontier-model API access for local control and specialization; the catch is the 640 GB GPU memory requirement and unproven real-world deployment.

The key facts

12 to know
  1. apex-flash-1 is a RL fine-tune of Z.ai's GLM-5.3-Flash

  2. Solves 40 of 60 held-out vulnerability discovery tasks

  3. Released on Hugging Face under MIT license

  4. Deployable on vLLM, SGLang, or Transformers

  5. BF16 inference requires ~640 GB GPU memory

  6. Developed by Cantina Security with Yeta Labs

  7. Model: apex-flash-1, RL fine-tune of Z.ai's GLM-5.3-Flash

  8. Release: open-weights, MIT license, Hugging Face

  9. Capability: solves 40 of 60 held-out vulnerability discovery tasks

  10. Deployment: vLLM, SGLang, or Transformers; BF16 requires ~640 GB GPU memory

  11. Developer: Cantina Security with Yeta Labs

  12. Domain: vulnerability research and security

The story so far

Earlier coverage of this storyline

  1. Aikido Security Releases Altar-1: An Open-Weight Security Model Pruned From GLM-5.3 to 328 GBMarkTechPost
  2. 2026 in LLMs (so far)Simon Willison
  3. This story

Go to the source

MarkTechPostmarktechpost.com

Publisher excerpt: Cantina Security, with Yeta Labs, has released apex-flash-1, an open-weights model trained specifically for vulnerability research. It is a reinforcement learning fine-tune of Z.ai’s GLM-5.3-Flash, released on Hugging Face under the MIT license. Is it deployable? Yes, the MIT weights serve on vLLM,…
Read original report
Back to today's editionMore frontier news

Keep reading

Related stories

More from Frontier