Vulnerability management startup Cogent Security Inc. today introduced Cogent VR-1, a frontier reasoning model trained to find and prove attack paths inside live enterprise environments.
The company says VR-1 proved twice as many attack paths as other frontier models on IntrusionBench, a benchmark released alongside it, at roughly a quarter of the cost. The test gives an agent a foothold and a target and nothing else. Getting there means working through cloud infrastructure, identity systems and whatever internal tooling the company happens to run. Scoring is based on execution. An agent that says it could have reached the target gets no credit.
Frontier models are good at finding a bug in a codebase. Real intrusions are messier. They travel through a chain of small weaknesses that individually look like backlog noise, such as a public service with a minor flaw or an identity carrying more permission than it needs. Cogent trained VR-1 to link those together the way an attacker would, then check whether a proposed fix closes the gap or simply relocates the risk.
The benchmark is Cogent’s own work and the headline numbers come from its hardest configuration, where the agent is told nothing about the environment it lands in. The comparison set is Kimi K3, Claude Opus 4.8 and GLM-5.2. A chart released with the model shows the doubling measured against those three running on their own default harnesses. Run inside Cogent’s harness, all three land within a few percentage points of VR-1, which posted a success rate under 30% itself. As more of the environment was revealed, every model improved and the spread narrowed further.
Cogent is marketing the model as “Mythos-class,” a reference to the Anthropic PBC frontier model whose cyber capabilities set off months of argument this year. The company says fully autonomous AI attacks have since hit governments and large technology companies, and pitches VR-1 as the defensive equivalent. Cogent did not benchmark VR-1 against Mythos. The Anthropic model in its comparison set is Claude Opus 4.8.
“For two years, every security vendor has claimed to be AI-native. VR-1 lets us put a number on it,” said Vineet Edupuganti, co-founder and chief executive of Cogent. “We can show them exactly which attack paths a frontier-capable adversary could reach, then use the same model to close them. Attackers already have this capability. Our job is to make sure defenders get it first.”
Co-founder and Chief Technology Officer Geng Sng said today’s frontier models surface attack paths only as a byproduct of being good at code and reasoning, and that nobody had set out to build a model for the task.
Shipping with VR-1 is the Cogent AI Harness, a runtime that supplies environment context, scoped tools and policy enforcement to any capable model, open-weight or frontier. Every action is checked against the customer’s own policy. Cogent calls its validation principle “prove, don’t detonate,” meaning exposure is confirmed without causing damage, persistence or disruption.
The model will not be released openly. Access runs through a vetting process the company calls the Cogent Frontier Access Program, with guardrails and audit logging in place. Qualified applicants can also request a Frontier Model Risk Assessment, a readout of which attack paths a frontier-level model could reach inside their environment.
Founded in 2025 and staffed by researchers and operators from Google DeepMind, Abnormal AI Inc. and Coinbase Global Inc., Cogent sells AI agents that investigate vulnerabilities, route them to the teams that own the affected systems and verify that fixes landed. Fortune 500 customers have cut the exposure window for critical vulnerabilities by 97%, the company says. It has raised $53 million to date, including a $42 million Series A in February led by Bain Capital Ventures.
Image: Cogent Security
A message from John Furrier, co-founder of SiliconANGLE:
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
- 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
- 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
Are you AWS customer? Support SiliconANGLE Financially by buying your AWS services from our Marketplace portal page and links.
https://siliconangle.com/aws-marketplace/
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.
