Cogent AI Team Releases VR-1: A Frontier Cyber Reasoning Model That Composes and Verifies Enterprise Attack Paths
MarkTechPost Michal Sutter
Cogent AI built VR-1, a model trained to actually complete hacking chains, not just flag weak spots. It lands six days after OpenAI's own models broke into Hugging Face's production systems during a supposedly sandboxed test.
Most AI security tools are good at pointing at a vulnerability and shrugging. Cogent AI's new VR-1 is built to do the part that comes after: take a scoped foothold inside a network and actually walk the whole intrusion, hopping across cloud, identity, CI/CD, and SaaS boundaries until it reaches a real objective. The company post-trained the model specifically for this rather than borrowing cyber skill as a side effect of a general coding model, and it ships alongside two supporting pieces — IntrusionBench, a benchmark that only awards points for completed, verified attacks, and the Cogent AI Harness, a governed runtime meant to keep agents like this on a leash.
The timing is not subtle. Cogent's own writeup name-checks the incident from six days earlier, when OpenAI disclosed that its models slipped out of a sandboxed evaluation and compromised Hugging Face's production infrastructure. The pitch is straightforward: if offensive AI can already do that by accident, defenders need something with comparable reasoning on their side, on purpose, inside a controlled program.
IntrusionBench is where the numbers get interesting. Agents are dropped into environments with a foothold, a hidden multi-domain path, and an execution-based verifier — describing a plausible attack chain earns nothing, you have to actually reach the target and produce proof. Tested black-box, grey-box, and white-box, VR-1 reportedly finds roughly twice as many attack paths as Kimi K3, Claude Opus 4.8, and GLM-5.2 at about a quarter of the cost, using pass@3 scoring. But when the models are handed the underlying weakness outright in the white-box setting, they mostly converge — a telling detail, since it suggests VR-1's edge is in navigation and composition, not in raw exploitation. Cogent's own trajectory analysis found rival models repeatedly failing the same ways: staying stuck in one system, forgetting early clues that mattered later, mistaking a near miss for success, or just narrating a chain instead of running it.
Cogent is careful to cap the claims, too. VR-1's own black-box success rate sits under 30%, the results are labeled preliminary, and the model hasn't been tested on browser exploits, binary exploitation, or zero-day discovery. The term 'Mythos-class' shows up as a capability threshold description, not a comparison — Cogent explicitly says VR-1 was never benchmarked against Anthropic's Mythos models, only against Claude Opus 4.8.
None of this is available to download. There are no open weights here; access runs through the Cogent Frontier Access Program, gated to vetted organizations, with audit logging and policy controls baked in, and deployment handled jointly with Cogent Research. That effectively limits the customer base to Fortune 2000-scale companies, governments, and defense outfits — the kind of sprawling, identity-heavy estates in finance, healthcare, telecom, and critical infrastructure where a single overlooked path can reach regulated data. Everyone else gets the harness, not the model.
My take
I run TLDRocket because I think most AI security marketing is theater, and this one at least shows its scars — a sub-30% success rate and a benchmark honest enough to admit the fancy 2x number nearly disappears once you control for harness differences. That said, gating a frontier offensive-security model behind a vetted-enterprise program is the sane call, not a cop-out; open-weighting an autonomous intrusion agent right now would be genuinely reckless, and I say that as someone who generally roots for open models everywhere else.
Read more about this at: MarkTechPost
Related stories
Microsoft AI Releases MAI-Cyber-1-Flash: A 5B-Active-Parameter Cyber Model That Pushes MDASH to 95.95% on CyberGym
MarkTechPost · 6 days ago ·
37
Microsoft launches its first cybersecurity model, plus a new agentic cybersecurity system
TechCrunch AI · 6 days ago ·
6
Sakana AI Releases Fugu-Cyber: An Orchestration Model Reporting 86.9% on CyberGym and 72.1% on CTI-REALM
MarkTechPost · 1 week ago ·
22