TLDRocket
Sign in

OrcaRouter Releases OrcaCyber Zero 1.5 Cybersecurity Model With 1M Context

MarkTechPost Asif Razzaq

OrcaRouter launched OrcaCyber Zero 1.5, a security model with 1M context and gated access. It’s tuned for finding real vulns, not just spitting out alerts.

Based on reporting by MarkTechPost, Asif Razzaq — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

OrcaRouter has pushed out OrcaCyber Zero 1.5, the latest version of its security-focused model and the follow-up to OrcaCyber Zero 1.0, which shipped on September 17, 2026. The pitch is straightforward: this one is trained for authorized vulnerability research, including reproduction, exploit development and penetration testing.

The headline feature is the size of the window. OrcaCyber Zero 1.5 ships with 1M-token context, plus native function calling and structured outputs. Orca says that makes it better suited to long, messy security work across large codebases, where the model has to track evidence, test ideas and keep going without losing the thread.

The benchmark claims are strong, at least on paper. Orca reports 100% on Cybench, 95.8% on CVE-Bench, 93.9% on HumanEval+ and 76.5% on SWE-bench Pro V2. The company says the Cybench score covers 39 tasks under unrestricted agent execution, while the CVE-Bench result comes from a 24-task evaluable subset. It also says the SWE-bench Pro V2 number is not directly comparable with standard SWE-bench Pro results.

Access is tightly controlled. Developers use an OpenAI-compatible API through OrcaRouter, but only through the Security Research tier. Orca says that tier is for trusted security researchers, red teams and authorized testing, with an engagement, a passkey and accepted terms required. Pricing is set at $3.00 per 1M input tokens and $7.50 per 1M output tokens, with cache reads at $0.75 per 1M tokens.

Orca also says the model is built for autonomous agents and large-scale security reasoning, with a focus on finding flaws such as RCE, sandbox escapes, auth bypasses, privilege escalation and attack chains. The company’s own numbers are doing most of the talking here, though, and the fine print matters: there’s no independent replication in the release, no disclosed parameter count and no weights for anyone to poke at locally.

My take — AI-written commentary, not fact-checked reporting

This is the right place for closed access, frankly. Security models are one of the few AI categories where “just release everything” can sound heroic and still be a terrible idea. The bigger story is how quickly every vendor now turns one self-reported leaderboard into a product launch and a morality play.

Read more about this at: MarkTechPost

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.