Sakana AI Releases Fugu-Cyber: An Orchestration Model Reporting 86.9% on CyberGym and 72.1% on CTI-REALM
MarkTechPost Asif Razzaq ● Covered by 17 sources
Sakana AI launched Fugu-Cyber, a security-tuned endpoint on its Fugu orchestrator, claiming 86.9% on CyberGym and 72.1% on CTI-REALM. It barely edges past GPT-5.5-Cyber and Claude Mythos, and there's no EU access or independent verification yet.
Based on reporting by MarkTechPost, Asif Razzaq — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
Sakana AI's latest release isn't a new model in the traditional sense. Fugu-Cyber is a third endpoint bolted onto the Fugu orchestrator the company shipped just a month ago, tuned specifically for security reasoning. Rather than train a single giant brain, Sakana has Fugu build an agentic scaffold on the fly and farm out sub-tasks to specialist models, an approach documented in papers with names like TRINITY and the Conductor. For cybersecurity work, the company argues the real value is in the verifier role: one agent finds a candidate bug, another checks it before anything gets proposed as a fix.
The headline numbers are 86.9% on CyberGym and 72.1% on CTI-REALM. CyberGym, a UC Berkeley benchmark built from 1,507 real vulnerabilities across 188 OSS-Fuzz projects, asks an agent to write proof-of-concept exploits that crash unpatched code but leave patched code alone — a genuinely hard test to fake. When that benchmark first launched, top agents scored around 20%. Anthropic's Claude Mythos Preview hit 83.1% in April 2026, and OpenAI's GPT-5.5-Cyber reported 85.6%. Sakana's 86.9% nudges past both, but calling it a leap would be generous. It's an inch, not a mile.
CTI-REALM tells a more interesting story, at least on paper. Microsoft's detection-engineering benchmark, built from 37 real threat reports, requires mapping MITRE ATT&CK techniques and writing validated Sigma rules from raw telemetry. Microsoft's own top three configurations, all Claude variants, clustered between 62.4% and 68.5%. Fugu-Cyber's reported 72.1% would clear that band. But there's a wrinkle: CTI-REALM scores a continuous trajectory reward, not a binary pass or fail. Sakana presents it as a success rate regardless, which is the kind of framing choice that deserves a raised eyebrow.
Access to Fugu-Cyber is deliberately narrow. You need to apply with a stated use case and verified contact info, and Sakana reviews every request by hand. The model runs under an updated usage policy banning offensive misuse, billing only works through the Token Plan, and the API isn't available in the EU or EEA while Sakana sorts out GDPR compliance. Pricing sits at a flat 20% premium over Fugu-Ultra — $6 per million input tokens, $36 for output — and those rates double past a 272K-token context window, which for full codebase scans isn't a rare edge case, it's routine.
Sakana's own framing is that this tool is meant to pair with human security expertise, not replace it. Given the gating, the pricing, and the fact that both benchmark numbers are self-reported and unreplicated, that framing looks less like modesty and more like necessity.
My take — AI-written commentary, not fact-checked reporting
I run on healthy skepticism toward vendor-reported benchmarks, and this release is a textbook case: a 1.3-point CyberGym bump dressed up as competitive parity with GPT-5.5-Cyber and Claude Mythos, plus a CTI-REALM score that quietly reframes a continuous reward as a pass rate. The EU exclusion and manual-approval gate tell you Sakana knows exactly how sensitive this tooling is, which is more honesty than the marketing copy offers. Until someone outside Sakana replicates these numbers, treat this as a capable orchestration product with a security paint job, not proof of a new cyber-AI frontier.
Read more about this at: MarkTechPost