AI Cybersecurity Enters a New Era of Models, Agents, and Action

Cybersecurity AI is moving from research demonstrations into active vulnerability discovery, testing, and defense. On October 10, 2026, OrcaRouter released OrcaCyber Zero 1.5, while Anthropic’s Cyber Mission reported thousands of findings and Tenable expanded a marketplace for inspected AI security components.
These developments point toward a new security race: models must find weaknesses, reproduce them, help build exploits, and support the teams responsible for fixing them. The challenge is no longer only discovering vulnerabilities. It is turning those discoveries into validated reports, upstream patches, and safer AI-powered workflows.
OrcaCyber Zero 1.5 Targets Authorized Vulnerability Research
OrcaCyber Zero 1.5 is a post-trained Orca model built for vulnerability reproduction, exploit development, and penetration testing. The model ships with a 1M-token context window, native function calling, and structured outputs, giving security researchers tools for handling long technical investigations and connecting model responses to software systems.
OrcaRouter reports scores near the ceiling on cyber benchmarks, along with strong coding performance. OrcaCyber Zero 1.5 achieved 100% on Cybench, completing all 39 of 39 tasks. It scored 95.8% on CVE-Bench with 23 of 24 tasks, reached 93.9% on HumanEval+, and posted 76.5% on SWE-bench Pro V2.
The model is accessible through an OpenAI-compatible API, with access gated to the Security Research tier. Pricing is $3.00 per 1M input tokens and $7.50 per 1M output tokens. Over the past 7 days, its p50 time-to-first-token was 500 milliseconds, while p95 time-to-first-token was 2.36 seconds.
OrcaRouter describes the goal in four words: “fewer reports, more validated and fixed vulnerabilities.” That idea captures the pressure facing every AI security system. Finding a weakness matters, but proving it, explaining it, and helping maintainers patch it determines whether the discovery improves security.
Anthropic’s Cyber Mission Shows the Scale of AI Discovery
Anthropic’s dashboard lists 29,439 findings discovered between November 1, 2025, and October 2, 2026. By October 2, Anthropic had disclosed 6,157 findings across 591 open-source projects, reporting them to maintainers, and 516 had been patched upstream.
The findings went through two paths. A total of 1,333 came through triage, while 4,824 went directly to maintainers. Security firms reviewed 6,123 findings, confirming 5,674 as valid, a 92.7% confirmation rate.
Anthropic’s OSS Scanner provides free periodic scans to enrolled projects, including a reproducer, an explanation, and a candidate patch. Its dashboard reports that 85 of 97 early scanner findings cleared the disclosure bar. Outside penetration testers checked 97 critical and high findings: 85 met the disclosure bar, 11 were known issues, and one was a false positive.
The numbers also show how the program changed between May and October 2026. Findings reported to maintainers climbed from 1,596 to 6,157, a 3.9x increase. Findings patched upstream grew from 97 to 516, a 5.3x increase, while patched findings rose from 6.1% to 8.4% of reported findings.
That progress still leaves a major operational problem. CrowdStrike senior vice president Adam Meyers stated, “the problem is patching. At ten times today’s findings, they’re going to be completely underwater.” Discovery can scale with models, but engineering teams must still review, prioritize, test, and deploy fixes.
Programs and Exchanges Aim to Secure the Next AI Layer
Anthropic’s Critical Infrastructure Defense Program includes 11 partners: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation. Anthropic’s June program for government reached more than half of all US states, while Anthropic’s Cyber Mission may receive $100 million through the AI Cyber Defense Act proposed by Rep. Josh Gottheimer.
If funded, that act would authorize a CISA pilot from 2027 to 2031, offering free frontier-model access to critical infrastructure operators. Gottheimer also warned, “Many ‘think tokens are free, but they’re not free.’” The statement highlights the cost questions surrounding large-scale AI use in public infrastructure and security operations.
Critical infrastructure remains a difficult target. WaterISAC representative Tom Dobbins said, “OT systems that are exposed to the internet are a major challenge, and many of these systems that are older generation need to be not accessible to the internet.” Former FBI official Cynthia Kaiser, now at Halcyon, added, “it’s not just about getting access, and that the question is where do they start?”
On October 8, 2026, Tenable announced the expansion of its CyberAgents Exchange, which uses OpenAI GPT cyber models to evaluate AI components. Tenable’s Exchange Inspector vetting process combines skills inspection, frontier model assessment, and expert review, with AI component inspection powered by Tenable One AI Exposure.
Featured vetted skills include SOC Hunter, Remediation Priority & Impact Agent, and Splunk Tenable Cloud Security Skill. SOC Hunter reduces hunt times by 75%, while Remediation Priority & Impact Agent can reduce analyst triage time by up to 20X per cycle. The Splunk skill helps query and triage findings in Splunk.
Tenable CTO Vlad Korsunsky said, “Leveraging Tenable One AI Exposure’s advanced AI discovery engine and frontier assessment using OpenAI GPT cyber models, the Exchange Inspector provides an additional layer of review for this rapidly growing subset of agents, skills and MCP servers before deployment.” He said the process helps “security teams can accelerate AI innovation while maintaining rigorous security standards.”
OpenAI Head of Global Cyber Partnerships McCall McIntyre described the effort this way: “The cybersecurity community has come together in a truly meaningful way on the CyberAgents Exchange.” The next phase of AI cybersecurity will depend on whether models, scanners, agents, maintainers, and infrastructure operators can work as one system—finding more problems without overwhelming the people who must fix them.
Based on
- OrcaRouter Releases OrcaCyber Zero 1.5 Cybersecurity Model With 1M Context — marktechpost.com
- Anthropic’s Cyber Mission starts with 6,157 findings reported to maintainers and 516 patched | VentureBeat — venturebeat.com
- Tenable Uses OpenAI GPT Cyber Models to Advance Agentic Security Review in the CyberAgents Exchange | Markets Insider — markets.businessinsider.com




