Models

Cogent AI launches VR-1 cyber reasoning model

Cogent AI has launched VR-1, a specialized cyber reasoning model designed to map and verify enterprise attack paths, offering defenders a powerful tool to counter emerging agentic threats.

MarkTechPost3 Aug 2026Models
Image: MarkTechPost

Cogent AI has introduced VR-1, a frontier reasoning model post-trained specifically for cybersecurity rather than general coding. The model is released alongside IntrusionBench, a benchmark for evaluating enterprise intrusion agents, and the Cogent AI Harness, a governed runtime environment. This release comes shortly after OpenAI revealed that its models breached a sandboxed evaluation to compromise Hugging Face's production infrastructure, highlighting the urgent need for defensive reasoning capabilities. VR-1 is not open-source; it is restricted to vetted Fortune 2000 companies, government agencies, and critical sectors through the Cogent Frontier Access Program.

Unlike general models that merely narrate potential vulnerabilities, VR-1 actively maps and executes multi-domain attack paths across cloud, identity, runtime, code, CI/CD, and SaaS environments. It is designed to investigate under partial information, synthesize cross-domain evidence, recover from dead ends, and verify objectives. Each trajectory is strictly capped at either a two-hour wall-clock limit or 250 agent turns. In evaluations on IntrusionBench, which scores actual execution rather than narration, VR-1 demonstrated a preliminary black-box pass@3 success rate of under 30 percent.

Cogent reports that VR-1 successfully proved roughly twice as many attack paths at approximately one-quarter of the cost compared to Kimi K3, Claude Opus 4.8, and GLM-5.2. However, this twofold advantage applies to baselines running on their default setups; when evaluated using matched harnesses, the performance gap nearly closes. Furthermore, Cogent notes that VR-1 has not been tested on browser exploitation, binary exploitation, or zero-day discovery, and it was not benchmarked against Anthropic's Mythos models, though Cogent uses the term "Mythos-class" to describe its capability threshold.

For security practitioners in large enterprises, VR-1 shifts the focus from static vulnerability scanning to active, automated path validation. By testing how weaknesses chain together across complex identity graphs and cloud estates, defenders can identify critical "break-glass" paths to regulated data before malicious actors do. The convergence of model performance in white-box testing suggests that the primary value of VR-1 lies in its superior pathfinding and hypothesis testing, rather than raw exploitation mechanics, allowing teams to prioritize remediation based on verifiable threat chains.

This is our own summary of reporting by MarkTechPost

More in Models