Cantina releases apex-flash-1, an open-weights security model post-trained on real paid vulnerabilities

ctjlewis · x · 2026-10-02

Security firm Cantina, with Yeta Labs, released apex-flash-1, its first open-weights model for security research, post-trained on real vulnerabilities found via its paid bounty programs. An abliterated variant with fewer refusals is also available for authorized research workflows.

The team argues the dominant safety debate—controlling advanced cyber capabilities via proprietary APIs and usage restrictions—is flawed because cybersecurity is adversarial: attackers ignore acceptable-use policies and procurement rules, and capability will spread through open weights anyway. The linked post digs into governance questions around who should access such capabilities.

Original post →

More from Models

Models channel →