Cogent Launches VR-1 Attack Path Model

Cogent Security launched VR-1 on July 27, a cybersecurity reasoning model designed to find and prove enterprise attack paths from an initial foothold. According to Cogent's benchmark results, VR-1 proved twice as many paths as Kimi K3, Claude Opus 4.8, and GLM-5.2 at roughly one-quarter of the cost, although SiliconANGLE reports that the comparison depends substantially on Cogent's proprietary agent harness.
Cogent Security launched VR-1 on July 27, introducing a frontier reasoning model built to identify and prove attack paths across live enterprise environments. The model is accompanied by IntrusionBench, a Cogent-created benchmark that gives an agent an initial foothold and a target, then scores successful execution of an attack chain rather than a model's stated assessment that a path exists.
According to Cogent's press release, VR-1 proved twice as many enterprise attack paths as competing frontier models at roughly one-quarter of the cost. The reported comparison set includes Kimi K3, Claude Opus 4.8, and GLM-5.2. Cogent CEO Vineet Edupuganti said, "For two years, every security vendor has claimed to be AI-native. VR-1 lets us put a number on it."
Benchmark design and limitations
SiliconANGLE reports that IntrusionBench's hardest configuration provides no information about the enterprise environment beyond the initial foothold and objective. Reaching a target can require traversing cloud infrastructure, identity systems, public-facing services, and internal tooling, where individual flaws may only become material when chained together.
The publication also reports an important qualification to Cogent's headline result: the chart compares VR-1 with the other models operating under their default harnesses. When Kimi K3, Claude Opus 4.8, and GLM-5.2 ran within Cogent's harness, their results were within a few percentage points of VR-1. VR-1's success rate was itself below 30%, SiliconANGLE reports, and all models improved as more environmental information was disclosed.
Cogent did not benchmark VR-1 against Anthropic's Mythos model, despite marketing VR-1 as "Mythos-class," according to SiliconANGLE. The Anthropic model used in the published comparison was Claude Opus 4.8.
Why execution-based evaluation matters
Attack-path validation is a more demanding task than isolated vulnerability discovery. It requires an agent to reason across permissions, configuration state, software artifacts, and network exposure, then demonstrate that a sequence of actions can reach a defined objective. For security teams, that distinction can help separate theoretically plausible findings from reachable, higher-priority paths.
The published harness result also illustrates a broader evaluation issue for autonomous cybersecurity agents: model weights, tool access, orchestration, and environmental context can all materially affect measured performance. Independent replication and more detail on IntrusionBench's environments, task composition, and scoring would be needed to determine how broadly Cogent's comparative results generalize.
Key Points
- 1Cogent released VR-1 for execution-based enterprise attack-path validation, targeting multi-step chains rather than isolated vulnerability findings.
- 2Cogent reports a 2x result at one-quarter cost, but SiliconANGLE found the gap narrows when competitors use Cogent's harness.
- 3Cybersecurity-agent evaluations increasingly depend on orchestration, tools, and context, making benchmark design as consequential as underlying model capability.
Scoring Rationale
VR-1 addresses a relevant security-agent capability: proving multi-step attack paths in enterprise environments. Its practical significance is tempered by the vendor-created benchmark and reporting that the comparative advantage narrows under a shared harness.
Sources
Primary source and supporting public references used for this report.
Practice with real Telecom & ISP data
90 SQL & Python problems · 15 industry datasets
250 free problems · No credit card
See all Telecom & ISP problems
