Research2026-07-15

Cogent Security described VR-1, a post-trained cyber reasoning model built to investigate unfamiliar enterprise environments from a limited foothold, combine weaknesses across cloud, identity, application runtime, CI/CD, SaaS and internal documentation, and execute verified attack chains. On the black-box configuration of Cogent's own IntrusionBench, VR-1 reportedly achieved more than a 2x lift in pass@3 over the strongest evaluated frontier baseline within a two-hour wall-clock or 250-turn budget, with the gap narrowing in grey-box and disappearing largely in white-box settings. Cogent characterizes VR-1 as "Mythos-class" only in the sense of moving from finding weaknesses to executing material attack paths, not as parity with Anthropic's Mythos on binary exploitation or zero-day discovery. Both VR-1 and IntrusionBench are at early preview; results come from a small task set, with task counts and confidence intervals promised in a later technical report.

Send this to someone who needs it

Shares the story and its sources. Nothing about you.

What does this mean for your job?

This is the story as everyone gets it. Once a week we send you the version written for your role — what changed, why it matters for the work you actually do, and one thing to try. Free while we tune it.