Meta and Cisco Integrate Open-Source AI Models into Next-Generation Security Operations

As cyberattacks accelerate at machine speed, open-source large language models (LLMs) are rapidly emerging as core infrastructure. They empower startups and established cybersecurity leaders to build and deploy flexible, cost-efficient defenses against threats that outpace human response times.
The inherent benefits of open-source LLMs—faster deployment, greater adaptability, and lower costs—establish a scalable, secure bedrock for infrastructure delivery. At last week’s RSAC 2025 conference, Cisco, Meta, and ProjectDiscovery unveiled new open-source LLMs and a community-powered attack surface innovation, collectively shaping the future of open-source cybersecurity.
A central theme from RSAC this year is the evolution of open-source LLMs to enhance and fortify infrastructure on a large scale.
Open-source AI is nearing the breakthrough that cybersecurity leaders have long advocated: enabling diverse security providers to unite against increasingly sophisticated threats. Given the RSAC announcements, the vision of collaborative creation around a unified open-source LLM and infrastructure is now closer to reality.
As Cisco’s Chief Product Officer Jeetu Patel stated in his keynote, “Our real opponent isn’t our competition—it’s the adversary. We must ensure the ecosystem has the tools and unity to collectively counter these threats.”
Patel highlighted the urgency behind this complex mission: “AI is reshaping everything, and cybersecurity sits at the epicenter. We’re facing threats that operate at machine scale, not human scale.”
Cisco’s Foundation-sec-8B LLM defines a new era of open-source AI
Cisco’s newly formed Foundation AI group—stemming from its acquisition of Robust Intelligence—specializes in delivering domain-specific AI infrastructure for cybersecurity, one of the most demanding fields. Built on Meta’s Llama 3.1 architecture, this 8-billion parameter open-weight LLM is not a repurposed general-purpose AI. It was purpose-built and rigorously trained on a cybersecurity dataset curated internally by Cisco’s Foundation AI team.
Yaron Singer, VP of AI and Security at Foundation, writes, “By nature, the challenges in this domain are among AI’s toughest. To make the technology widely accessible, we decided that most Foundation AI work should be open. Open innovation creates compounding industry benefits, especially in cybersecurity.”
By anchoring itself in open-source, Cisco has designed a practical framework for cybersecurity providers—often competitors with similar offerings—to collaborate on building stronger, unified defenses.
Singer notes, “Whether you’re embedding it into existing tools or creating new workflows, foundation-sec-8b adapts to your organization’s specific requirements.” According to Cisco’s launch blog, security teams can deploy foundation-sec-8b across the security lifecycle. Suggested use cases include SOC acceleration, proactive threat defense, engineering support, AI-assisted code review, configuration validation, and custom integration.
Foundation-sec-8B’s model weights and tokenizer are available under the Apache 2.0 license on Hugging Face, giving enterprises customization and deployment freedom without vendor lock-in, while preserving compliance and privacy. Cisco also plans to open-source the training pipeline to fuel community-driven innovation.
Cybersecurity is in the LLM’s DNA
Cisco developed a cybersecurity-specific model optimized for SOC, DevSecOps, and enterprise security teams. Retrofitting a generic AI model wouldn’t suffice, so the Foundation AI team trained it using a broad, high-quality cybersecurity dataset.
This precision-driven approach ensures the model comprehensively understands real-world cyber threats, vulnerabilities, and defense strategies.
Core training datasets included:
- Vulnerability Databases: Detailed CVEs (Common Vulnerabilities and Exposures) and CWEs (Common Weakness Enumerations) for identifying known threats and weaknesses.
- Threat Behavior Mappings: Structured information from proven security frameworks like MITRE ATT&CK, detailing attacker techniques and behaviors.
- Threat Intelligence Reports: Comprehensive analysis of global cybersecurity incidents and emerging threats.
- Red-Team Playbooks: Real-world adversarial tactics and penetration strategies.
- Real-World Incident Summaries: Documented cybersecurity breach analyses, incidents, and resolution paths.
- Compliance and Security Guidelines: Best practices from leading standards bodies, including NIST frameworks and OWASP secure coding principles.
This tailored training equips Foundation-sec-8B to handle complex cybersecurity tasks with superior accuracy, deeper context, and faster response times compared to general-purpose models.
Benchmarking Foundation-sec-8B LLM
Cisco’s technical benchmarks indicate Foundation-sec-8B delivers cybersecurity performance rivaling much larger models:
Benchmark Foundation-sec-8B Llama-3.1-8B Llama-3.1-70B CTI-MCQA 67.39 64.14 68.23 CTI-RCM 75.26 66.43 72.66
By designing a cybersecurity-specific foundation model, Cisco helps SOC teams achieve higher efficiency with advanced threat analytics, all without incurring steep infrastructure costs.
As detailed in its blog, “Foundation AI: Robust Intelligence for Cybersecurity,” Cisco’s strategy tackles common AI adoption hurdles, including limited domain alignment of general models, insufficient datasets, and legacy system integration. Foundation-sec-8B is engineered to overcome these barriers, running effectively on minimal hardware—often just one or two Nvidia A100 GPUs.
Meta expands open-source AI security with AI Defenders suite
At RSAC 2025, Meta reinforced its open-source commitment, expanding its AI Defenders Suite to secure generative AI infrastructure. The updated open-source toolkit includes Llama Guard 4, a multimodal classifier that identifies policy violations in text and images, improving compliance monitoring in AI workflows.
Meta also introduced LlamaFirewall, an open-source real-time security framework with modular features. These include PromptGuard 2, which detects prompt injections and jailbreak attempts; Agent Alignment Checks to monitor and protect AI agent decisions; and CodeShield, which inspects generated code to find and fix vulnerabilities.
Prompt Guard 2 now offers two open-source variants: a high-accuracy 86M-parameter model and a more streamlined 22M-parameter version for low-resource environments.
Additionally, Meta launched CyberSec Eval 4, an open-source benchmarking suite developed with CrowdStrike. It includes CyberSOC Eval, which measures AI performance in realistic SOC scenarios, and AutoPatchBench, which tests AI systems on autonomously identifying and patching software flaws.
Meta also debuted the Llama Defenders Program, offering early access to open AI-based security tools such as sensitive-document classifiers and audio threat detection. Private Processing, a privacy-centric on-device AI, is also being piloted within WhatsApp.
ProjectDiscovery’s Nuclei: Community-Driven, open-source security innovation
At RSAC 2025, ProjectDiscovery earned the “Most Innovative Startup” award in the Innovation Sandbox, underscoring its dedication to open-source cybersecurity. Its flagship tool, Nuclei, is a customizable open-source vulnerability scanner that leverages a global community to swiftly detect issues across APIs, websites, cloud instances, and networks.
Nuclei’s YAML-based template library contains over 11,000 detection patterns—3,000 of which map to specific CVEs—enabling real-time threat identification. Andy Cao, COO of ProjectDiscovery, noted, “Winning the 20th annual RSAC Innovation Sandbox shows that open-source models can thrive in cybersecurity. It’s a testament to our community-driven approach to democratizing security.”
ProjectDiscovery’s progress aligns with Gartner’s 2024 Hype Cycle for Open-Source Software, which identifies open-source AI and cybersecurity tools in the “Innovation Trigger” phase. Gartner advises organizations to establish open-source program offices (OSPOs), adopt SBOM frameworks, and ensure regulatory compliance through sound governance.
Actionable insights for security leaders
Cisco’s Foundation-sec-8B, Meta’s AI Defenders Suite enhancements, and ProjectDiscovery’s Nuclei collectively illustrate that cybersecurity innovation flourishes when openness, collaboration, and domain expertise converge across organizations. These vendors and others are paving the way for every cybersecurity provider to participate in building more effective, affordable defenses.
As Patel stressed in his keynote, “This isn’t just theoretical—it’s real. With purpose-built security models that are accessible to all, we’ll achieve better security outcomes at a fraction of the cost, backed by state-of-the-art reasoning.”
Related article
Base44 Unveils Proprietary AI Model to Bolster Defensibility in Vibe Coding Platform
Base44, the vibe coding platform acquired by Wix for $80 million just a year ago — when it was merely six months old with a team of eight — has begun deploying its proprietary AI model to help users build applications using natural language.This deve
Multiverse Computing Launches Free Compressed Generative AI Model
Large language models face a significant challenge: their immense size. Spanish startup Multiverse Computing is tackling this problem by creating compressed models designed to bridge the gap between the capabilities of cutting-edge AI and what busine
Secret Tracking Data Exposes Theft of AI Models
A new method can invisibly watermark models like ChatGPT in seconds without retraining, leaving no trace in standard outputs and resisting all practical removal attempts. The key distinction between watermarking and 'copyright-baiting' is that waterm
Related Special Topic Recommendations
Comments (2)
0/500
オープンソースLLMがセキュリティの基盤になるとは、面白い展開ですね。コスト効率が良いのは良いですが、攻撃側も同じ技術を使うなら、結局エスカレートしそうです。中小企業には朗報ですが、管理責任が曖昧にならないか心配です。🤔

As cyberattacks accelerate at machine speed, open-source large language models (LLMs) are rapidly emerging as core infrastructure. They empower startups and established cybersecurity leaders to build and deploy flexible, cost-efficient defenses against threats that outpace human response times.
The inherent benefits of open-source LLMs—faster deployment, greater adaptability, and lower costs—establish a scalable, secure bedrock for infrastructure delivery. At last week’s RSAC 2025 conference, Cisco, Meta, and ProjectDiscovery unveiled new open-source LLMs and a community-powered attack surface innovation, collectively shaping the future of open-source cybersecurity.
A central theme from RSAC this year is the evolution of open-source LLMs to enhance and fortify infrastructure on a large scale.
Open-source AI is nearing the breakthrough that cybersecurity leaders have long advocated: enabling diverse security providers to unite against increasingly sophisticated threats. Given the RSAC announcements, the vision of collaborative creation around a unified open-source LLM and infrastructure is now closer to reality.
As Cisco’s Chief Product Officer Jeetu Patel stated in his keynote, “Our real opponent isn’t our competition—it’s the adversary. We must ensure the ecosystem has the tools and unity to collectively counter these threats.”
Patel highlighted the urgency behind this complex mission: “AI is reshaping everything, and cybersecurity sits at the epicenter. We’re facing threats that operate at machine scale, not human scale.”
Cisco’s Foundation-sec-8B LLM defines a new era of open-source AI
Cisco’s newly formed Foundation AI group—stemming from its acquisition of Robust Intelligence—specializes in delivering domain-specific AI infrastructure for cybersecurity, one of the most demanding fields. Built on Meta’s Llama 3.1 architecture, this 8-billion parameter open-weight LLM is not a repurposed general-purpose AI. It was purpose-built and rigorously trained on a cybersecurity dataset curated internally by Cisco’s Foundation AI team.
Yaron Singer, VP of AI and Security at Foundation, writes, “By nature, the challenges in this domain are among AI’s toughest. To make the technology widely accessible, we decided that most Foundation AI work should be open. Open innovation creates compounding industry benefits, especially in cybersecurity.”
By anchoring itself in open-source, Cisco has designed a practical framework for cybersecurity providers—often competitors with similar offerings—to collaborate on building stronger, unified defenses.
Singer notes, “Whether you’re embedding it into existing tools or creating new workflows, foundation-sec-8b adapts to your organization’s specific requirements.” According to Cisco’s launch blog, security teams can deploy foundation-sec-8b across the security lifecycle. Suggested use cases include SOC acceleration, proactive threat defense, engineering support, AI-assisted code review, configuration validation, and custom integration.
Foundation-sec-8B’s model weights and tokenizer are available under the Apache 2.0 license on Hugging Face, giving enterprises customization and deployment freedom without vendor lock-in, while preserving compliance and privacy. Cisco also plans to open-source the training pipeline to fuel community-driven innovation.
Cybersecurity is in the LLM’s DNA
Cisco developed a cybersecurity-specific model optimized for SOC, DevSecOps, and enterprise security teams. Retrofitting a generic AI model wouldn’t suffice, so the Foundation AI team trained it using a broad, high-quality cybersecurity dataset.
This precision-driven approach ensures the model comprehensively understands real-world cyber threats, vulnerabilities, and defense strategies.
Core training datasets included:
- Vulnerability Databases: Detailed CVEs (Common Vulnerabilities and Exposures) and CWEs (Common Weakness Enumerations) for identifying known threats and weaknesses.
- Threat Behavior Mappings: Structured information from proven security frameworks like MITRE ATT&CK, detailing attacker techniques and behaviors.
- Threat Intelligence Reports: Comprehensive analysis of global cybersecurity incidents and emerging threats.
- Red-Team Playbooks: Real-world adversarial tactics and penetration strategies.
- Real-World Incident Summaries: Documented cybersecurity breach analyses, incidents, and resolution paths.
- Compliance and Security Guidelines: Best practices from leading standards bodies, including NIST frameworks and OWASP secure coding principles.
This tailored training equips Foundation-sec-8B to handle complex cybersecurity tasks with superior accuracy, deeper context, and faster response times compared to general-purpose models.
Benchmarking Foundation-sec-8B LLM
Cisco’s technical benchmarks indicate Foundation-sec-8B delivers cybersecurity performance rivaling much larger models:
| Benchmark | Foundation-sec-8B | Llama-3.1-8B | Llama-3.1-70B |
| CTI-MCQA | 67.39 | 64.14 | 68.23 |
| CTI-RCM | 75.26 | 66.43 | 72.66 |
By designing a cybersecurity-specific foundation model, Cisco helps SOC teams achieve higher efficiency with advanced threat analytics, all without incurring steep infrastructure costs.
As detailed in its blog, “Foundation AI: Robust Intelligence for Cybersecurity,” Cisco’s strategy tackles common AI adoption hurdles, including limited domain alignment of general models, insufficient datasets, and legacy system integration. Foundation-sec-8B is engineered to overcome these barriers, running effectively on minimal hardware—often just one or two Nvidia A100 GPUs.
Meta expands open-source AI security with AI Defenders suite
At RSAC 2025, Meta reinforced its open-source commitment, expanding its AI Defenders Suite to secure generative AI infrastructure. The updated open-source toolkit includes Llama Guard 4, a multimodal classifier that identifies policy violations in text and images, improving compliance monitoring in AI workflows.
Meta also introduced LlamaFirewall, an open-source real-time security framework with modular features. These include PromptGuard 2, which detects prompt injections and jailbreak attempts; Agent Alignment Checks to monitor and protect AI agent decisions; and CodeShield, which inspects generated code to find and fix vulnerabilities.
Prompt Guard 2 now offers two open-source variants: a high-accuracy 86M-parameter model and a more streamlined 22M-parameter version for low-resource environments.
Additionally, Meta launched CyberSec Eval 4, an open-source benchmarking suite developed with CrowdStrike. It includes CyberSOC Eval, which measures AI performance in realistic SOC scenarios, and AutoPatchBench, which tests AI systems on autonomously identifying and patching software flaws.
Meta also debuted the Llama Defenders Program, offering early access to open AI-based security tools such as sensitive-document classifiers and audio threat detection. Private Processing, a privacy-centric on-device AI, is also being piloted within WhatsApp.
ProjectDiscovery’s Nuclei: Community-Driven, open-source security innovation
At RSAC 2025, ProjectDiscovery earned the “Most Innovative Startup” award in the Innovation Sandbox, underscoring its dedication to open-source cybersecurity. Its flagship tool, Nuclei, is a customizable open-source vulnerability scanner that leverages a global community to swiftly detect issues across APIs, websites, cloud instances, and networks.
Nuclei’s YAML-based template library contains over 11,000 detection patterns—3,000 of which map to specific CVEs—enabling real-time threat identification. Andy Cao, COO of ProjectDiscovery, noted, “Winning the 20th annual RSAC Innovation Sandbox shows that open-source models can thrive in cybersecurity. It’s a testament to our community-driven approach to democratizing security.”
ProjectDiscovery’s progress aligns with Gartner’s 2024 Hype Cycle for Open-Source Software, which identifies open-source AI and cybersecurity tools in the “Innovation Trigger” phase. Gartner advises organizations to establish open-source program offices (OSPOs), adopt SBOM frameworks, and ensure regulatory compliance through sound governance.
Actionable insights for security leaders
Cisco’s Foundation-sec-8B, Meta’s AI Defenders Suite enhancements, and ProjectDiscovery’s Nuclei collectively illustrate that cybersecurity innovation flourishes when openness, collaboration, and domain expertise converge across organizations. These vendors and others are paving the way for every cybersecurity provider to participate in building more effective, affordable defenses.
As Patel stressed in his keynote, “This isn’t just theoretical—it’s real. With purpose-built security models that are accessible to all, we’ll achieve better security outcomes at a fraction of the cost, backed by state-of-the-art reasoning.”
Base44 Unveils Proprietary AI Model to Bolster Defensibility in Vibe Coding Platform
Base44, the vibe coding platform acquired by Wix for $80 million just a year ago — when it was merely six months old with a team of eight — has begun deploying its proprietary AI model to help users build applications using natural language.This deve
Multiverse Computing Launches Free Compressed Generative AI Model
Large language models face a significant challenge: their immense size. Spanish startup Multiverse Computing is tackling this problem by creating compressed models designed to bridge the gap between the capabilities of cutting-edge AI and what busine
Secret Tracking Data Exposes Theft of AI Models
A new method can invisibly watermark models like ChatGPT in seconds without retraining, leaving no trace in standard outputs and resisting all practical removal attempts. The key distinction between watermarking and 'copyright-baiting' is that waterm
オープンソースLLMがセキュリティの基盤になるとは、面白い展開ですね。コスト効率が良いのは良いですが、攻撃側も同じ技術を使うなら、結局エスカレートしそうです。中小企業には朗報ですが、管理責任が曖昧にならないか心配です。🤔





Home






