Exclusive: Cogent Security debuts VR-1, a frontier model built to prove attack paths

Vulnerability management startup Cogent Security Inc. today introduced Cogent VR-1, a frontier reasoning model trained to find and prove attack paths inside live enterprise environments.

The company says VR-1 proved twice as many attack paths as other frontier models on IntrusionBench, a benchmark released alongside it, at roughly a quarter of the cost. The test gives an agent a foothold and a target and nothing else. Getting there means working through cloud infrastructure, identity systems and whatever internal tooling the company happens to run. Scoring is based on execution. An agent that says it could have reached the target gets no credit.

Frontier models are good at finding a bug in a codebase. Real intrusions are messier. They travel through a chain of small weaknesses that individually look like backlog noise, such as a public service with a minor flaw or an identity carrying more permission than it needs. Cogent trained VR-1 to link those together the way an attacker would, then check whether a proposed fix closes the gap or simply relocates the risk.

The benchmark is Cogent’s own work and the headline numbers come from its hardest configuration, where the agent is told nothing about the environment it lands in. The comparison set is Kimi K3, Claude Opus 4.8 and GLM-5.2. A chart released with the model shows the doubling measured against those three running on their own default harnesses. Run inside Cogent’s harness, all three land within a few percentage points of VR-1, which posted a success rate under 30% itself. As more of the environment was revealed, every model improved and the spread narrowed further.