AI News Feed
Market watch
Cybersecurity

OrcaRouter Releases OrcaCyber Zero 1.5 Cybersecurity Model With 1M-Token Context

OrcaRouter released OrcaCyber Zero 1.5, a gated 1M-context cybersecurity model for authorized vulnerability research.

OrcaCyber Zero 1.5 has a 1-million-token context window, a maximum output of 128K tokens, native function calling and structured outputs, MarkTechPost reported. Parameter count, hardware, weights and quantized variants were not disclosed. The model supports text input and text output. OrcaRouter said the model was post-trained for security research and authorized security engineering, with listed uses including vulnerability reproduction, exploit development, penetration testing, security auditing and cyber reasoning.

The report said OrcaRouter described three design goals: find unknown flaws such as remote code execution, sandbox escapes, authentication bypasses, privilege escalation and attack chains; go beyond detection by reasoning through attack paths, challenging its own hypotheses and ranking flaws by demonstrable exploitability; and support autonomous agents working with large codebases through the 1M-token context, native tool calling and extended reasoning.

OrcaRouter published four vendor-reported benchmark results, last evaluated October 10, 2026, according to the report. The model scored 100% on Cybench, or 39 of 39 tasks under unrestricted agent execution; 95.8% on CVE-Bench, or 23 of 24 evaluable tasks; 93.9% on HumanEval+; and 76.5% on SWE-bench Pro V2. MarkTechPost noted that Cybench contains 40 professional CTF tasks, so the 100% result covered 39 of them. CVE-Bench is built on 40 critical-severity web CVEs, and Orca's 95.8% covers a 24-task evaluable subset. The SWE-bench Pro V2 score is not directly comparable with standard SWE-bench Pro results.

The report said all figures were self-reported, none were independent replications, and no technical report was yet available. It also said the 98% CyberGym claim belongs to Zero 1.0 inside Orca's harness. OrcaRouter said the model brings fewer reports and more validated and fixed vulnerabilities for security teams.

Developers access OrcaCyber Zero 1.5 through an OpenAI-compatible API, setting the base URL to https://api.orcarouter.ai/v1 and calling orca/orcacyber-zero-1.5, according to MarkTechPost. Access is gated to the Security Research tier, which OrcaRouter says targets trusted security researchers, red teams and authorized testing. Requirements include an engagement, a passkey and accepted terms. Pricing is $3.00 per 1 million input tokens and $7.50 per 1 million output tokens, with cache reads at $0.75 per 1 million tokens.

Over the past seven days, the model's p50 time-to-first-token was 500 milliseconds and p95 was 2.36 seconds, MarkTechPost reported. The report said the sample was small, at 1.3K tokens of traffic. Zero 1.0 recorded a 3.43-second p50 over a much larger traffic window, and the two latency figures are not a clean comparison.

MarkTechPost compared the model with other cyber-focused releases, including Anthropic's Claude Mythos Preview, OpenAI's GPT-5.5-Cyber and Sakana AI's Fugu-Cyber. The report said those competitor figures came from each vendor's own announcement and were not independently replicated. It also noted that OrcaCyber Zero 1.5 pricing is far below Mythos Preview's listed $25 per 1 million input tokens and $125 per 1 million output tokens after credits. OrcaCyber Zero 1.5 is available on the gated Security Research tier.