{"slug": "depthfirst-continuous-cyber-defense", "title": "DepthFirst: Continuous Cyber Defense", "summary": "DepthFirst launched an AI-native continuous cyber defense product that scans code, dependencies, infrastructure and live environments, and published a benchmark comparing 34 model and thinking-level configurations on detection cost, recall and validation precision. The top configuration, Mythos 5, achieved 69% overall recall at $99.19 in detection cost, while dfs-large1 reached 62.2% recall at $6.77; GPT 6 Sol at xhigh scored 59.3% recall at $13.30 and the lowest-cost configuration, GPT 6 Sol at med, hit 37.3% recall for $0.15. Validation precision ranged from 15.7% to 48.5%, yielding F1 scores between 27.6% and 51.5%.", "body_md": "AI-native security that thinks like an elite security research team and works across your code, dependencies, infrastructure, and live environment.\n\n%\n\n< min\n\n> %\n\n| Model and thinking level |  | \n|---|---|\n|  | Thinking | \n|---|---|\n| dfs-large1 |  | \n| GPT 5.6 Sol | xhigh | \n| GPT 5.6 Sol | high | \n| GPT 5.6 Sol | med | \n| GPT 5.6 Luna | xhigh | \n| GPT 5.6 Luna | high | \n| GPT 5.6 Luna | med | \n| Opus 5 | high | \n| Opus 5 | med | \n| Opus 5.5 | high | \n| Opus 5.5 | med | \n| Grok 4.5 | high | \n| Grok 4.7 | xhigh | \n| Grok 4.7 | high | \n| Kimi K3 | max | \n| Kimi K3 | high | \n| Qwen 3.8 | max | \n| GLM 5.2 | xhigh | \n| GLM 5.2 | high | \n| DeepSeek v4 Flash | max | \n| DeepSeek v4 Flash | high | \n| Gemini 3.6 Flash | high | \n| Mythos 5* |  | \n| Gemini 3.8 Flash | high | \n| Muse Spark 1.3 | xhigh | \n| DeepSeek v4.1 Flash | high | \n| GPT 6 Luna | xhigh | \n| GPT 6 Luna | high | \n| GPT 6 Luna | med | \n| GPT 6 Sol | xhigh | \n| GPT 6 Sol | high | \n| GPT 6 Sol | med | \n| MiMo-v2.6 Flash |  | \n| MiMo-v2.6 Pro |  | \n\n| Detection cost and overall recall |  | \n|---|---|\n| $6.77 | 62.2% | \n| $43.37 | 65.7% | \n| $26.47 | 59.6% | \n| $9.51 | 48.9% | \n| $2.53 | 52.4% | \n| $1.57 | 39.6% | \n| $0.69 | 28% | \n| $22.66 | 45.4% | \n| $21.89 | 47.8% | \n| $8.42 | 54.9% | \n| $7.66 | 48.1% | \n| $7.70 | 57.2% | \n| $19.94 | 59.0% | \n| $16.02 | 56.6% | \n| $9.10 | 48% | \n| $6.22 | 46.7% | \n| $7.91 | 40.8% | \n| $9.72 | 40.7% | \n| $4.09 | 38.2% | \n| $1.23 | 31.8% | \n| $1.03 | 30.1% | \n| $7.44 | 20.9% | \n| $99.19 | 69% | \n| $8.03 | 44.2% | \n| $10.24 | 47.4% | \n| $1.69 | 57.3% | \n| $0.43 | 45.7% | \n| $0.28 | 38.1% | \n| $0.15 | 37.3% | \n| $13.30 | 59.3% | \n| $6.45 | 57.7% | \n| $3.43 | 49.6% | \n| $0.86 | 53.5% | \n| $1.38 | 55% | \n\n| Detection recall by domain |  |  | \n|---|---|---|\n| 66.5% | 42.4% | 62.3% | \n| 67.1% | 67.3% | 60.7% | \n| 62.8% | 62.3% | 49.2% | \n| 54.2% | 38.5% | 44.3% | \n| 56.8% | 45.1% | 47.5% | \n| 48.4% | 23.1% | 31.1% | \n| 31.6% | 15.4% | 29.5% | \n| 54.8% | 34.1% | 31.1% | \n| 45.8% | 57.7% | 44.3% | \n| 60.9% | — | 48.2% | \n| 57.5% | — | 35.9% | \n| 59.1% | 51.6% | 0% | \n| 68.4% | 42.1% | 53.9% | \n| 68.4% | 15.8% | 55.1% | \n| 31.8% | 31.8% | 30.4% | \n| 48.4% | 51.8% | 37.9% | \n| 40.8% | 40.8% | 40.8% | \n| 34.8% | 22.4% | 44.3% | \n| 42.6% | 11.1% | 44.3% | \n| 27.6% | 29.5% | 45.9% | \n| 30.1% | 30.1% | 30.1% | \n| 19.4% | 11.5% | 32.8% | \n| 70.8% | 61.4% | 71% | \n| 50.6% | 17.3% | 50.8% | \n| 55.5% | 32% | 39.3% | \n| 64.1% | 54.5% | 48.9% | \n| 50% | 40.4% | 39.3% | \n| 43.9% | 25% | 34.4% | \n| 40.6% | 26.9% | 37.7% | \n| 61.9% | 51.9% | 59% | \n| 58.7% | 56.9% | 55.7% | \n| 48.4% | 51.9% | 50.8% | \n| 54.9% | 47.9% | 55.3% | \n| 58.6% | 38.9% | 59.8% | \n\n| Detection recall by repository scope |  | \n|---|---|\n| 63% | 52.6% | \n| 66.3% | 57.9% | \n| 63.3% | 10.5% | \n| 50.6% | 26.3% | \n| 53.2% | 42.1% | \n| 40.2% | 31.6% | \n| 29.3% | 10.5% | \n| 47% | 26.3% | \n| 48.2% | 42.1% | \n| 57.2% | 31.3% | \n| 49.7% | 31.6% | \n| 59.9% | 25% | \n| 61.4% | 20% | \n| 57.7% | 40% | \n| 49.8% | 34.8% | \n| 48.5% | 31.6% | \n| 40.8% | 40.8% | \n| 43.4% | 20.9% | \n| 42.2% | 36.8% | \n| 32.9% | 26.3% | \n| 31.9% | 8.3% | \n| 20.9% | 21.1% | \n| 70.4% | 50% | \n| 44.8% | 36.3% | \n| 48.6% | 31.6% | \n| 58.5% | 42.1% | \n| 46.4% | 36.8% | \n| 39.4% | 21.1% | \n| 38.6% | 21.1% | \n| 59.4% | 57.9% | \n| 58.9% | 42.1% | \n| 50.2% | 42.1% | \n| 54.3% | 28.6% | \n| — | — | \n\n| Validation precision | \n|---|\n| 18.3% | \n| 18% | \n| 22.3% | \n| 24.6% | \n| 23.2% | \n| 24.8% | \n| 27.3% | \n| 39.4% | \n| 40.5% | \n| 48.5% | \n| 44.2% | \n| 29.5% | \n| 23.9% | \n| 30.5% | \n| 30.1% | \n| 33.3% | \n| 29.6% | \n| 28.6% | \n| 30.8% | \n| 24.8% | \n| 26.8% | \n| 43.5% | \n| 24.5% | \n| 41.4% | \n| 34.1% | \n| 36.4% | \n| 21.8% | \n| 24.5% | \n| 33.3% | \n| 15.7% | \n| 18.9% | \n| 22.6% | \n| 24.4% | \n| 18.1% | \n\n| F1 from detect recall and validate precision | \n|---|\n| 28.3% | \n| 28.3% | \n| 32.5% | \n| 32.7% | \n| 32.2% | \n| 30.5% | \n| 27.6% | \n| 42.2% | \n| 43.8% | \n| 51.5% | \n| 46.1% | \n| 38.9% | \n| 34.0% | \n| 39.7% | \n| 37.0% | \n| 38.9% | \n| 34.3% | \n| 33.6% | \n| 34.1% | \n| 27.9% | \n| 28.4% | \n| 28.2% | \n| 36.2% | \n| 42.8% | \n| 39.7% | \n| 44.5% | \n| 29.5% | \n| 29.8% | \n| 35.2% | \n| 24.8% | \n| 28.5% | \n| 31.1% | \n| 33.5% | \n| 27.2% | \n\n| Differential analysis |  | \n|---|---|\n| $1.34 | 75.6% | \n| $10.67 | 75.3% | \n| $5.46 | 76.3% | \n| $2.32 | 74.4% | \n| $0.62 | 71% | \n| $0.30 | 71.3% | \n| $0.13 | 65.1% | \n| $7.41 | 70.3% | \n| $5.48 | 71.3% | \n| $1.78 | 79.5% | \n| $1.34 | 75.3% | \n| $3.38 | 65.1% | \n| $6.56 | 74.8% | \n| $6.46 | 70.3% | \n| $6.34 | 60.3% | \n| $4.18 | 60.1% | \n| $2.99 | 72.7% | \n| $2.04 | 61.4% | \n| $1.56 | 58.6% | \n| $0.79 | 66.8% | \n| $0.55 | 67.4% | \n| $1.51 | 61% | \n| — | — | \n| $1.57 | 63.8% | \n| $3.12 | 72.8% | \n| $0.71 | 70.1% | \n| $0.12 | 72.1% | \n| $0.09 | 72.4% | \n| $0.07 | 69.5% | \n| $3.90 | 75.2% | \n| $2.06 | 76.3% | \n| $1.00 | 71.6% | \n| $0.08 | 72.7% | \n| $0.12 | 76.5% | \n\n| Differential analysis by NEW, KEPT, and CLOSED |  |  | \n|---|---|---|\n| 45.8% | 95% | 86% | \n| 46.8% | 95% | 84.1% | \n| 45.6% | 94.4% | 88.9% | \n| 39.2% | 93.3% | 90.7% | \n| 38.9% | 89.3% | 84.8% | \n| 32.5% | 92.4% | 89.1% | \n| 22.2% | 79.2% | 94% | \n| 38.2% | 79.8% | 92.8% | \n| 37.4% | 83.8% | 92.8% | \n| 66.7% | 86.8% | 85.2% | \n| 47.7% | 91.5% | 86.8% | \n| 39.9% | 74.5% | 80.9% | \n| 51.2% | 90.5% | 82.6% | \n| 43.9% | 86.3% | 80.8% | \n| 35.5% | 72% | 73.4% | \n| 31.4% | 75.3% | 73.5% | \n| 33.6% | 95% | 89.6% | \n| 25.5% | 85.6% | 73% | \n| 25.3% | 76.4% | 74.1% | \n| 28.4% | 83% | 89% | \n| 27.1% | 88.1% | 87% | \n| 18.3% | 68.9% | 96.5% | \n| — | — | — | \n| 32% | 66.3% | 93.1% | \n| 47.1% | 85.1% | 86.2% | \n| 48.5% | 67.5% | 94.2% | \n| 44.4% | 89% | 82.9% | \n| 45.8% | 91.2% | 80.1% | \n| 36.1% | 87.4% | 85% | \n| 58.3% | 92.9% | 74.5% | \n| 61.8% | 92% | 75% | \n| 52.8% | 86.3% | 75.9% | \n| 38.7% | 89.9% | 89.5% | \n| 55.6% | 92.8% | 81.3% | \n\nDependency Firewall blocks malicious packages. Security Reviewer validates every human and AI-generated code change before vulnerabilities, sensitive data, or malware enter your codebase.\n\ndepthfirst reasons about business logic and cross-service data flows the way a security engineer does, so the only findings you see are the ones that are genuinely exploitable.\n\ndepthfirst attacks your running applications continuously, proving at runtime which vulnerabilities are actually exploitable and re-testing every fix after merge.\n\ndepthfirst traces every dependency to the code that actually calls it, so you fix the handful of vulnerabilities with a real path into your application instead of the whole SBOM.\n\nSet policy once. Every scan, fix, and agent action inherits it automatically.\n\nEvery finding, decision, and fix lives in one place: searchable, exportable, audit-ready.\n\nSee who did what, when, and why. Every human and agent action is logged, immutable, and traceable.\n\nGive teams exactly the access they need. No more, no less. Scoped by repo, environment, or org.\n\nIndependently audited. Your data handled the way your security team demands.\n\nBring your own key. Your data stays encrypted under your control, not ours.", "url": "https://wpnews.pro/news/depthfirst-continuous-cyber-defense", "canonical_source": "https://depthfirst.com/", "published_at": "2026-09-30 21:12:59+00:00", "updated_at": "2026-09-30 21:49:00.249351+00:00", "lang": "en", "topics": ["ai-safety", "artificial-intelligence", "ai-products", "ai-tools"], "entities": ["DepthFirst", "dfs-large1", "GPT 5.6 Sol", "GPT 6 Sol", "Mythos 5", "Opus 5", "Grok 4.7", "Kimi K3"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/depthfirst-continuous-cyber-defense", "markdown": "https://wpnews.pro/news/depthfirst-continuous-cyber-defense.md", "text": "https://wpnews.pro/news/depthfirst-continuous-cyber-defense.txt", "jsonld": "https://wpnews.pro/news/depthfirst-continuous-cyber-defense.jsonld"}}