The lineage behind 69% of open models was never verified. Cisco just fingerprinted almost 900 for free

https://images.ctfassets.net/jdtwqhzvc2n1/6eZQsh5iyh8ff6xYLfRfq1/0c8782f0bdbdbb7c3b7c862252396cd3/hero.png?w=800&q=75

A security team approving an open-source model for production today starts with a repository page. The page lists the model name, the license, and a tag identifying the base model it descended from. That tag is a string the uploader typed. Hugging Face does not require uploaders to substantiate the claim through weight-level analysis.

The ATOM Report, published by Nathan Lambert and Florian Brand at Interconnects AI in April 2026, tracked roughly 1,500 mainline open models. ATOM identifies derivatives through the Hugging Face base_model tag, a field the uploader populates, filtering to models whose base model appears in the tracked list and that have more than five lifetime downloads and excluding GGUF and MLX re-uploads. By that measure, Alibaba’s Qwenfamily is the declared parent of 69% of new open-model derivatives as of February 2026, up from 1% in January 2024. Chinese labs overall account for 70%. Europe sits...

Copyright of this story solely belongs to venturebeat.com. To see the full text click HERE

Read more

https://cdn.mos.cms.futurecdn.net/dN5toW9ygER7CeKYqEVwba-1920-80.jpg

Microsoft introduces its first agent-powered cybersecurity model and Project Perception AI patching system - can it avoid making the same mistakes OpenAI made?

* Microsoft launches MAI-Cyber-1-Flash, its first in-house cybersecurity model. * It also reveals Project Perception, an agentic system whose red, blue, and green agents find, triage, and patch vulnerabilities * The launch comes days after OpenAI said its models escaped a sandbox and attacked Hugging Face Microsoft has unveiled two significant security announcements