Logic of Logic
thursday, august 6, 2026 · the day's ai, attributed published by trilot llc · wyoming
brief productssafety

Cognition ships Devin Security Swarm

Devin Security Swarm runs parallel agents that find vulnerabilities, validate exploits in sandboxes, and open fix PRs; 72% recall on a 50-CVE benchmark.

Cognition launched Devin Security Swarm on July 1, an enterprise product that points a swarm of parallel agents at a codebase to find vulnerabilities, confirm they are exploitable, and ship remediation PRs. It runs on an architecture Cognition calls Agentic MapReduce: agents investigate segments of the codebase, findings are composed into full attack paths, and each path is reproduced in an isolated sandbox before a patch is generated.

The sandbox step is the interesting part. On Cognition’s benchmark of 50 real vulnerabilities drawn from published GitHub Security Advisories across 14 languages, the swarm found 36 (72% recall) at $90.23 per run, against 68% for Claude Security at $131.87, 48% for Codex Security, and 26% for Cursor Security. Three critical vulnerabilities were found only by Devin. The numbers come from Cognition’s own evaluation, so apply the usual discount, but runtime validation directly targets the false-positive noise that makes most scanners expensive to operate.

Availability is enterprise-only from July 1, with an optional six-week program where Cognition’s forward-deployed engineers work through an existing CVE backlog.

Every major coding-agent vendor now has a security product: OpenAI expanded its Daybreak tools in June, and the agent-infrastructure side is getting the same treatment from Runlayer’s MCP governance layer. Whatever finds the bugs, the verification habit still applies to the fixes.

sources 2 cited
1 cognition.com Introducing Devin Security Swarm 2 devin.ai Evaluating Security Swarm
next