All the US companies are keeping their "cyber" models locked down for special customers. So, it seems like anyone who isn't at a Fortune 500 or whatever qualifies for access, will be using Chinese models for vulnerability research.
I would, most of these cybersecurity models have not been made available to the public and the larger models have guardrails in place for certain cybersecurity tasks unless you've been specifically approved.