{"slug": "mai-cyber-1", "title": "MAI-Cyber 1", "summary": "Microsoft announced MAI-Cyber-1-Flash, a compact security model integrated into its MDASH multi-agent vulnerability harness, achieving 96% on the CyberGym benchmark, 12 points above Mythos, while delivering a 50% cost saving compared to its previous best offering. The model, derived from the MAI-Thinking-1 lineage, is designed to handle up to 90% of security tasks efficiently, reserving larger models like GPT-5.4 for the hardest 10%.", "body_md": "#\nIntroducing MAI-Cyber-1-Flash inside MDASH\n\nToday we’re announcing MAI-Cyber-1-Flash inside of MDASH, our multi-agent vulnerability identification and remediation harness. Together they deliver **world-class performance at 50% of the cost of leading models.**\n\nProgress in AI has been startling and so has the new generation of cyber threats it’s unleashing. Attackers now wield increasingly powerful capabilities, probing an ever-growing mountain of code for just a single weakness that lets them in.\n\nAs the cost of finding a flaw collapses, the old model of security, where you scan occasionally and patch eventually, is now obsolete. If we’re to unlock the true benefits of AI, we must first build outstanding cyber models that help all of us harden the software the world runs on.\n\nThat’s the motivation behind MAI-Cyber-1-Flash, which has been built to find challenging vulnerabilities in complex codebases. It’s been deeply integrated into MDASH, honed by the best cybersecurity experts in the industry and hardened across the largest security estate on the planet.\n\nThis combined expertise delivers exceptional security protection, beating Mythos, Gemini and GPT on CyberGym, the gold standard benchmark for evaluating how systems reason over large codebases to find real vulnerabilities in the code.\n\n**Picking the right model for the task**\n\nSecurity is an always-on mission, and given the enormous volume of inbound attacks, token cost is now the real constraint for defenders. MAI-Cyber-1-Flash was designed to efficiently handle up to 90% of all tasks, enabling MDASH to use the larger and most costly models in our fleet (in this case GPT-5.4) for the 10% of exceptionally hard tasks that truly need them.\n\nThe result is that the unified system of MDASH with MAI-Cyber-1-Flash delivers ** 96% on CyberGym (+12 pt above Mythos)**.\n\nThis combination delivers a ** 50% cost saving** when compared against our best offering in MDASH today (GPT 5.4 + 5.4 mini + 5.3 codex). That’s the power of a well-tuned, multi-model system with access to uniquely rich historical training data. It ensures you always have the best model at the best price for every task.\n\nIn this new environment, being able to go from identifying a new vulnerability to addressing it in real-time is critical. And while AI remediation of software vulnerabilities is now a key security workflow, there are many jobs to be done by Security practitioners themselves.\n\nThat’s why today we’re also launching [Perception](http://aka.ms/agenticsecurityblog), our agentic security systems, that provides teams of agents for a variety of security workflows in MDASH, to continuously monitor, patch, and close new threat vectors. Perception will also soon use MAI-Cyber-1-Flash for many more security workflows, beyond the software vulnerability work.\n\n**Three things matter today: Model. Data. Harness.**\n\nWe have jointly optimized our world-class models, our unmatched historic data, and our expert-tuned harness to ensure that our customers have a uniquely powerful security offering.\n\n**Model.** MAI-Cyber-1-Flash is a compact, code-heavy security model derived from the MAI-Thinking-1 lineage, which was built from scratch, in-house, on the highest quality data. Details in our [technical report](https://microsoft.ai/pdf/mai-thinking-1.pdf).\n\n**Data.** Our deepest advantage. Decades of building world-class security systems now give us trillions of daily signals across identity, endpoint, cloud, and network, and an unmatched record of real exploits and remediations. No one can manufacture this history.\n\n**Harness.** [MDASH](https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-tops-leading-industry-benchmark/?msockid=07e1b320223d63fa1e34a47d23db623b), our multi-agent vulnerability identification and remediation harness, is tuned by the best security experts in the industry, who have created 100+ agents using multiple leading models to find, validate, and remediate vulnerabilities. Agentic code scanning is a critical function in the Security Operating Center and feeds Project Perception, our new agentic security system.\n\n**Built with safety first\n**\n\nBecause MAI-Cyber-1-Flash is Microsoft’s first cyber model, we built trust into every layer of the system, from model training to customer deployment. The model was developed with a security-first calibration, rigorously evaluated by Microsoft’s AI Red Team, tested through automated and expert-led adversarial exercises, and independently assessed by a third party.\n\nTrust extends beyond the model itself. Through MDASH, customers get enterprise-grade controls including Role-Based Controls, tenant isolation, encryption, auditability, and sandboxed execution environments with no internet access. The result is a cyber model that delivers powerful capabilities to defenders while maintaining the governance, security, and control enterprises expect from Microsoft.\n\n**Our hill-climbing machine**\n\nCybersecurity is not just a data-rich domain; it is a live reinforcement learning loop. Every day, defenders investigate threats, triage alerts, hunt adversaries, remediate vulnerabilities, deploy protections, and learn from the outcome.\n\nMicrosoft sees that loop end to end: vulnerabilities through [Microsoft Security Response Center](https://www.microsoft.com/en-us/msrc); attacks and defenses across identity, endpoint, cloud, data, browser, and applications; **more than 100 trillion security signals every day**; and operational insight from 1.6 million customers. Because we can connect actions to outcomes; what was exploitable, what was contained, what was blocked, and what actually worked; we have more than data.\n\nOur MAI reinforcement learning loop gives us the foundation to build cyber models that improve continuously and become expert cyber defenders. That’ll remain our commitment to our customers for years to come.\n\n##\nBuild the Future With Us\n\nWe’re a lean, talent-dense team of explorers, researchers, and full-stack engineers. We move fast, sweat the details, and operate at frontier scale with a roadmap to build the world’s most powerful AI models. Most importantly, we’re united by the belief that doing this right is the only way to do it at all. If our mission resonates with you, we’d love to talk.\n\n[Explore all jobs](/careers)", "url": "https://wpnews.pro/news/mai-cyber-1", "canonical_source": "https://microsoft.ai/news/introducing-mai-cyber-1-flash-inside-mdash/", "published_at": "2026-07-27 16:52:22+00:00", "updated_at": "2026-07-27 18:04:44.381912+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-products", "ai-safety", "ai-agents", "ai-infrastructure"], "entities": ["Microsoft", "MAI-Cyber-1-Flash", "MDASH", "Mythos", "Gemini", "GPT", "CyberGym", "GPT-5.4"], "alternates": {"html": "https://wpnews.pro/news/mai-cyber-1", "markdown": "https://wpnews.pro/news/mai-cyber-1.md", "text": "https://wpnews.pro/news/mai-cyber-1.txt", "jsonld": "https://wpnews.pro/news/mai-cyber-1.jsonld"}}