Microsoft on Monday unveiled its first cybersecurity-focused model along with a new AI cybersecurity platform at a small event in San Francisco, dealing a major blow to the space’s major players — namely Anthropic, Google and OpenAI.
The company describes MAI-Cyber-1-Flash as a model built “to find challenging vulnerabilities in complex codebases.” The model is built to bring to life MDASH, Microsoft’s harness dedicated to software vulnerability detection and remediation.
The new security platform is called Perception and is designed to develop groups of agents to assist and automate various security workflows, including bug detection and remediation. The platform can also be integrated with MDASH.
The company claims that the MAI-Cyber-1-Flash is significantly more powerful (and more cost-effective) than competing models, based on its performance on an established AI cybersecurity benchmark.
“We are very excited to announce our results,” said Mustafa Suleyman, the co-founder of DeepMind and current CEO of Microsoft AI. “We have the MAI-1 Cyber Flash reserved [sic] with GPT 5.4 inside the MDASH harness — beating Gemini, GPT 5.5 Cyber, GPT 5.6 Sol and Mythos 5 in Cyber Gym, which is the main benchmark we all use. The golden benchmark”.
“We’re sending it to production immediately,” he added.
Noting that hackers are increasingly using AI in their cyberattacks, Hayete Gallot, Microsoft’s vice president of security, described Perception as a way for enterprise defenders to “defend against AI with AI at the scale and speed that attackers have.”
Perception uses green red groups, blue groups and green groups. Red teams can provide detailed simulations of potential attacks — providing context about potential threat actors and the potential vulnerabilities they might exploit. Blue teams are dedicated to identifying and measuring existing bugs, while green teams take “corrective actions” against those bugs.
Dave Weston, Perception’s chief engineer, described the platform as a huge efficiency upgrade for enterprise defenders. “We’ve gotten away from that taking hours and hours of manual work from a lot of specialized people across the security organization—app hunters, remediation engineers, you name it—and within minutes, we have a solution for all of that. Not only do we discover the problems and prioritize them, but we have detection, posture remediation, and even code remediation.”
Although artificial intelligence has provided companies with new defensive capabilities, its availability to cybercriminals has given rise to a dazzling array of potential threats.
Microsoft’s new security tools, which the company said will be available in preview on Nov. 3, will enter an increasingly crowded field of AI cybersecurity solutions. Earlier this year, Anthropic released Mythos, a security platform released to a small group of partner organizations through a program called Glasswing. OpenAI has also started its own security solution in May through a program called Daybreak.
When you purchase through links in our articles, we may earn a small commission. This does not affect our editorial independence.
