New Microsoft Model Targets Vulnerability Detection

Microsoft has launched MAI-Cyber-1-Flash, a cybersecurity AI model built to find vulnerabilities in complex codebases, inside its MDASH multi-agent identification and remediation harness.

The company said the combination delivers strong performance at half the cost of leading models. MAI-Cyber-1-Flash is designed to efficiently handle up to 90 per cent of tasks, letting MDASH reserve larger, costlier models for the hardest 10 per cent that truly need them.

Microsoft framed the release as a response to a changing threat landscape. Attackers now use increasingly powerful AI to probe growing volumes of code for a single weakness. As the cost of finding a flaw falls, the company argued, the old model of scanning occasionally and patching eventually is obsolete.

MAI-Cyber-1-Flash was built to find challenging vulnerabilities in complex codebases and has been integrated into MDASH, which Microsoft said was honed by cybersecurity experts and hardened across a very large security estate. The company said the model beats rival systems, including Mythos, Gemini and GPT, on CyberGym, a benchmark for evaluating how systems reason over large codebases to find real vulnerabilities.

Microsoft reported the unified system of MDASH with MAI-Cyber-1-Flash scores 96 per cent on CyberGym, 12 points above the Mythos model. It said the combination delivers a 50 per cent cost saving against its current best MDASH configuration, which pairs several larger models.

The company positioned the model as an example of a well-tuned, multi-model system, using a smaller specialised model for the bulk of tasks and escalating only the hardest cases to frontier models. It said this ensures the best model at the best price for each task.

Microsoft also launched Perception, agentic security systems that provide teams of agents for a range of security workflows within MDASH. The agents continuously monitor, patch and close new threat vectors. Microsoft said Perception will use MAI-Cyber-1-Flash for more security workflows over time, beyond software vulnerability work.

The economics argument sits at the centre of the launch. Microsoft said that, given the volume of inbound attacks, token cost is now the real constraint for defenders. Running a cheaper specialised model for most tasks, and escalating only the hardest cases, is intended to make continuous scanning affordable at scale.