
Microsoft AI has announced MAI-Cyber-1-Flash, a compact security model purpose-built for finding vulnerabilities in complex code, and shipped it inside MDASH, the company’s multi-agent vulnerability identification and remediation harness. The combined system scores 96% on CyberGym, the standard benchmark for reasoning over large codebases to surface real flaws, and does so at roughly half the cost of running the strongest competing configurations.
What MAI-Cyber-1-Flash does
MAI-Cyber-1-Flash is derived from the MAI-Thinking-1 lineage and was built in-house on Microsoft’s highest quality training data. The model targets the long tail of challenging vulnerability cases in large codebases, where attackers need only a single weakness to gain a foothold. By handling the bulk of these scans efficiently, the model lets MDASH reserve larger, more expensive models for the small share of tasks that genuinely require them.
Microsoft’s stated split is that MAI-Cyber-1-Flash handles up to 90% of all tasks, while the larger GPT-5.4 is reserved for the remaining 10% of exceptionally hard cases. Microsoft frames this routing as the practical reason for the cost reduction, since token spend, not raw model strength, is the binding constraint for security teams facing enormous volumes of inbound attacks.
Performance on CyberGym
On CyberGym, the unified MDASH system with MAI-Cyber-1-Flash scored 96%, a 12-point lift over Mythos. Microsoft also reports that the combination beats Gemini and GPT on the same benchmark. Compared with Microsoft’s previous best MDASH offering, GPT-5.4 plus 5.4 mini plus 5.3 codex, the new configuration cuts cost by 50%.
How MDASH fits in
MDASH is a multi-agent harness tuned by internal security experts and now contains more than 100 agents built on multiple leading models. Those agents find, validate, and remediate vulnerabilities. Agentic code scanning inside MDASH feeds Project Perception, a new agentic security system Microsoft is launching in parallel that runs teams of agents to continuously monitor, patch, and close new threat vectors. Perception will also begin using MAI-Cyber-1-Flash for additional security workflows beyond software vulnerability work.
What makes the training signal unique
Three layers are doing the work, according to Microsoft: the model, the data, and the harness.
- Model. MAI-Cyber-1-Flash is a compact, code-heavy security model derived from MAI-Thinking-1, built from scratch in-house on high-quality data.
- Data. Decades of running security products give Microsoft trillions of daily signals across identity, endpoint, cloud, and network, along with a record of real exploits and remediations that Microsoft describes as unmatched.
- Harness. MDASH orchestrates more than 100 expert-tuned agents across multiple leading models to find, validate, and remediate vulnerabilities.
Safety and enterprise controls
MAI-Cyber-1-Flash is Microsoft’s first cyber model, and the company built trust into every layer of the system. Training used a security-first calibration, the model was evaluated by Microsoft’s AI Red Team, was tested through automated and expert-led adversarial exercises, and was independently assessed by a third party. Through MDASH, customers get enterprise-grade controls including role-based access, tenant isolation, encryption, auditability, and sandboxed execution environments with no internet access.
Why the reinforcement loop matters
Microsoft frames cybersecurity as a live reinforcement learning loop. Every day, defenders investigate threats, triage alerts, hunt adversaries, remediate vulnerabilities, deploy protections, and learn from the outcome. Microsoft says it sees that loop end to end: vulnerabilities through the Microsoft Security Response Center, attacks and defenses across identity, endpoint, cloud, data, browser, and applications, more than 100 trillion security signals every day, and operational insight from 1.6 million customers. Because the company can connect actions to outcomes (what was exploitable, what was contained, what was blocked, and what worked), it argues its models can improve continuously.
FAQ
What is MAI-Cyber-1-Flash?
MAI-Cyber-1-Flash is a compact, code-heavy security model from Microsoft AI, derived from the MAI-Thinking-1 lineage, designed to find challenging vulnerabilities in complex codebases.
What is MDASH?
MDASH is Microsoft’s multi-agent vulnerability identification and remediation harness. It coordinates more than 100 expert-tuned agents built on multiple leading models to find, validate, and remediate vulnerabilities.
How does the new configuration perform and cost?
MDASH with MAI-Cyber-1-Flash scores 96% on CyberGym, a 12-point lift over Mythos, and cuts cost by 50% compared with Microsoft’s prior best MDASH configuration (GPT-5.4 plus 5.4 mini plus 5.3 codex).
This article summarizes reporting from microsoft.ai. See our editorial disclaimer for how our articles are produced.
Run a free scan to see your AI Visibility Score, SEO rating, and local citation accuracy.