{"id":2034,"date":"2026-07-28T06:35:29","date_gmt":"2026-07-28T06:35:29","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2034"},"modified":"2026-07-28T06:35:29","modified_gmt":"2026-07-28T06:35:29","slug":"microsoft-says-new-cybersecurity-ai-model-helps-mdash-hit-95-95-at-half-the-cost","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2034","title":{"rendered":"Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Swati Khandelwal<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 28, 2026<\/span><\/span><span class=\"p-tags\">AI Security \/ Vulnerability Management<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhwmG858LYHQA-u4cQupdhqsi5oUcvLaQdoorupsW3tzPZvDg7kwgRIewOBPVNvp3Szfqb4VFJ_j6caul2NTIlm69_-vskp4gYQwVkQA59LbsMhOEO3yr4C48nhrO177ORbi9uFc_oIOrcXnCBs_dmPhVDZVZx9F3Cyp4RQKi71EhvfZQqmUKat36cbqEE\/s1700-e365\/MAI-Cyber-1-Flash.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Microsoft has launched its first cybersecurity-specific model inside <strong>MDASH<\/strong>, its multi-model vulnerability identification and remediation harness.<\/p>\n<p>The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. Access is limited to approved MDASH customers through an Azure AI Foundry private preview.<\/p>\n<p><strong>MAI-Cyber-1-Flash<\/strong> is designed to handle up to 90% of MDASH tasks, with GPT-5.4 reserved for the hardest 10%. It is available only inside MDASH, not as a standalone public model or general-purpose application programming interface.<\/p>\n<p>The headline score belongs to MDASH running MAI-Cyber-1-Flash alongside GPT-5.4, not to the new model by itself. CyberGym Level 1 is a known-vulnerability reproduction test. It gives an agent a vulnerability description and the corresponding unpatched source code, then checks whether it can produce a working proof of concept. It does not measure blind vulnerability discovery or whether a generated patch is correct.<\/p>\n<p>CyberGym&#8217;s <a href=\"https:\/\/www.cybergym.io\/cybergym\/\" target=\"_blank\">public leaderboard<\/a> did not list Microsoft&#8217;s 95.95% result when checked on July 28, 2026. It still listed Microsoft&#8217;s May 12 MDASH submission at 88.4%. Microsoft&#8217;s public materials do not say whether the result was submitted for listing.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Microsoft&#8217;s earlier 96.55% MDASH result does not resolve the comparison. That June figure counted any crash, including non-target vulnerabilities. The July materials do not say whether the 95.95% result uses the same criterion, so the two scores cannot safely be read as a before-and-after performance trend.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>According to Microsoft&#8217;s <a href=\"https:\/\/microsoft.ai\/pdf\/MAI-Cyber-1-Flash-Model-Card.pdf\" target=\"_blank\">model card<\/a>, MAI-Cyber-1-Flash is a sparse mixture-of-experts transformer with 137 billion total parameters, five billion active parameters, and a 256,000-token context window. It is a cybersecurity fine-tune of <a href=\"https:\/\/microsoft.ai\/pdf\/MAI-Code-1-Flash-Model-Card.PDF\" target=\"_blank\">MAI-Code-1-Flash<\/a>, which was developed from a MAI-Thinking-1 mid-training checkpoint.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgazmP6BMN3M57ye7u-mMY9xJnDCbSof-iyyabOuYZED1wVlWfpc0AcS0ne_SOeGhZaQe3vCkusr4IZRLCo35JTOXTjvtzEF16gW_kc9xq41LNb8zgqnlDir9P121HsDnSEy9AheqiqBSwRZ1Gp_kgVsXfOHQT-axfciZF0bB8rI25dEgmMvdfNcgFwnl8\/s1700-e365\/cybergym.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgazmP6BMN3M57ye7u-mMY9xJnDCbSof-iyyabOuYZED1wVlWfpc0AcS0ne_SOeGhZaQe3vCkusr4IZRLCo35JTOXTjvtzEF16gW_kc9xq41LNb8zgqnlDir9P121HsDnSEy9AheqiqBSwRZ1Gp_kgVsXfOHQT-axfciZF0bB8rI25dEgmMvdfNcgFwnl8\/s1700-e365\/cybergym.jpg\" alt=\"\" border=\"0\" data-original-height=\"637\" data-original-width=\"1037\"\/><\/a><\/div>\n<p>The model card says the evaluated configuration replaced 80% of MDASH&#8217;s existing models and raised the reported CyberGym result from 88.4% to 95.95%. That 80% figure is the share of models replaced. The separate 90% figure is the maximum share of tasks Microsoft says the smaller model can handle.<\/p>\n<p>Taken together, the disclosed design points to routing as the central technical claim: MAI-Cyber-1-Flash is intended to handle most tasks, GPT-5.4 takes the hardest remainder, and Microsoft reports the outcome at the MDASH system level.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj-0pDwWk82TIHOE4kinFAkFjZZvfAGWYr9H6PAEItaQNVkiresTVbsYlFHq8lTxSIMv8D1W0A27P4ebbNIIyUP7kJ2xFtJmLFr4bNDQd2lxpZuh2pJEBoYHuQBfjqyLvDWpR4_0kbEt51nmyM1WbfqMrF5drDa7M8n7_qO3eC1p4L0p3lAH3JipQbPpVA\/s1700-e365\/CyberGym-ms.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj-0pDwWk82TIHOE4kinFAkFjZZvfAGWYr9H6PAEItaQNVkiresTVbsYlFHq8lTxSIMv8D1W0A27P4ebbNIIyUP7kJ2xFtJmLFr4bNDQd2lxpZuh2pJEBoYHuQBfjqyLvDWpR4_0kbEt51nmyM1WbfqMrF5drDa7M8n7_qO3eC1p4L0p3lAH3JipQbPpVA\/s1700-e365\/CyberGym-ms.jpg\" alt=\"\" border=\"0\" data-original-height=\"693\" data-original-width=\"1382\"\/><\/a><\/div>\n<p>Microsoft&#8217;s <a href=\"https:\/\/microsoft.ai\/news\/introducing-mai-cyber-1-flash-inside-mdash\/\" target=\"_blank\">launch announcement<\/a> defines the 50% saving against its current best MDASH model mix of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. The product page separately describes the system as delivering \u00abcomparable performance at 50% of the cost of leading models.\u00bb The announcement and model card do not disclose the token use, call volume, latency, task mix, or compute allocation behind that comparison, so the figure cannot yet be independently reproduced or normalised against other systems.<\/p>\n<p>\u00abThe model is one input, the system around it is the product.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thn.news\/sygnia-webinar\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh3-o9La7DYm6jz5qcavVBLvRXUoQLqwrMmrvB529PbUxdg7TJZS3BMjVi4D7vd6V9vlSf_OX48mmXQWPgah_SPITaGgg4AP9YxB2AH-63YeWU39N3DXadwc_2zjIpTwCt0iyTdPZIM-KzKhDf_JDPWDGu3IbYfi1ilQE8Ly29HiKYagSIur-il4k7MMNv8\/s728-e100\/sygnia-d-3.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Taesoo Kim, Microsoft&#8217;s vice president of agentic security, used that distinction when <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/06\/17\/beyond-the-benchmark-advancing-security-at-ai-speed\/\" target=\"_blank\">describing MDASH in June<\/a>. Under a lightweight terminal harness, the model card reports scores of 0.314 on CVEBench, 0.553 on CyberSecEval4 threat intelligence, 0.33 on its malware-analysis test, and 0.651 on CRSBench at POV=1200.<\/p>\n<p>The model scored zero across the kernel, userspace, and browser categories of <a href=\"https:\/\/www.cybergym.io\/exploitgym\/\" target=\"_blank\">ExploitGym<\/a>, which asks agents to turn supplied vulnerabilities and crashing inputs into working code-execution exploits. Those results come from different tasks and scoring scales, so none is a standalone CyberGym score for MAI-Cyber-1-Flash.<\/p>\n<p>Microsoft said all benchmark testing took place in a network-isolated environment with no access to production systems, the public internet, or external services. The model card also warns that generated text and code may be inaccurate or incomplete and should be reviewed before consequential use.<\/p>\n<p>Software vulnerability management using MAI-Cyber-1-Flash inside MDASH is the first scenario Microsoft has announced for Project Perception, its broader system for coordinating defensive security agents. <a href=\"https:\/\/blogs.microsoft.com\/blog\/2026\/07\/27\/rethinking-security-for-the-age-of-ai\/\" target=\"_blank\">Project Perception<\/a> is scheduled to enter public preview on August 3, with Microsoft planning to extend the model beyond software vulnerability work to additional security workflows.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Swati Khandelwal\ue802Jul 28, 2026AI Security \/ Vulnerability Management Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2035,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[845,490,2752,434,1657,147,111],"class_list":["post-2034","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-cost","tag-cybersecurity","tag-helps","tag-hit","tag-mdash","tag-microsoft","tag-model"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2034","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2034"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2034\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2035"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2034"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2034"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2034"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}