{"id":905,"date":"2026-05-13T14:38:00","date_gmt":"2026-05-13T14:38:00","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=905"},"modified":"2026-05-13T14:38:00","modified_gmt":"2026-05-13T14:38:00","slug":"microsofts-mdash-ai-system-finds-16-windows-flaws-fixed-in-patch-tuesday","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=905","title":{"rendered":"Microsoft&#8217;s MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">May 13, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Artificial Intelligence<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg1Iq16GS3jdGiIU24GHBkwg6unk05ctdgYwXO5df8zRu1qko95_XhszCjq6jlEIRozLsrtZHgi5GqDZnS1Sw_KDzUzsagwP0If3VswmYHsnuYwVseU2lapxQiPpItTdAiv-CCdTFR87ZVOu65buyvmvzmdWuJPKHuPA4DSo58HQIMAV__2ymsmRe2g3UVe\/s1700-e365\/windows-ai.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Microsoft has unveiled a new multi-model artificial intelligence (AI)-driven system called <strong>MDASH<\/strong> to facilitate vulnerability discovery and remediation at scale, adding that it&#8217;s being tested by some customers as part of a limited private preview.<\/p>\n<p>MDASH, short for <strong>m<\/strong>ulti-mo<strong>d<\/strong>el <strong>a<\/strong>gentic <strong>s<\/strong>canning <strong>h<\/strong>arness, is designed as a model-agnostic system that uses bespoke AI agents for different vulnerability classes to autonomously discover, validate, and prove exploitable defects in complex codebases like Windows.<\/p>\n<p>\u00abUnlike single-model approaches, the harness orchestrates more than 100 specialized AI agents across an ensemble of frontier and distilled models to discover, debate, and prove exploitable bugs end-to-end,\u00bb Taesoo Kim, vice president of agentic security at Microsoft, <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/05\/12\/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-tops-leading-industry-benchmark\/\">said<\/a>.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlabz-vpn-risk-2026-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhnNON5UeWywT7OcPNw7V4L7QNWnCnm7Xl_99Y9ek8dL-gRwx-bWxQM1TKqt8deqqrdpUyKMuuijAWyyPQVB0s0qf8ntQ6ldFAJLru-QUWhddKTopc7SeNbBBnd-TsfFyRPP-AAyDuclLlL6XHK4_LXqDC_7eyaz9pzToYr7U543MhrJ7qcK-89sVWHTQUZ\/s728-e100\/zz-2-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>MDASH is envisioned as a \u00abstructured pipeline\u00bb that ingests a codebase and produces validated, proven findings through a series of actions.<\/p>\n<p>It starts with analyzing the source code to build a threat model and attack surface, running specialized \u00abauditor\u00bb agents over candidate code paths to flag potential issues, running a second set of \u00abdebater\u00bb agents that validate the findings, grouping semantically equivalent findings, and then finally proving the existence of the vulnerabilities.<\/p>\n<p>The system is powered by a configurable panel of models, with state-of-the-art (SOTA) models used for reasoning, distilled models for validation for high-volume passes, and a second separate SOTA model for independent counterpoint.<\/p>\n<p>\u00abDisagreement between models is itself a signal: when an auditor flags something as suspect and the debater can&#8217;t refute it, that finding\u2019s posterior credibility goes up,\u00bb Microsoft explained. \u00abAn auditor does not reason like a debater, which does not reason like a prover. Each pipeline stage has its own role, prompt regime, tools, and stop criteria.\u00bb<\/p>\n<p>Redmond noted that the specialized agents have been constructed based on past common vulnerabilities and exposures (CVEs) and their patches. It also said the architecture allows for portability across model generations.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhH6N60CGLSE6IAFBHjgwPACpNx54RIaa2nfqXvq41uLiHcHX20E2GLFzzM9zqCC5aceI8GB9qk7w675a-dy32FQaJsZNW84kPt-1NpAuwhqxTpC-P-DRNYeBBYLni_D4I3WyZhVqznHU4fYlTWUDJHw7kgPHnTAxSc9wKqt6DV2vTkwlSLdITRIO4H4hR6\/s1700-e365\/cyber-ms.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhH6N60CGLSE6IAFBHjgwPACpNx54RIaa2nfqXvq41uLiHcHX20E2GLFzzM9zqCC5aceI8GB9qk7w675a-dy32FQaJsZNW84kPt-1NpAuwhqxTpC-P-DRNYeBBYLni_D4I3WyZhVqznHU4fYlTWUDJHw7kgPHnTAxSc9wKqt6DV2vTkwlSLdITRIO4H4hR6\/s1700-e365\/cyber-ms.jpg\" alt=\"\" border=\"0\" data-original-height=\"900\" data-original-width=\"1600\"\/><\/a><\/div>\n<p>MDASH has already been put to test, unearthing 16 of the vulnerabilities that were fixed in this month&#8217;s Patch Tuesday release. The shortcomings span across the Windows networking and authentication stack, including two critical flaws that could pave the way for remote code execution &#8211;<\/p>\n<ul>\n<li><strong><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2026-33824\">CVE-2026-33824<\/a><\/strong> (CVSS score: 9.8) &#8211; A double-free vulnerability in \u00abikeext.dll\u00bb that could allow an unauthenticated attacker to send specially crafted packets to a Windows machine with Internet Key Exchange (IKE) version 2 enabled, leading to remote code execution.<\/li>\n<li><strong><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2026-33827\">CVE-2026-33827<\/a><\/strong> (CVSS score: 8.1) &#8211; A race condition vulnerability in Windows TCP\/IP (\u00abtcpip.sys\u00bb) that allows an unauthorized attacker to send a specially crafted IPv6 packet to a Windows node where IPSec is enabled, leading to remote code execution exploitation.<\/li>\n<\/ul>\n<p>News of MDASH follows the debut of Anthropic&#8217;s Project Glasswing and OpenAI Daybreak, both of which are AI-powered cybersecurity initiatives for accelerating vulnerability discovery, validation, and remediation before they can be discovered by bad actors.<\/p>\n<p>\u00abThe strategic implication is clear: AI vulnerability discovery has crossed from research curiosity into production-grade defense at enterprise scale, and the durable advantage lies in the agentic system around the model rather than any single model itself,\u00bb Kim said.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802May 13, 2026Vulnerability \/ Artificial Intelligence Microsoft has unveiled a new multi-model artificial intelligence (AI)-driven system called MDASH to facilitate vulnerability discovery and remediation at scale, adding that it&#8217;s&hellip;<\/p>\n","protected":false},"author":1,"featured_media":906,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[509,1658,11,1657,1656,348,1045,349,307],"class_list":["post-905","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-finds","tag-fixed","tag-flaws","tag-mdash","tag-microsofts","tag-patch","tag-system","tag-tuesday","tag-windows"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/905","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=905"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/905\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/906"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=905"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=905"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=905"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}