MAI-Cyber-1-Flash Reduces Microsoft’s MDASH Costs by 50%


MAI-Cyber-1-Flash
Image credit: Microsoft

Microsoft has announced MAI-Cyber-1-Flash, its first internally developed AI model built specifically for cybersecurity tasks.

The company has integrated the model into MDASH, its multi-agent system for detecting vulnerabilities, verifying findings, developing fixes, and validating security patches. Microsoft says the updated configuration delivers strong performance at around half the cost of its current leading setup.

Microsoft targets faster vulnerability detection

MAI-Cyber-1-Flash focuses on finding difficult security flaws in large and complex codebases.

Microsoft argues that AI gives attackers faster and cheaper ways to search software for weaknesses. As a result, occasional security scans and delayed patching may no longer provide enough protection.

The company wants systems such as MDASH to continuously identify vulnerabilities, confirm their impact, and help developers address them before attackers can exploit them.

MDASH assigns models based on task difficulty

Microsoft designed MAI-Cyber-1-Flash to handle up to 90% of MDASH security tasks efficiently.

MDASH can reserve more powerful and expensive models, including GPT-5.4, for the most difficult 10% of cases. This approach allows the system to match each task with an appropriate model while reducing token and operating costs.

Microsoft says the configuration costs 50% less than its current combination of GPT-5.4, GPT-5.4 Mini, and GPT-5.3 Codex.

MAI-Cyber-1-Flash comes from Microsoft’s MAI-Thinking-1 model family. The compact, code-focused model uses security and software data selected for vulnerability research and remediation work.

CyberGym results reach approximately 96%

MDASH achieved an approximately 96% score on the CyberGym benchmark after Microsoft added MAI-Cyber-1-Flash.

Microsoft says this result places the system 12 percentage points above Anthropic’s Mythos. The company also claims MDASH outperformed competing systems that rely on Gemini and GPT models.

MDASH coordinates more than 100 specialized AI agents. These agents can:

  • Search code for vulnerabilities
  • Verify and deduplicate findings
  • Generate supporting evidence
  • Develop possible fixes
  • Test and validate patches

MDASH can also send vulnerability-scanning results to Project Perception, Microsoft’s system for continuous organizational monitoring and defense.

Microsoft adds enterprise security controls

Microsoft says its AI Red Team evaluated MAI-Cyber-1-Flash during development. The company also used automated adversarial testing, internal security reviews, and an independent third-party assessment.

MDASH includes role-based access controls, tenant isolation, encryption, auditing, and sandboxed environments without internet access.

Microsoft has not announced whether MAI-Cyber-1-Flash will become available as a standalone model outside MDASH.

More about the topics: AI, microsoft, security

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages