Microsoft announced its first cybersecurity-specific model and new AI cybersecurity platform at a small event in San Francisco on Monday, giving it a big win over the major players in the space: Anthropic, Google, and OpenAI.
The company describes MAI-Cyber-1-Flash as a model built “to find difficult vulnerabilities in complex codebases.” This model is built to animate MDASH, Microsoft’s harness dedicated to identifying and remediating software vulnerabilities.
The new security platform is called Perception and is designed to deploy a team of agents to assist and automate various security workflows, including identifying and remediating bugs. This platform can also be integrated with MDASH.
The company claims MAI-Cyber-1-Flash is significantly more powerful (and more cost-effective) than competing models based on its performance on established AI cybersecurity benchmarks.
Mustafa Suleiman, co-founder of DeepMind and current CEO of Microsoft AI, said: “We use MAI-1 Cyber Flash bound to GPT 5.4 within the MDASH harness. It outperforms Gemini, GPT 5.5 Cyber, GPT 5.6 Sol, and Cybergym’s Mythos 5. It’s the primary benchmark we all use. It’s the golden benchmark.”
“We’ll be shipping this into production soon,” he added.
Hayete Gallot, vice president of security at Microsoft, noted that hackers are increasingly using AI in cyberattacks, and said Perception is a way for enterprise defenders to “defend against AI using AI at the scale and speed of attackers.”
Perception uses red, blue, and green teams of agents. Red Teaming provides detailed simulations of potential attacks and provides context about potential threat actors and the vulnerabilities they might exploit. The blue team focuses on detecting and prioritizing existing bugs, while the green team takes “corrective actions” against those bugs.
Dave Weston, principal engineer at Perception, described the platform as a significant efficiency upgrade for enterprise defenders. “We spent hours of manual effort from multiple expert staff across our security organization (appsec hunters, remediation engineers, etc.) to resolve this issue, and we were able to fix all of this in minutes. We not only discover and prioritize issues, we also detect, remediate state, and even remediate code.”
While AI has provided businesses with new defensive capabilities, the availability of AI to cybercriminals has created a surprising number of potential threats.
Microsoft’s new security tools will be available for preview on November 3, the company has announced, entering the increasingly crowded field of AI cybersecurity solutions. Earlier this year, Anthropic launched Mythos, a security platform released to small partner organizations through a program called Glasswing. OpenAI also announced its own security solution in May through a program called Daybreak.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.
