Skip to content

Microsoft cyber model hits 96% on CyberGym while halving MDASH cost

Original: Introducing MAI-Cyber-1-Flash inside MDASH View original →

Read in other languages: 한국어日本語
AI Jul 28, 2026 By Insights AI 2 min read 1 views Source

The security model race is shifting from raw frontier size to cheaper specialization and routing. Microsoft’s July 27 release of MAI-Cyber-1-Flash inside MDASH puts a hard number on that bet: the company says the combined system scores 95.95% on CyberGym and costs about 50% less than its current MDASH configuration.

MAI-Cyber-1-Flash is not being framed as a standalone assistant. Microsoft built it into MDASH, its multi-agent harness for identifying, analyzing, and remediating software vulnerabilities. The model is designed to handle up to 90% of tasks, while the hardest 10% are escalated to larger and more expensive models such as GPT-5.4. That matters because continuous vulnerability work can become bounded by token economics, not only by model capability.

The benchmark claim is pointed. Microsoft describes CyberGym as a test of how systems reason over large codebases to find real vulnerabilities. Its published chart puts the MDASH configuration with MAI-Cyber-1-Flash and GPT-5.4 at 95.95%, about 12 points above Mythos and ahead of Gemini and GPT comparison systems. The next question is independent reproducibility: security teams will care as much about false positives, missed vulnerabilities, and triage load as about the top-line score.

Microsoft paired the model post with a broader Project Perception launch. Perception is an agentic security system with red agents probing possible attack paths, blue agents investigating risks, and green agents applying remediation and hardening steps. The product page says the system is in preview through Microsoft Defender and keeps humans in control of critical decisions.

The deeper asset is Microsoft’s security data loop. The company says it sees more than 100 trillion security signals each day across identity, endpoint, cloud, network, and other surfaces, plus operational insight from 1.6 million customers. In its telling, MAI-Cyber-1-Flash is improved not just by static training data but by a live reinforcement loop from investigations, remediations, blocked attacks, and observed outcomes.

This is also a dual-use story. A model that can find and reproduce vulnerabilities faster helps defenders, but similar capabilities can compress the attacker’s cost curve. Microsoft points to role-based controls, tenant isolation, encryption, auditability, and sandboxed execution without internet access as guardrails. The real test starts after the August 3 public preview: whether agent teams can reduce exposure time in production systems without adding a new layer of opaque automation risk.

Share: Long

Related Articles