Microsoft has launched its first specialized cybersecurity AI model, MAI-Cyber-1-Flash, and integrated it into the MDASH vulnerability detection system.
According to company executives, this model outperforms both Mythos 5 and GPT-5.5-Cyber while being 50% more cost-effective than the previous MDASH configuration, which included GPT-5.4, 5.4-Mini, and 5.3-Codex.
In the CyberGym benchmark, the model achieved an impressive score of 95.95%. This benchmark challenges AI agents to replicate 1,507 known vulnerabilities across 188 open-source projects, evaluating them based on the percentage of successfully reproduced errors in a controlled environment.
The results positioned MDASH ahead of GPT-5.5-Cyber (85.6%), Mythos 5 (83.8%), and GPT-5.6 Sol (83.6%). However, these findings have not yet been published in a public ranking.
Source: Microsoft.Microsoft emphasizes that MAI-Cyber-1-Flash employs a hybrid approach, handling up to 90% of tasks independently while directing the remaining 10% of the more complex tasks to GPT-5.4, which is significant for token savings.
MDASH utilizes over 100 specialized AI agents tasked with code auditing, verifying findings, and creating Proof-of-Concepts to demonstrate the presence of vulnerabilities.
According to Microsoft CEO Satya Nadella, this marks the first instance where an optimized LLM from Microsoft has achieved such high efficiency:
“Combined with MDASH, the MAI-Cyber-1-Flash model delivers world-class performance at 50% of the cost of leading models.”
Initially, MDASH is available to a limited number of users through the Microsoft Security Exposure Management service on the Defender portal. Clients can scan GitHub repositories, analyze identified vulnerabilities ranked from "unlikely" to "confirmed," and use Defender CLI to automatically generate code fix suggestions, which are then sent to developers for review.
It is worth noting that infrastructure risks related to OpenAI and Anthropic were highlighted in July.
