Skip to content

Microsoft's First Cybersecurity Model: 90% of Tasks Handled by Self-developed Small Model, Cost Reduced by Half

Jul 28, 09:21

According to DynaRisk Beating Monitoring, Microsoft has released its first self-developed cybersecurity model, MAI-Cyber-1-Flash, and integrated it into the vulnerability scanning system, MDASH. It is a cybersecurity fine-tuned version of MAI-Code-1-Flash, with a total of 137 billion parameters, 50 billion activated per run, supporting a 256K context.

MDASH will enable it to handle up to 90% of vulnerability discovery, validation, classification, and remediation tasks. The most challenging 10% will be passed on to GPT-5.4. Microsoft stated that this combination is nearly 50% cheaper than the existing GPT-5.4, 5.4 mini, and 5.3 Codex solutions.

In Microsoft's disclosed CyberGym testing, "MAI-Cyber-1-Flash + GPT-5.4" scored 95.95%. GPT-5.5 Cyber scored 85.6%, and Anthropic Mythos 5 scored 83.8%. This comparison is between the complete model and Agent combinations and should not be understood as MAI-Cyber-1-Flash single-handedly outperforming these models.

It will also integrate with the security Agent product, Project Perception. The three types of Agents—Red, Blue, and Green—are responsible for vulnerability identification, risk assessment, and fortification. Project Perception is set to begin public testing on August 3rd, but MAI-Cyber-1-Flash is currently only available for private testing to MDASH clients who have passed the audit.

Source