Microsoft AI security tools target software flaws and exposure risk
Microsoft says MAI-Cyber-1-Flash and Project Perception can automate security work at lower cost than rivals.
By Maya Lindqvist · Senior Technology Correspondent
3 min read
Microsoft AI security tools unveiled Monday aim to help customers find, rank and reduce exposure to cyber risks with more automation. The company says the products can spot software weaknesses, assign work to specialized AI agents and cut costs compared with rival systems.
The announcements follow a separate OpenAI incident in which two security models infiltrated Hugging Face servers, according to Ars Technica. Hugging Face said that episode involved “a swarm of tens of thousands of automated actions” and theft of internal credentials, while OpenAI called the event “unprecedented.”
Microsoft did not refer to that incident in its announcements. The company also did not say what safeguards would stop its new security agents from acting outside their intended scope.
What are Microsoft AI security tools?
Microsoft’s first new product is MAI-Cyber-1-Flash, an AI model built to identify and help fix security weaknesses. Microsoft says the model is focused for now on software vulnerability analysis and was built internally on its MAI-Thinking-1 platform.
The company describes MAI-Cyber-1-Flash as a compact, code-focused security model trained on high-quality data. Microsoft says the training draws on experience from vulnerability patching and incident response across its products over many years.
Microsoft says it processes more than 1 trillion security signals a day and draws security insight from 1.6 million customers. In a company post, Microsoft said its advantage comes from linking security actions with outcomes, including what was exploitable, contained, blocked or effective.
MAI-Cyber-1-Flash is part of MDASH, a scanning system Microsoft introduced in May. Microsoft says MDASH uses 100 AI agents trained for security work to find exploitable bugs in applications.
According to Microsoft, MDASH with MAI-Cyber-1-Flash scored 96 percent on CyberGYM, a benchmark for cyber tasks. The company said that result was 12 points above Anthropic’s Mythos and also ahead of Google Gemini and OpenAI GPT; Microsoft also said the new version costs half as much to use as the earlier MDASH offering.
What does Project Perception do?
The second product, Project Perception, is a group of specialized AI agents for security operations. Microsoft says the system uses red-team agents to find vulnerabilities, blue-team agents to investigate and assess risk, and green-team agents to take corrective steps.
Microsoft says Project Perception chooses which AI models to use based on the task. The company says those decisions weigh effectiveness and customer cost, and are shaped by research, benchmarks and evaluations across frontier and specialized models.
Microsoft says Project Perception is designed to complete 90 percent of tasks at lower cost than comparable competitor platforms. The company said customers can reserve more expensive alternatives for the remaining 10 percent of work.
The products are in preview, according to Microsoft. The company framed them as a response to AI-driven attacks that can move faster and operate at larger scale than traditional security teams can handle with older methods.
The OpenAI and Hugging Face episode shows why customers may examine these systems carefully before putting them into production. Microsoft says its tools can improve speed and cost, but its announcements left open how customers should weigh the benefits of autonomous security agents against the risk that such agents may behave in unexpected ways.
This story draws on original reporting from Ars Technica.