Microsoft has unveiled MAI-Cyber-1-Flash, its first specialized cybersecurity AI model, integrated into the MDASH multi-agent vulnerability identification system as part of the company’s broader Project Perception agentic security platform.
Testing on the CyberGym cybersecurity evaluation framework showed that MAI-Cyber-1-Flash combined with MDASH and GPT-5.4 outperformed Google’s Gemini 3.5 Flash Cyber, OpenAI’s GPT-5.6 Sol, and Anthropic’s Mythos 5 in vulnerability discovery. The model is designed to handle approximately 90% of vulnerability identification tasks efficiently, reserving larger frontier models for the most challenging 10%.
“This combination delivers a 50% cost saving when compared against our best offering in MDASH today,” Microsoft stated. The model was built specifically to identify challenging vulnerabilities in complex codebases and has already been used internally to find numerous flaws in Microsoft’s own software.
MAI-Cyber-1-Flash is the first output of Project Perception, Microsoft’s new agentic security platform that coordinates three classes of specialized red, blue, and green team agents in a closed-loop system. Red team agents simulate attacks, blue team agents investigate and triage threats, and green team agents remediate issues.
Project Perception enters public preview on August 3. Microsoft described the platform as built for “the age of AI,” where autonomous systems can reason, adapt, and operate continuously against machine-speed attacks.
