Microsoft is preparing to launch a new product that uses artificial intelligence to automatically detect and fix software vulnerabilities. Seen as a direct challenger to Anthropic’s cybersecurity-focused model “Claude Mitos,” the move signals an aggressive pivot toward AI in Microsoft’s security business strategy.
According to a report published on the 16th (local time) by U.S. tech publication The Information, Microsoft’s forthcoming product will simultaneously leverage multiple AI models to analyze software code and identify bugs. After verifying the root cause of detected flaws, the system is expected to automatically generate remediation code.
The core technology powering this product is widely believed to be “MDASH,” Microsoft’s internally developed AI-based vulnerability detection system. MDASH combines high-performance reasoning models with cost-efficient lightweight models to perform tasks such as code scanning, vulnerability verification, and deduplication. A key feature is its ability to significantly boost detection speed and accuracy while reducing dependency on any single AI model.
Microsoft previously disclosed that it used MDASH to discover 16 new vulnerabilities in Windows network and authentication systems. These technical achievements are seen as the foundation for the new product launch.
The new offering is expected to compete head-to-head with Anthropic’s Claude Mitos. Mitos is currently available only on a limited basis to select vetted enterprises and institutions, given its potential for misuse. If Microsoft pursues the market with a broadly accessible product, it could create a differentiated competitive dynamic against Mitos’s closed distribution model.
Major Organizational Restructuring and AI Security Focus
The product launch preparations coincide with a sweeping restructuring of Microsoft’s security business unit. As The Information reported on the 15th, Hayete Gallot, Corporate Vice President overseeing Microsoft’s security division, has replaced at least nine Corporate Vice President-level executives in the roughly five months since assuming her role in February. She also executed an organizational overhaul that included laying off several hundred employees from the division’s total workforce of approximately 10,000.
Under the reshuffle, teams responsible for traditional security products were scaled back, while teams dedicated to AI security products were expanded. In an internal message, Gallot acknowledged that “the last few months have been a difficult period” and emphasized that “times like these require clarity, conviction, and focus.” She added that “the entire industry is being reshaped from the ground up” and stressed that “Microsoft is in a favorable position to deliver results through the proliferation of AI.”
Changes to the security business’s sales model are also anticipated. Gallot is reported to hold a negative view of Microsoft’s long-standing practice of bundling security features into enterprise software packages. As a result, the company is reportedly exploring the option of unbundling security features and selling them as standalone products.
AI Reshapes the Security Paradigm
Microsoft’s moves are driven by the growing need to fundamentally reorganize traditional human-centric security frameworks, as AI proves capable of detecting software vulnerabilities with greater speed and precision. On the 14th, Microsoft deployed a regular update that fixed 570 security flaws across its product suite, including Windows and Office, in a single release — the largest number of vulnerabilities ever addressed in one Microsoft security update.
The AI security automation tool MDASH, championed by Gallot, was utilized in this process. Since its introduction, MDASH has been credited with dramatically improving vulnerability detection speed. As top-tier AI models achieve vulnerability detection capabilities comparable to security experts, the industry is witnessing an accelerating shift from periodic human-led assessments and patch deployments to a system of continuous AI-driven detection and rapid remediation.
This trend extends beyond Microsoft. Apple, which previously bundled security updates with operating system overhauls, has also shifted its policy toward more frequent releases with shorter cycles. As the potential for AI to be weaponized for cyberattacks grows alongside the increasing efficiency of defensive technologies, the workforce and business structures of the global security industry are poised for rapid transformation.
The Information projects that Microsoft’s new product will compete directly with Anthropic’s Claude Mitos. If Microsoft can deliver an integrated AI security tool built on its vast software ecosystem and cloud infrastructure, it could wield significant influence in the enterprise security market.