Microsoft has unveiled MDASH, a cybersecurity system powered by more than 100 AI agents that work together to uncover software vulnerabilities. The company says the platform discovered 16 previously unknown Windows flaws and outperformed rivals including Anthropic’s Mythos and OpenAI’s GPT-5.5 on a major industry benchmark.
For the last few years, cybersecurity experts warned that artificial intelligence would eventually become good enough to hunt software vulnerabilities faster than humans. That future now appears to be arriving, and Microsoft wants to be the company leading it rather than reacting to it.
This week, the tech giant revealed a new internally developed system called MDASH, short for “multi-model agentic scanning harness”, a sprawling network of specialised AI agents designed to identify security flaws in software code. Unlike conventional AI systems that rely on a single large model, MDASH functions more like a coordinated cyber investigation team, with dozens of AI agents handling different stages of vulnerability detection simultaneously.
STORY CONTINUES BELOW THIS AD
Our new multi-model agentic security system brings together more than 100 specialized agents across frontier and custom models to find exploitable bugs, delivering top performance on the CyberGym benchmark.
We used it ahead of Patch Tuesday to help find and fix 16…
— Satya Nadella (@satyanadella) May 13, 2026
The announcement was not just theoretical. Microsoft said the system had already uncovered 16 previously unknown vulnerabilities across Windows systems, including four critical remote code execution flaws affecting components such as the Windows kernel TCP/IP stack and the IKEv2 service. The vulnerabilities were patched as part of this month’s Patch Tuesday security updates.
Why Microsoft is betting on AI teams instead of one giant model
The most interesting part of MDASH is not simply that it found vulnerabilities, but how it found them.
Microsoft’s approach leans heavily into the idea that cybersecurity may require multiple AI systems working together instead of one highly capable model doing everything alone. The company built MDASH as a pipeline of specialised agents, each responsible for a different task in the vulnerability discovery process.
One group scans software code searching for suspicious behaviour. Another set evaluates whether the findings are genuine security risks or harmless anomalies. A final stage attempts to build proof-of-concept exploits to confirm whether the bug can actually be triggered in practice.
That collaborative structure appears to have given Microsoft an edge on CyberGym, a benchmark created by researchers at the University of California, Berkeley. The benchmark measures how effectively AI systems can reproduce real-world vulnerabilities using unpatched software projects.
Microsoft said MDASH achieved an 88.45 per cent score on the benchmark, outperforming Anthropic’s cybersecurity-focused Mythos Preview model, which scored 83.1 per cent. Anthropic OpenAI GPT-5.5 followed with 81.8 per cent.
STORY CONTINUES BELOW THIS AD
The results, however, remain self-reported by the participating companies, and no independent organisation has formally verified the rankings.
The growing fear around AI-powered hacking
The rapid progress also raises uncomfortable questions for the cybersecurity industry.
The same AI systems capable of discovering vulnerabilities for defensive purposes can just as easily be adapted for offensive cyberattacks. Researchers have increasingly warned that AI may drastically reduce the time required for attackers to identify exploitable weaknesses in widely used software.
Anthropic’s Mythos already triggered debate earlier this year after demonstrating advanced vulnerability discovery and exploitation capabilities. Access to the model was restricted through a limited consortium known as
Project Glasswing, which notably includes Microsoft itself.
Now Microsoft appears to be signalling that vulnerability discovery at machine speed may soon become normal inside enterprise security operations.
The company said MDASH will initially remain an internal tool for Microsoft’s security engineering teams before expanding into a limited private preview for selected customers.
Microsoft also hinted that organisations should prepare for larger and more frequent security updates in the future as AI accelerates the pace of vulnerability discovery. For an industry already struggling to patch systems quickly enough, that warning may prove just as significant as the benchmark scores themselves.
STORY CONTINUES BELOW THIS AD
First Published:
May 14, 2026, 08:03 IST
HomeTechMicrosoft debuts MDASH, an AI cyber system that beats Claude Mythos on security testsEnd of Article