{"id":121855,"date":"2026-07-28T19:38:22","date_gmt":"2026-07-28T19:38:22","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/121855\/"},"modified":"2026-07-28T19:38:22","modified_gmt":"2026-07-28T19:38:22","slug":"mai-cyber-1-flash-microsoft-targets-vulnerability-scanning-costs","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/121855\/","title":{"rendered":"MAI-Cyber-1-Flash: Microsoft targets vulnerability scanning costs"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Microsoft has released MAI-Cyber-1-Flash, a security model built into <a href=\"https:\/\/learn.microsoft.com\/en-us\/security-exposure-management\/ai-code-security-overview\" rel=\"nofollow noopener\" target=\"_blank\">MDASH<\/a> that finds vulnerabilities at half the cost of alternatives.<\/p>\n<p class=\"wp-block-paragraph\">Redmond announced the model alongside Perception \u2013 a set of security agents \u2013 in a joint post from Mustafa Suleyman, CEO of Microsoft AI, and Hayete Gallot, Executive VP of Microsoft Security. The pairing targets a problem brewing for a while: the volume of code needing review has outpaced the budget available to review it.<\/p>\n<p class=\"wp-block-paragraph\">Suleyman and Gallot describe attackers using AI to probe growing codebases for a single flaw, and argue the response has to change with it. \u201cThe old model of security, where you scan occasionally and patch eventually, is now obsolete,\u201d they write.<\/p>\n<p class=\"wp-block-paragraph\">Running frontier models against every line of code in an enterprise repository gets expensive at scale, and Microsoft says computation cost \u2013 not model availability \u2013 now limits how much scanning defenders can afford to run.<\/p>\n<p>A cheaper model does most of the work, a bigger one covers the rest<\/p>\n<p class=\"wp-block-paragraph\">MAI-Cyber-1-Flash handles up to 90 percent of vulnerability-finding tasks inside MDASH, according to Microsoft. The remaining share, described as exceptionally hard cases, gets routed to GPT-5.4, the larger model Microsoft already runs inside the harness.<\/p>\n<p class=\"wp-block-paragraph\">That routing arrangement is the mechanism behind the cost claim. MDASH now defaults to the cheaper model and escalates only when a task exceeds it.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft says the combined system scores 96 percent on CyberGym, a benchmark it describes as the standard for evaluating how models reason over large codebases to find real vulnerabilities in code. That figure sits 12 points above Anthropic\u2019s Mythos, one of the systems Microsoft names alongside Gemini and GPT as competitors. Microsoft also claims the setup delivers a 50 percent cost saving against its previous best MDASH configuration, a combination of GPT-5.4, 5.4 Mini, and 5.3 Codex.<\/p>\n<p class=\"wp-block-paragraph\">CyberGym scores, cost comparisons, and the 90\/10 routing split all come from Microsoft\u2019s own testing on its own infrastructure. Synthetic vulnerability sets built for benchmarking behave differently from a live codebase carrying incomplete documentation, stale dependencies, and years of accumulated patch history. A model that reasons well over benchmark code doesn\u2019t automatically reason well over a decade-old internal repository nobody has fully documented.<\/p>\n<p>Finding a flaw and fixing it are different jobs<\/p>\n<p class=\"wp-block-paragraph\">Microsoft is also launching Perception, a set of security agents built to work alongside MAI-Cyber-1-Flash inside MDASH. The model\u2019s job is identification.<\/p>\n<p class=\"wp-block-paragraph\">Perception handles what comes after: monitoring, patching, and closing threat vectors once a vulnerability turns up. Microsoft says Perception will extend to cover more security workflows beyond software vulnerability work, though the company hasn\u2019t given a timeline for that expansion.<\/p>\n<p class=\"wp-block-paragraph\">Finding a flaw faster doesn\u2019t help much if the remediation queue behind it stays backed up. Microsoft\u2019s own post acknowledges as much, noting that \u201cthere are many jobs to be done by security practitioners themselves\u201d even as AI remediation becomes a routine part of the workflow.<\/p>\n<p class=\"wp-block-paragraph\">Because MAI-Cyber-1-Flash is Microsoft\u2019s first purpose-built cyber model, the company has attached a heavier governance layer than it typically discloses for general-purpose releases.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft says the model went through evaluation by its internal AI Red Team, automated and expert-led adversarial testing, and an assessment from an unnamed third party. MDASH deployment adds role-based access controls, tenant isolation, encryption, audit logging, and sandboxed execution environments without internet access, according to the company.<\/p>\n<p class=\"wp-block-paragraph\">Security leaders adopting this kind of tooling still need to run their own validation rather than rely on vendor testing alone. A model with access to internal repositories and remediation permissions can widen the attack surface it\u2019s meant to shrink.<\/p>\n<p>The data Microsoft says can\u2019t be replicated<\/p>\n<p class=\"wp-block-paragraph\">Model architecture and harness tuning explain part of the performance claim. Microsoft says the bigger factor is data: more than 100 trillion telemetry events collected daily across identity, endpoint, cloud, and network layers \u2013 drawn from a base of 1.6 million customers \u2013 plus a record of real exploits and the remediations that followed them. That combination of attack data and outcome data, Microsoft argues, is what separates its models from competitors training on public code repositories alone.<\/p>\n<p class=\"wp-block-paragraph\">MAI-Cyber-1-Flash descends from the MAI-Thinking-1 lineage, built in-house rather than adapted from an existing open or licensed model, according to Microsoft\u2019s technical report on the release.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft frames the training approach as a \u201clive reinforcement learning loop\u201d rather than a static dataset: defenders triage alerts, remediate flaws, and deploy protections, and the outcomes feed back into model training on an ongoing basis.<\/p>\n<p class=\"wp-block-paragraph\">The cost argument is the most attractive part of the pitch and the hardest to verify independently. Microsoft\u2019s 50 percent saving figure compares its own new configuration against its own old one, not against a competitor\u2019s pricing.<\/p>\n<p class=\"wp-block-paragraph\">The bigger operational question is how the 90\/10 routing behaves on a codebase Microsoft hasn\u2019t seen before. CyberGym testing happens under controlled conditions. A production repository with legacy code, undocumented dependencies, and inconsistent patch histories will likely push a higher share of tasks toward the expensive escalation tier than the benchmark suggests.<\/p>\n<p class=\"wp-block-paragraph\">MAI-Cyber-1-Flash is available now inside MDASH for customers already running Microsoft\u2019s security stack, with Perception rolling out as a companion set of agents for the patching and monitoring work the identification model doesn\u2019t cover.<\/p>\n<p class=\"wp-block-paragraph\">See also: <a href=\"https:\/\/www.developer-tech.com\/news\/open-secure-ai-alliance-open-source-ai-security-defences\/\" rel=\"nofollow noopener\" target=\"_blank\">Open Secure AI Alliance aims to open-source AI security defences<\/a><\/p>\n<p><a href=\"https:\/\/cybersecuritycloudexpo.com\/?utm_source=CloudTech-News&amp;utm_medium=Footer-banner&amp;utm_campaign=world-series\" rel=\"nofollow noopener\" target=\"_blank\"><img fetchpriority=\"high\" decoding=\"async\" width=\"728\" height=\"90\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/cyber-security-expo.png\" alt=\"Banner for Cyber Security Expo by TechEx events.\" class=\"wp-image-109966\" style=\"width:800px;height:auto\"  \/><\/a><\/p>\n<p class=\"wp-block-paragraph\">Want to learn more about cybersecurity from industry leaders? Check out <a href=\"https:\/\/cybersecuritycloudexpo.com\/?utm_source=CloudTech-News&amp;utm_medium=Footer-banner&amp;utm_campaign=world-series\" rel=\"nofollow noopener\" target=\"_blank\">Cyber Security &amp; Cloud Expo<\/a> taking place in Amsterdam, California, and London. The comprehensive event is part of <a href=\"https:\/\/techexevent.com\/?utm_source=CloudTech-News&amp;utm_medium=Footer-banner&amp;utm_campaign=world-series\" rel=\"nofollow noopener\" target=\"_blank\">TechEx<\/a> and is co-located with other leading technology events including the <a href=\"https:\/\/www.ai-expo.net\/?utm_source=AI-News&amp;utm_medium=Footer-banner&amp;utm_campaign=world-series\" rel=\"nofollow noopener\" target=\"_blank\">AI &amp; Big Data Expo<\/a>. Click <a href=\"https:\/\/techexevent.com\/?utm_source=CloudTech-News&amp;utm_medium=Footer-banner&amp;utm_campaign=world-series\" rel=\"nofollow noopener\" target=\"_blank\">here<\/a> for more information.<\/p>\n<p class=\"wp-block-paragraph\">Developer is powered by <a href=\"https:\/\/techforge.pub\/?utm_source=cloud-News&amp;utm_medium=Footer-banner&amp;utm_campaign=world-series\" rel=\"nofollow noopener\" target=\"_blank\">TechForge Media<\/a>. Explore other upcoming enterprise technology events and webinars <a href=\"https:\/\/techforge.pub\/events\/?utm_source=cloud-News&amp;utm_medium=Footer-banner&amp;utm_campaign=world-series\" rel=\"nofollow noopener\" target=\"_blank\">here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"Microsoft has released MAI-Cyber-1-Flash, a security model built into MDASH that finds vulnerabilities at half the cost of&hellip;\n","protected":false},"author":2,"featured_media":121856,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[4077,24,1276,420,7829,20394,9604,313,8921,11380,3888,23641,320,7828,314,291,16487,9578],"class_list":["post-121855","post","type-post","status-publish","format-standard","has-post-thumbnail","category-microsoft","tag-agents","tag-ai","tag-ai-models","tag-azure","tag-azure-ai","tag-code-review","tag-cybergym","tag-cybersecurity","tag-devsecops","tag-gpt","tag-infosec","tag-mdash","tag-microsoft","tag-microsoft-ai","tag-security","tag-threat-detection","tag-vulnerability-scanning","tag-zero-trust"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/121855","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=121855"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/121855\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/121856"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=121855"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=121855"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=121855"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}