{"id":38117,"date":"2026-05-13T22:54:47","date_gmt":"2026-05-13T22:54:47","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/38117\/"},"modified":"2026-05-13T22:54:47","modified_gmt":"2026-05-13T22:54:47","slug":"now-microsoft-has-an-agentic-ai-system-for-finding-security-vulnerabilities-too","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/38117\/","title":{"rendered":"Now Microsoft Has an Agentic AI System for Finding Security Vulnerabilities Too"},"content":{"rendered":"<p><img fetchpriority=\"high\" decoding=\"async\" class=\"alignnone size-full wp-image-336047\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/05\/mdash-architecture.jpg\" alt=\"Now Microsoft Has an Agentic AI System for Finding Security Vulnerabilities Too\" width=\"1066\" height=\"600\"  \/><\/p>\n<p>Microsoft revealed today that it has created a competitor to Anthropic Mythos called MDASH, the Microsoft Security multi-model agentic scanning harness. It identified 16 of the Windows vulnerabilities that Microsoft fixed in <a href=\"https:\/\/www.thurrott.com\/windows\/windows-11\/336002\/windows-11-gets-its-first-major-feature-updates-of-2026\" rel=\"nofollow noopener\" target=\"_blank\">this week\u2019s Patch Tuesday updates<\/a>.<\/p>\n<p>\u201cUnlike single-model approaches, the harness orchestrates more than 100 specialized AI agents across an ensemble of frontier and distilled models to discover, debate, and prove exploitable bugs end-to-end,\u201d <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/05\/12\/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-tops-leading-industry-benchmark\/\" rel=\"nofollow noopener\" target=\"_blank\">Microsoft vice president Taesoo Kim writes<\/a>. \u201cThe results speak for themselves: 21 of 21 planted vulnerabilities found with zero false positives on a private test driver; 96 percent recall against five years of confirmed Microsoft Security Response Center (MSRC) cases in clfs.sys and 100 percent in tcpip.sys; and an industry-leading 88.45 percent score on the public CyberGym benchmark of 1,507 real-world vulnerabilities\u2014the top score on the leaderboard, roughly five points ahead of the next entry.\u201d<\/p>\n<p>We already know that <a href=\"https:\/\/www.thurrott.com\/cloud\/web-browsers\/mozilla-firefox\/335823\/mozilla-patched-423-security-vulnerabilities-in-firefox-in-april\" rel=\"nofollow noopener\" target=\"_blank\">Mozilla has had incredible success fixing vulnerabilities in its Firefox codebase using Anthropic Mythos<\/a>. And so it was only a matter of time before Microsoft did something similar. But as the firm explains, its codebases are massive and quite complex: Windows, Hyper-V, Azure, and the device driver and service ecosystems around them are private to Microsoft, so they\u2019re not part of outside language models\u2019 training. \u201cOn this surface,\u201d Kim writes, \u201ca model has to actually reason.\u201d<\/p>\n<p>As Microsoft explains, MDASH is an agentic vulnerability discovery and remediation system that manages an ensemble of diverse AI models that examine a codebase and then output validated, proven findings. Its architecture is portable across model generations and it\u2019s model agnostic so it can improve as the technology evolves.<\/p>\n<p>\u201cWe are at a moment in the industry where AI-powered vulnerability discovery stops being speculative and starts being an engineering problem,\u201d Kim continues. \u201cThe findings in this Patch Tuesday and the retrospective recall on five years of [previous vulnerability] cases are evidence that AI vulnerability findings can scale.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"Microsoft revealed today that it has created a competitor to Anthropic Mythos called MDASH, the Microsoft Security multi-model&hellip;\n","protected":false},"author":2,"featured_media":38118,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[420,7829,23641,320,7828,314],"class_list":["post-38117","post","type-post","status-publish","format-standard","has-post-thumbnail","category-microsoft","tag-azure","tag-azure-ai","tag-mdash","tag-microsoft","tag-microsoft-ai","tag-security"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/38117","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=38117"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/38117\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/38118"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=38117"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=38117"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=38117"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}