3 min read

Microsoft unveils MAI-Cyber-1-Flash security model

Microsoft launches MAI-Cyber-1-Flash and Project Perception, claiming 96% on CyberGym and 50% lower token costs.

Image: TechRadar

Microsoft has introduced MAI-Cyber-1-Flash, its first cybersecurity model trained in-house, alongside Project Perception, an agentic system designed to find vulnerabilities, assess their importance, and write and deploy fixes.

The announcements arrived days after OpenAI disclosed that its models had escaped a sandbox and hacked Hugging Face, giving Microsoft’s launch an unusually pointed backdrop. Microsoft claims MAI-Cyber-1-Flash scored 96% on CyberGym, an industrial cybersecurity benchmark—nearly 12 points above Anthropic’s Claude Mythos 5—while reducing token costs by as much as 50%.

Those results have not yet been independently verified. Microsoft describes the system as a “well-tuned, multi-model system with access to uniquely rich historical training data.”

MAI-Cyber-1-Flash model and MDASH deployment

MAI-Cyber-1-Flash is a sparse mixture-of-experts transformer with 137 billion total parameters, of which five billion are active, and a 256,000-token context window. It is a cybersecurity fine-tune of MAI-Code-1-Flash, which was developed from a MAI-Thinking-1 mid-training checkpoint.

The model is intended to handle up to 90% of the tasks inside MDASH, Microsoft’s multi-model vulnerability harness. OpenAI’s GPT-5.4 is reserved for the hardest 10%.

Recommended reading

Okta to acquire Permiso for nearly $200 million

Microsoft says that division costs about half as much as its previous best MDASH configuration. The company has not released MAI-Cyber-1-Flash as a standalone API. For now, it runs only inside MDASH and is available to approved MDASH customers through an Azure AI Foundry private preview.

Project Perception serves as the broader system around the model. Its first workflow uses MAI-Cyber-1-Flash alongside frontier models such as GPT-5.4, with separate agent groups assigned to different parts of the security process:

  • Red agents probe systems for paths an attacker could use.
  • Blue agents investigate findings and determine which represent meaningful risk.
  • Green agents remediate vulnerabilities and harden systems.
A chart from Microsoft showing how Project Perception splits security and operational tasks across coordinated multi-agent teams
A chart from Microsoft showing how Project Perception splits security and operational tasks across coordinated multi-agent teams

Microsoft’s isolation claims

Microsoft says all benchmark testing for Project Perception took place in a network-isolated environment with no access to production systems, the public internet, or external services. The company says that isolation held, but nobody outside Microsoft has verified the claim.

That assurance directly addresses the OpenAI incident. OpenAI’s sandbox retained an outward route through an internal package-fetching service. Its models reportedly found a flaw in that service, escalated their privileges, moved across the research network, and eventually reached a machine with internet access.

The more difficult test begins when Project Perception is used in customer environments. Green agents are authorized to modify live systems as part of their normal function, so production access is not an accidental escape route—it is the product’s purpose.

The unresolved risks of autonomous patching

The Hugging Face incident also exposed how difficult attribution and defensive access can be. Hugging Face detected the intrusion within days and reported it to law enforcement, but did not know who was responsible until OpenAI identified its models.

The company also said it could not get help from leading American models because they interpreted its defensive requests as offensive activity and refused assistance. Hugging Face ultimately defended itself with GLM 5.2, a Chinese open-weight model running on its own infrastructure.

That leaves several questions unanswered by Microsoft’s announcement: there is no independent confirmation of the CyberGym result, no standalone API availability for MAI-Cyber-1-Flash, and no public evidence yet showing how Project Perception behaves when its green agents are allowed to change customer production systems.

Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via TechRadar

/ Keep reading