HomeMicrosoft targets vulnerability scanning costsUncategorizedMicrosoft targets vulnerability scanning costs

Microsoft targets vulnerability scanning costs

Microsoft has released MAI-Cyber-1-Flash, a security model built into MDASH that finds vulnerabilities at half the cost of alternatives.

Redmond announced the model alongside Perception – a set of security agents – in a joint post from Mustafa Suleyman, CEO of Microsoft AI, and Hayete Gallot, Executive VP of Microsoft Security. The pairing targets a problem brewing for a while: the volume of code needing review has outpaced the budget available to review it.

Suleyman and Gallot describe attackers using AI to probe growing codebases for a single flaw, and argue the response has to change with it. “The old model of security, where you scan occasionally and patch eventually, is now obsolete,” they write.

Running frontier models against every line of code in an enterprise repository gets expensive at scale, and Microsoft says computation cost – not model availability – now limits how much scanning defenders can afford to run.

A cheaper model does most of the work, a bigger one covers the rest

MAI-Cyber-1-Flash handles up to 90 percent of vulnerability-finding tasks inside MDASH, according to Microsoft. The remaining share, described as exceptionally hard cases, gets routed to GPT-5.4, the larger model Microsoft already runs inside the harness.

That routing arrangement is the mechanism behind the cost claim. MDASH now defaults to the cheaper model and escalates only when a task exceeds it.

Microsoft says the combined system scores 96 percent on CyberGym, a benchmark it describes as the standard for evaluating how models reason over large codebases to find real vulnerabilities in code. That figure sits 12 points above Anthropic’s Mythos, one of the systems Microsoft names alongside Gemini and GPT as competitors. Microsoft also claims the setup delivers a 50 percent cost saving against its previous best MDASH configuration, a combination of GPT-5.4, 5.4 Mini, and 5.3 Codex.

CyberGym scores, cost comparisons, and the 90/10 routing split all come from Microsoft’s own testing on its own infrastructure. Synthetic vulnerability sets built for benchmarking behave differently from a live codebase carrying incomplete documentation, stale dependencies, and years of accumulated patch history. A model that reasons well over benchmark code doesn’t automatically reason well over a decade-old internal repository nobody has fully documented.

Finding a flaw and fixing it are different jobs

Microsoft is also launching Perception, a set of security agents built to work alongside MAI-Cyber-1-Flash inside MDASH. The model’s job is identification.

Perception handles what comes after: monitoring, patching, and closing threat vectors once a vulnerability turns up. Microsoft says Perception will extend to cover more security workflows beyond software vulnerability work, though the company hasn’t given a timeline for that expansion.

Finding a flaw faster doesn’t help much if the remediation queue behind it stays backed up. Microsoft’s own post acknowledges as much, noting that “there are many jobs to be done by security practitioners themselves” even as AI remediation becomes a routine part of the workflow.

Because MAI-Cyber-1-Flash is Microsoft’s first purpose-built cyber model, the company has attached a heavier governance layer than it typically discloses for general-purpose releases.

Microsoft says the model went through evaluation by its internal AI Red Team, automated and expert-led adversarial testing, and an assessment from an unnamed third party. MDASH deployment adds role-based access controls, tenant isolation, encryption, audit logging, and sandboxed execution environments without internet access, according to the company.

Security leaders adopting this kind of tooling still need to run their own validation rather than rely on vendor testing alone. A model with access to internal repositories and remediation permissions can widen the attack surface it’s meant to shrink.

The data Microsoft says can’t be replicated

Model architecture and harness tuning explain part of the performance claim. Microsoft says the bigger factor is data: more than 100 trillion telemetry events collected daily across identity, endpoint, cloud, and network layers – drawn from a base of 1.6 million customers – plus a record of real exploits and the remediations that followed them. That combination of attack data and outcome data, Microsoft argues, is what separates its models from competitors training on public code repositories alone.

MAI-Cyber-1-Flash descends from the MAI-Thinking-1 lineage, built in-house rather than adapted from an existing open or licensed model, according to Microsoft’s technical report on the release.

Microsoft frames the training approach as a “live reinforcement learning loop” rather than a static dataset: defenders triage alerts, remediate flaws, and deploy protections, and the outcomes feed back into model training on an ongoing basis.

The cost argument is the most attractive part of the pitch and the hardest to verify independently. Microsoft’s 50 percent saving figure compares its own new configuration against its own old one, not against a competitor’s pricing.

The bigger operational question is how the 90/10 routing behaves on a codebase Microsoft hasn’t seen before. CyberGym testing happens under controlled conditions. A production repository with legacy code, undocumented dependencies, and inconsistent patch histories will likely push a higher share of tasks toward the expensive escalation tier than the benchmark suggests.

MAI-Cyber-1-Flash is available now inside MDASH for customers already running Microsoft’s security stack, with Perception rolling out as a companion set of agents for the patching and monitoring work the identification model doesn’t cover.

See also: Open Secure AI Alliance aims to open-source AI security defences

Banner for Cyber Security Expo by TechEx events.

Want to learn more about cybersecurity from industry leaders? Check out Cyber Security & Cloud Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including the AI & Big Data Expo. Click here for more information.

Developer is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.

Home
Services
Careers
Call Us
Contact