
Microsoft has released its first in-house cybersecurity model, MAI-Cyber-1-Flash, and integrated it into its MDASH vulnerability scanning system. It's a fine-tuned version of MAI-Code-1-Flash, with 137 billion total parameters and 5 billion activated per inference, supporting a 256K context window.
MDASH lets the model handle up to 90 percent of vulnerability discovery, validation, triage, and remediation tasks. The toughest 10 percent are passed to GPT-5.4. According to Microsoft, this combination costs nearly 50 percent less than existing setups using GPT-5.4, 5.4 mini, and 5.3 Codex.
In Microsoft's CyberGym benchmark, the "MAI-Cyber-1-Flash + GPT-5.4" system scored 95.95 percent. GPT-5.5 Cyber scored 85.6 percent, and Anthropic Mythos 5 scored 83.8 percent. Note that these comparisons are for the full model and agent combo, not MAI-Cyber-1-Flash alone.
The model will also be incorporated into Project Perception, a security agent product. There are three types of agents — red, blue, and green — responsible for finding vulnerabilities, assessing risk, and patching defenses. Project Perception will enter public beta on August 3rd, but MAI-Cyber-1-Flash is currently available only to approved MDASH customers in a private preview.