Skip to content
feed: live
>_ 0dayNews
microsoft

Microsoft Adds Security AI to MDASH at Half the Cost

MAI-Cyber-1-Flash, Microsoft's first cybersecurity-specific model, joins MDASH and scores 95.95% on CyberGym at 50% lower cost than the previous config.

Microsoft Adds Security AI to MDASH at Half the Cost
Image: 0dayNews / 0dayNews Editorial · All rights reserved
kilobaud Dave "Kilobaud" Ferris · Published · 2 min read

Microsoft rolled out its first cybersecurity-specific model inside MDASH, the multi-model vulnerability identification and remediation harness the company has been expanding for most of this year. The new model, MAI-Cyber-1-Flash, runs alongside GPT-5.4 and scored 95.95% on CyberGym — Microsoft’s chosen benchmark for AI performance on security-specific tasks. Access is currently limited to approved parties.

The cost figure is the more interesting data point. Microsoft says the MAI-Cyber-1-Flash plus GPT-5.4 pairing costs 50% less than its previous best MDASH configuration — GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex stacked together. That cost reduction matters at the volume MDASH was processing in July, when the system was scoring and triaging 622 CVEs. Running three large models in parallel on that volume adds up. Running two — one of them purpose-built for the task — apparently adds up less.

The 95.95% number will draw the attention. CyberGym is a benchmarking framework designed for security-related AI tasks: vulnerability analysis, patch reasoning, detection and classification work. A high score there is signal. It is not the same as signal in your environment, against your actual code, on your actual CVE distribution, which doesn’t map cleanly to any fixed test set. The open question — the same one that has been open since MSRC started routing MDASH findings to human analysts downstream — is how the benchmark performance translates to real triage quality at scale.

What the combination of a high benchmark score and a significant cost reduction does suggest is a shift in how Microsoft is building MDASH. The previous approach was additive: stack general-purpose models, cover more ground. The new approach introduces a smaller, domain-trained model and claims better results at lower cost. That’s an argument the security AI field has been making in general terms for a while — purpose-specific models for narrow, well-defined tasks — with limited public evidence. Microsoft’s MDASH data, limited as it is, is at least a concrete data point.

Whether MAI-Cyber-1-Flash eventually surfaces beyond MDASH — in Azure Defender, Copilot for Security, or something external — isn’t clear from the announcement. The “limited to approved parties” language puts it firmly in internal or early-partner territory for now.

The benchmark is strong, the cost claim is leading the announcement, and the access is restricted. That’s the current state.

Found this useful? Share it.