{"id":65061,"date":"2026-07-28T14:25:11","date_gmt":"2026-07-28T18:25:11","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=65061"},"modified":"2026-07-28T14:25:11","modified_gmt":"2026-07-28T18:25:11","slug":"mai-cyber-1-flash-mdash-cybergym","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/mai-cyber-1-flash-mdash-cybergym\/","title":{"rendered":"MAI-Cyber-1-Flash Pushes MDASH to 95.95% on CyberGym"},"content":{"rendered":"<p><a href=\"https:\/\/www.microsoft.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Microsoft<\/a> AI has released MAI-Cyber-1-Flash, its first model purpose-built for cyber defense, and it does not ship as a standalone endpoint. Instead, it operates exclusively inside MDASH, Microsoft\u2019s multi-model agentic scanning harness, where it helped push the system to a benchmark score of 95.95 percent on the CyberGym public vulnerability suite. The result represents a twelve-point gain over the best competing system and a seven-point improvement over MDASH\u2019s own previous configuration from May 2026. For engineering teams evaluating autonomous vulnerability discovery, this release signals that the combination of a small, specialized model with efficient routing to a frontier model can deliver commercial-grade results at roughly half the cost of earlier approaches.<\/p>\n<h2>What is MAI-Cyber-1-Flash: Architecture and lineage<\/h2>\n<p>MAI-Cyber-1-Flash is a transformer model that uses self-attention and sparse Mixture-of-Experts layers. It carries 137 billion total parameters with only 5 billion active per inference, and it supports a 256k context window. Inputs and outputs are text only. The model is a cybersecurity-specialized fine-tune of MAI-Code-1-Flash, the lightweight agentic coding model that Microsoft already embeds in GitHub Copilot and VS Code. The launch post further describes it as derived from the MAI-Thinking-1 lineage, making it part of a broader family of models designed for reasoning-heavy tasks.<\/p>\n<p>The developer of record is Microsoft Ireland Operations Limited. At 5 billion active parameters, the model is designed to be efficient enough for high-throughput scanning tasks while retaining the capacity to reason about complex codebases. The 256k context window allows it to ingest entire files or module-level code in a single pass, a requirement for realistic vulnerability discovery where context from distant parts of a codebase often determines whether a bug is reachable.<\/p>\n<h2>The CyberGym benchmark: How 95.95 percent was achieved<\/h2>\n<p>CyberGym is a public suite of 1,507 real-world vulnerability reproduction tasks drawn from 188 OSS-Fuzz projects. Microsoft evaluated at CyberGym\u2019s default level 1 configuration, which supplies vulnerable source code along with a high-level description of the vulnerability. This setup mirrors a realistic scenario where a security engineer has some contextual knowledge of the target.<\/p>\n<p>MDASH running MAI-Cyber-1-Flash alongside GPT-5.4 scores 95.95 percent. The launch chart places four competing systems \u2014 including Anthropic\u2019s Mythos and configurations based on <a href=\"https:\/\/www.google.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Google<\/a> <a href=\"https:\/\/overcentral.com\/en\/google-home-speaker-gemini-review\/\" title=\"Google Home Speaker launches with unfinished Gemini for Home\" data-iacss-internal=\"1\">Gemini<\/a> and OpenAI GPT models \u2014 between 83.2 percent and 85.6 percent. Microsoft frames its result as roughly twelve points above Mythos, the strongest competitor at the time of testing.<\/p>\n<p>When Microsoft first detailed MDASH in May 2026, the harness scored 88.45 percent on CyberGym using only generally available models. That was already the top public leaderboard score, about five points ahead the next entry at 83.1 percent. The research team states the improvement plainly: replacing 80 percent of the existing models in MDASH with MAI-Cyber-1-Flash moved the harness from 88.4 percent to 95.95 percent. The leap did not come from a larger model but from a model that is better calibrated to defensive security work inside a coordinated agent pipeline.<\/p>\n<h3>What is MDASH and how does it route tasks between models?<\/h3>\n<p>MDASH stands for Multi-model Agentic Scanning Harness. It orchestrates over 100 specialized agents through five stages: Prepare, Scan, Validate, Dedupe, and Prove. In the Prepare stage, the system ingests the source target, builds language-aware indices, and derives the attack surface and threat model by analyzing past commits. In the Scan stage, auditor agents emit candidate findings. In the Validate stage, debater agents argue for and against reachability and exploitability \u2014 disagreement between models is treated as signal. The Dedupe stage collapses semantically equivalent findings. Finally, in the Prove stage, the system constructs and executes triggering inputs, validating pre-conditions dynamically, for example with AddressSanitizer on C and C++ targets.<\/p>\n<p>To control frontier model costs at scale, MAI-Cyber-1-Flash handles up to 90 percent of MDASH tasks, escalating the hardest 10 percent to a larger frontier model, currently GPT-5.4. Microsoft reports that this routing yields a 50 percent cost saving compared to the previous configuration of GPT-5.4, 5.4 mini, and 5.3 codex. The cost reduction is significant because agentic scanning runs thousands of inferences per codebase, and frontier models are expensive to operate at that volume.<\/p>\n<h2>Why the model scores zero on exploit generation<\/h2>\n<p>The research team also present standalone results from a lightweight terminal harness, separate from the MDASH system. On CVEBench, which tests the ability to exploit real web application CVEs, MAI-Cyber-1-Flash scores 0.314. On CyberSecEval4 Threat Intelligence, it scores 0.553. On CyberSecEval4 Malware Analysis, it scores 0.33. On CRSBench, a full-pipeline cyber reasoning benchmark, it scores 0.651 with a POV setting of 1200. On ExploitGym, which tests kernel, userspace, and browser exploitation, it scores zero across all three categories.<\/p>\n<p>Those zeros are deliberate, not a defect. The Microsoft team states that the model was trained to perform defensive tasks such as patching bugs and recovering vulnerabilities, not offensive tasks such as deploying malware or crafting exploits. A 5-billion-parameter active model that cannot generate exploits but can drive a 95.95 percent discovery pipeline is exactly the artifact a defender-only product needs. In production, this calibration also reduces the risk of misuse: the model is less useful to attackers even if access controls are bypassed.<\/p>\n<h2>MDASH production results: 16 CVEs and recovery of historical cases<\/h2>\n<p>MDASH was developed by Microsoft\u2019s Autonomous Code Security (ACS) team, which includes members from the DARPA AI Cyber Challenge-winning Team Atlanta. The system has already demonstrated production value. In May 2026, MDASH-assisted work generated 16 CVEs, including four Critical remote code execution flaws, in the Windows networking and authentication stack. Retrospective analysis showed that MDASH recovered 96 percent of 28 MSRC cases in clfs.sys and 100 percent of 7 cases in tcpip.sys over a five-year window.<\/p>\n<p>These recovery rates are noteworthy because they measure how well the system finds vulnerabilities that human researchers and existing tools had already found. A system that recovers 96 percent of known bugs in a complex kernel driver is likely discovering a similar proportion of unknown bugs, though that claim requires more data to validate. The clfs.sys result is particularly important because the Common Log File System driver has been a consistent source of critical vulnerabilities in Windows, and many of those bugs involve state machines that are difficult for general-purpose models to reason about without domain-specific help.<\/p>\n<h2>How domain plugins extend the model where it is blind<\/h2>\n<p>MDASH is extensible by design. Domain plugins inject context that foundation models cannot infer: kernel calling conventions, IRP rules, lock invariants, IPC trust boundaries, codec state machines. Microsoft\u2019s own CLFS proving plugin, which knows how to construct a triggering log file, is credited as part of why clfs.sys recall hit 96 percent. A CodeQL database can also be plugged in, allowing teams to combine static analysis with language model reasoning.<\/p>\n<p>For teams evaluating MDASH, the plugin system is where most of the tuning effort lands. The model alone is powerful, but the proof stage requires domain-specific knowledge to construct valid triggering inputs. Without plugins that encode the invariants of a specific driver or file system, the model may find a bug but fail to prove it is exploitable, which means the finding gets discarded during validation.<\/p>\n<h2>How to access MAI-Cyber-1-Flash: Three gated doors<\/h2>\n<p>There is no weights download and no open API for MAI-Cyber-1-Flash. Access runs through three gated doors, all of which route back to Microsoft\u2019s customer vetting process.<\/p>\n<p>Path A is the MDASH private preview. This is the harness itself, for teams that want agentic code scanning on their own repositories. Sign-up runs through aka.ms\/AI-drivenScanningHarness. MDASH has been in limited private preview since May 2026 and is already deployed by Fortune 500 customers. It provides RBAC, tenant isolation, and sandboxed execution with no internet access for the scanning agents.<\/p>\n<p>Path B is Azure AI Foundry Private Preview. The model card states that MAI-Cyber-1-Flash is offered through Azure AI Foundry solely for use within MDASH, with access restricted and subject to additional approval because of the dual-use nature of cyber capability. Reporting from the launch puts the Foundry availability date at 3 August 2026. This path does not provide a general-purpose endpoint; the model can only be used inside the MDASH harness.<\/p>\n<p>Path C is Project Perception, the broadest door and the only one with published commercial terms. Perception is an agentic security system that uses red agents to probe like an attacker, blue agents to investigate and rank risk, and green agents to remediate and harden. Microsoft says Perception will use MAI-Cyber-1-Flash for more security workflows over time, beyond software vulnerability work. It lands in <a href=\"https:\/\/overcentral.com\/en\/microsoft-defender-patch-disk-exhaustion\/\" title=\"Microsoft Defender patch risks filling Windows hard drives\" data-iacss-internal=\"1\">Microsoft Defender<\/a> first, then extends across the Microsoft Security portfolio. Human sign-off is required on high-impact actions, and decisions are described as scoped, traceable, and replayable.<\/p>\n<h3>What is Project Perception and how does it use MAI-Cyber-1-Flash?<\/h3>\n<p>Project Perception is Microsoft\u2019s multi-agent security system that enters public preview on 3 August 2026 inside Microsoft Defender. It uses a tri-color agent model: red agents probe for vulnerabilities, blue agents investigate and rank risk, and green agents write and deploy fixes. MAI-Cyber-1-Flash will power an increasing share of Perception\u2019s security workflows over time, starting with software vulnerability work and expanding to other domains. Pricing is consumption-based, metered in Security Compute Units (SCUs). Human sign-off is required on high-impact actions, and any issues or abuse concerns go to the Microsoft Security Response Center.<\/p>\n<h2>Safety and calibration trade-offs<\/h2>\n<p>Red team testing was conducted using the PyRIT framework, with an automated adversarial corpus of more than one million multi-turn jailbreak conversations. Testing was performed in a network-isolated environment with no access to production systems or the public internet. A third-party independent assessment found no critical-severity findings. The model was also trained to forget content unrelated to cyber defense, including weapons and child-safety domains.<\/p>\n<p>Microsoft calls this a security-first calibration and warns it cuts both ways. Safeguards may trigger on ambiguous requests even when the defensive goal is legitimate, meaning teams should expect refusals during evaluation. The model card states that calibration may be relaxed as operational data accumulates, but for now, false refusals are a known cost of the safety approach. Teams scoping a pilot should budget for these refusals and design their evaluation pipelines to distinguish between model limitations and actual safety violations.<\/p>\n<p>The model card also states plainly that generated code may be incorrect and must be reviewed and tested before production use. MDASH output should be treated as proven candidates, not merged patches. Even with a 95.95 percent detection rate, the system will miss bugs and produce false positives.<\/p>\n<h2>Strategic implications for the security tooling market<\/h2>\n<p>The combination of MAI-Cyber-1-Flash and MDASH represents a shift in how enterprise security teams can approach vulnerability discovery. Traditional approaches rely on static analysis, fuzzing, or human code review. Agentic scanning adds a layer that can reason about code the way a human reviewer would, but at machine scale. The cost reduction from small-model routing makes this approach economically viable for organizations with large codebases.<\/p>\n<p>The 95.95 percent CyberGym score also raises the bar for competitors. Any vendor claiming benchmark leadership will now need to demonstrate performance at that level or explain why their benchmark methodology differs. The result also puts pressure on open-source alternatives: while models like CodeLlama and DeepSeek Coder can be fine-tuned for security tasks, they lack the MDASH orchestration layer and the domain plugins that make the Microsoft system effective on real driver kernels and file systems.<\/p>\n<p>For security teams that are already Microsoft customers, the path to adoption is relatively short. MDASH is in private preview, Project Perception enters public preview on 3 August 2026, and both integrate with existing Microsoft <a href=\"https:\/\/overcentral.com\/en\/github-pypi-supply-chain-security\/\" title=\"New GitHub, PyPI Policies Boost Supply Chain Security\" data-iacss-internal=\"1\">supply chain<\/a> and security tools. For teams outside the Microsoft ecosystem, the barrier is higher: there is no API, no weights, and no independent deployment path. The model is designed to stay inside Microsoft\u2019s infrastructure, which means teams that want this capability may need to adopt MDASH or Perception as their scanning platform.<\/p>\n<p>The longer-term question is whether Microsoft will eventually release a standalone version of MAI-Cyber-1-Flash for on-premises or air-gapped deployment. Many enterprise security teams operate in environments where cloud connectivity is restricted, and a model that requires Azure AI Foundry access will not work for them. The model card provides no indication that a standalone release is planned, but the demand from defense and critical infrastructure customers may eventually force that decision.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft AI has released MAI-Cyber-1-Flash, its first model purpose-built for cyber defense, and it does not ship as a standalone endpoint. Instead, it operates exclusively inside MDASH, Microsoft\u2019s multi-model agentic scanning harness, where it helped push the system to a benchmark score of 95.95 percent on the CyberGym public vulnerability suite. The result represents a [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":83873,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/65061.png","fifu_image_alt":"MAI-Cyber-1-Flash Pushes MDASH to 95.95% on CyberGym","footnotes":""},"categories":[349],"tags":[],"class_list":["post-65061","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/65061.png","fifu_image_alt":"MAI-Cyber-1-Flash Pushes MDASH to 95.95% on CyberGym","fifu_redirection_url":"https:\/\/depthfirst.com\/research\/agent-capability-is-a-system-design-problem-lessons-from-a-90-improvement-on-cybergym","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/65061","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=65061"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/65061\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/83873"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=65061"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=65061"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=65061"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}