Microsoft has introduced MAI-Cyber-1-Flash, its first cybersecurity-focused AI model, as part of MDASH, the company’s multi-model platform for identifying and fixing software vulnerabilities.
The new model is designed to handle most vulnerability analysis tasks while reducing costs and improving overall system performance.
According to Microsoft, the latest MDASH configuration, which combines MAI-Cyber-1-Flash with GPT-5.4, achieved a 95.95% score on CyberGym Level 1, a benchmark that measures an AI agent’s ability to reproduce known software vulnerabilities by generating working proof-of-concept exploits from vulnerability descriptions and unpatched source code. Microsoft also says the new setup cuts costs by 50% compared to its previous best MDASH configuration, which relied on GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. The feature is currently available only to approved MDASH customers through an Azure AI Foundry private preview.
MAI-Cyber-1-Flash is built to complete up to 90% of MDASH tasks, leaving the most difficult 10% to GPT-5.4. The model is not available as a standalone AI service or public API and can only be used inside the MDASH platform.
Microsoft noted that the 95.95% CyberGym score reflects the performance of the complete MDASH system, not MAI-Cyber-1-Flash alone. CyberGym Level 1 focuses on reproducing already known vulnerabilities rather than discovering new ones or verifying whether generated patches fully fix the issues.

Despite Microsoft’s announcement, the public CyberGym leaderboard had not yet been updated with the new result as of July 28, 2026. It still listed Microsoft’s earlier MDASH submission from May with a score of 88.4%, and the company has not confirmed whether the new benchmark has been submitted for public listing.
The company also cautioned against comparing the new score with its previously reported 96.55% MDASH result from June because the two evaluations used different scoring methods. The earlier benchmark counted any successful crash, including unrelated vulnerabilities, while Microsoft has not confirmed whether the same criteria were used for the latest evaluation.
According to the model card, MAI-Cyber-1-Flash is based on a sparse mixture-of-experts transformer architecture with 137 billion total parameters, 5 billion active parameters, and a 256,000-token context window. It is a cybersecurity-specialized version of MAI-Code-1-Flash, which itself was developed from a MAI-Thinking-1 training checkpoint.
Microsoft says the new model replaced 80% of the existing models used inside MDASH, increasing the reported CyberGym score from 88.4% to 95.95%. The company explained that the 80% figure refers to the share of models replaced, while the separate 90% figure represents the proportion of tasks the smaller model is expected to handle.
The company describes intelligent task routing as the key innovation behind the new system. MAI-Cyber-1-Flash processes the majority of vulnerability analysis requests, while GPT-5.4 is automatically assigned the most complex cases, allowing MDASH to maintain strong performance while lowering operating costs.
Microsoft’s launch announcement says the reported 50% cost reduction is based on comparisons with its previous MDASH model mix. However, the company did not disclose details such as token usage, latency, compute allocation, or workload distribution, making the claim difficult to independently verify.
Microsoft Vice President of Agentic Security Taesoo Kim previously emphasized that the AI model itself is only one part of the overall product, with the surrounding system architecture playing a critical role in performance.
The model card also reports results on several other security benchmarks, including CVEBench, CyberSecEval4, CRSBench, and malware analysis tests. However, the model recorded zero scores across all ExploitGym categories, which focus on converting vulnerabilities into working code-execution exploits, highlighting that benchmark results vary depending on the task being measured.
Microsoft said all evaluations were performed in a network-isolated environment without access to production systems, the public internet, or external services. The company also warned that the AI-generated code and analysis may still contain errors and should always be reviewed before being used in real-world security operations.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
MAI-Cyber-1-Flash will first be used for software vulnerability management inside MDASH as part of Project Perception, Microsoft’s broader initiative for coordinating AI-powered defensive security agents. Project Perception is scheduled to enter public preview on August 3, with Microsoft planning to expand the technology to additional cybersecurity workflows in the future.





