{"id":1618,"date":"2026-07-30T13:38:32","date_gmt":"2026-07-30T13:38:32","guid":{"rendered":"https:\/\/feedsta.ai\/blog\/microsoft-mai-cyber-1-flash-mdash\/"},"modified":"2026-07-30T13:38:34","modified_gmt":"2026-07-30T13:38:34","slug":"microsoft-mai-cyber-1-flash-mdash","status":"publish","type":"post","link":"https:\/\/feedsta.ai\/blog\/microsoft-mai-cyber-1-flash-mdash\/","title":{"rendered":"Microsoft launches MAI-Cyber-1-Flash inside MDASH, a cyber-focused model it says halves cost"},"content":{"rendered":"<p>Microsoft introduced MAI-Cyber-1-Flash, a compact security model built to find vulnerabilities in complex codebases, and integrated it into MDASH, the company&#8217;s multi-agent vulnerability identification and remediation harness. The combined system scores 96% on CyberGym and is positioned to run at roughly 50% of the cost of Microsoft&#8217;s previous MDASH configuration, by routing most tasks to the new model and reserving larger models for the hardest cases.<\/p>\n<h2>What MAI-Cyber-1-Flash does inside MDASH<\/h2>\n<p>The model is designed to handle up to 90% of tasks that flow through MDASH, leaving the remaining 10%, the most difficult cases, to larger, more expensive models in Microsoft&#8217;s fleet, including GPT-5.4. That routing is the source of the cost saving. According to Microsoft, the unified MDASH + MAI-Cyber-1-Flash configuration delivers 96% on CyberGym, which the company calls the gold standard benchmark for evaluating how systems reason over large codebases to find real vulnerabilities. Microsoft also reports that the configuration outperforms Mythos, Gemini, and GPT on CyberGym, and runs at 50% of the cost of its earlier MDASH offering built on GPT 5.4, 5.4 mini, and 5.3 codex.<\/p>\n<h2>Why routing matters for defenders<\/h2>\n<p>The pitch is straightforward: security is an always-on function, the volume of inbound attacks is enormous, and token cost has become the practical limit on how much code defenders can scan. By splitting traffic between a cheap, focused model and a heavier general model, MDASH keeps operating cost down while keeping accuracy close to the ceiling. The approach leans on three pieces Microsoft says it jointly optimized: the model, the data, and the harness.<\/p>\n<h2>The model: derived from MAI-Thinking-1<\/h2>\n<p>MAI-Cyber-1-Flash is a code-heavy security model derived from the MAI-Thinking-1 lineage, built in-house. Microsoft is publishing a technical report with the full details. The model is compact by design, which is what lets it carry 90% of the workload without paying the inference cost of a frontier generalist.<\/p>\n<h2>The data: trillions of daily security signals<\/h2>\n<p>Microsoft frames its data advantage as the hardest thing for competitors to replicate. The company draws on decades of security work and reports more than 100 trillion security signals per day, gathered across identity, endpoint, cloud, data, browser, and applications, with operational insight from 1.6 million customers. That telemetry feeds a reinforcement learning loop in which actions (what was exploitable, what was contained, what was blocked) are tied to outcomes. The loop is the basis for continuous improvement of the cyber models.<\/p>\n<h2>The harness: MDASH and Perception<\/h2>\n<p>MDASH is the multi-agent system around the model. Microsoft says it is tuned by in-house security experts who have built more than 100 agents using multiple leading models, with roles covering finding, validating, and remediating vulnerabilities. Alongside the new model, Microsoft also launched Perception, an agentic security system within MDASH that runs teams of agents to continuously monitor, patch, and close new threat vectors. Perception will also soon use MAI-Cyber-1-Flash for security workflows beyond software vulnerabilities.<\/p>\n<h2>How safety and trust were handled<\/h2>\n<p>Microsoft describes MAI-Cyber-1-Flash as its first cyber model, and built in several layers of evaluation. The model was trained with a security-first calibration, evaluated by Microsoft&#8217;s AI Red Team, tested through automated and expert-led adversarial exercises, and independently assessed by a third party. Through MDASH, customers get enterprise-grade controls including role-based access controls, tenant isolation, encryption, auditability, and sandboxed execution environments with no internet access.<\/p>\n<h2>CyberGym, the benchmark behind the headline number<\/h2>\n<p>CyberGym is presented as the benchmark for reasoning over large codebases to surface real vulnerabilities. Microsoft reports a 96% score for the combined MDASH + MAI-Cyber-1-Flash system, which it says is 12 points above Mythos. Microsoft also claims the system beats Gemini and GPT on the same benchmark, though the post does not list per-model scores or a date for the comparison.<\/p>\n<h2>FAQ<\/h2>\n<h3>What is MAI-Cyber-1-Flash?<\/h3>\n<p>MAI-Cyber-1-Flash is Microsoft&#8217;s compact, code-heavy security model derived from the MAI-Thinking-1 lineage, built in-house and designed to find vulnerabilities in complex codebases.<\/p>\n<h3>What is MDASH?<\/h3>\n<p>MDASH is Microsoft&#8217;s multi-agent vulnerability identification and remediation harness. It uses more than 100 agents built by in-house security experts across multiple leading models to find, validate, and remediate vulnerabilities.<\/p>\n<h3>How much does MAI-Cyber-1-Flash cost to run inside MDASH?<\/h3>\n<p>Microsoft says the MDASH + MAI-Cyber-1-Flash configuration runs at 50% of the cost of its previous MDASH setup built on GPT 5.4, 5.4 mini, and 5.3 codex, by routing up to 90% of tasks to the new model.<\/p>\n<h2>Related coverage<\/h2>\n<ul>\n<li><a href=\"https:\/\/feedsta.ai\/blog\/poolside-laguna-s-2-1-open-weight-coding-model\/\">Poolside releases Laguna S 2.1, an open-weight coding model it says beats rivals 10x its size<\/a><\/li>\n<li><a href=\"https:\/\/feedsta.ai\/blog\/anthropic-claude-fable-5-access-max-team-premium\/\">Anthropic Settles Claude Fable 5 Access, Keeps Model Inside Max and Team Premium at Half Capacity<\/a><\/li>\n<\/ul>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"headline\":\"Microsoft launches MAI-Cyber-1-Flash inside MDASH, a cyber-focused model it says halves cost\",\"description\":\"MAI-Cyber-1-Flash inside MDASH scores 96% on CyberGym and runs at half the cost of Microsoft's previous setup, routing 90% of tasks to the new model.\",\"datePublished\":\"2026-07-30T13:37:07.730Z\",\"publisher\":{\"@type\":\"Organization\",\"name\":\"Feedsta\"}},{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What is MAI-Cyber-1-Flash?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"MAI-Cyber-1-Flash is Microsoft's compact, code-heavy security model derived from the MAI-Thinking-1 lineage, built in-house and designed to find vulnerabilities in complex codebases.\"}},{\"@type\":\"Question\",\"name\":\"What is MDASH?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"MDASH is Microsoft's multi-agent vulnerability identification and remediation harness. It uses more than 100 agents built by in-house security experts across multiple leading models to find, validate, and remediate vulnerabilities.\"}},{\"@type\":\"Question\",\"name\":\"How much does MAI-Cyber-1-Flash cost to run inside MDASH?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Microsoft says the MDASH + MAI-Cyber-1-Flash configuration runs at 50% of the cost of its previous MDASH setup built on GPT 5.4, 5.4 mini, and 5.3 codex, by routing up to 90% of tasks to the new model.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/microsoft.ai\/news\/introducing-mai-cyber-1-flash-inside-mdash\/\" target=\"_blank\" rel=\"nofollow noopener\">microsoft.ai<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft&#8217;s MAI-Cyber-1-Flash runs inside its MDASH multi-agent harness and posts a 96% CyberGym score at half the cost of previous configurations.<\/p>\n","protected":false},"author":1,"featured_media":1617,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"rank_math_title":"","rank_math_description":"","rank_math_focus_keyword":"","rank_math_canonical_url":"","rank_math_facebook_title":"","rank_math_facebook_description":"","rank_math_twitter_title":"","rank_math_twitter_description":"","rank_math_robots":[],"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1618","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-news"],"_links":{"self":[{"href":"https:\/\/feedsta.ai\/blog\/wp-json\/wp\/v2\/posts\/1618","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/feedsta.ai\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/feedsta.ai\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/feedsta.ai\/blog\/wp-json\/wp\/v2\/comments?post=1618"}],"version-history":[{"count":1,"href":"https:\/\/feedsta.ai\/blog\/wp-json\/wp\/v2\/posts\/1618\/revisions"}],"predecessor-version":[{"id":1619,"href":"https:\/\/feedsta.ai\/blog\/wp-json\/wp\/v2\/posts\/1618\/revisions\/1619"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/feedsta.ai\/blog\/wp-json\/wp\/v2\/media\/1617"}],"wp:attachment":[{"href":"https:\/\/feedsta.ai\/blog\/wp-json\/wp\/v2\/media?parent=1618"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/feedsta.ai\/blog\/wp-json\/wp\/v2\/categories?post=1618"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/feedsta.ai\/blog\/wp-json\/wp\/v2\/tags?post=1618"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}