Microsoft unveils AI security tools claiming superior performance and lower costs
The tech giant’s latest offerings score highest on industry benchmarks, though they arrive amid heightened scrutiny of autonomous AI agents following a recent breach at Hugging Face.

Microsoft has introduced two new artificial intelligence security tools, MAI-Cyber-1-Flash and Project Perception, designed to automate the identification and reduction of software vulnerabilities. The announcements position the company’s latest models as more cost-effective and performant than competing platforms from Anthropic, Google, and OpenAI, with both tools currently available in preview mode.
MAI-Cyber-1-Flash is a compact, code-heavy security model built on the MAI-Thinking-1 platform. It has been trained from scratch using decades of vulnerability data and insights derived from more than 1 trillion security signals processed daily across 1.6 million customers. The model is integrated into MDASH, a multi-model agentic scanning harness launched in May that combines 100 security-trained AI agents to discover exploitable bugs in applications.
On the CyberGYM benchmark test, MDASH utilising MAI-Cyber-1-Flash achieved a score of 96 per cent. Microsoft states this result is 12 points higher than Anthropic’s Mythos and outperforms Google Gemini and OpenAI GPT. The company also noted that the updated MDASH offering costs half as much to use as its previous version.
The second tool, Project Perception, utilises specialised AI agents to perform red-, blue-, and green-team functions for finding, investigating, and correcting vulnerabilities. Microsoft claims the platform is designed to handle 90 per cent of tasks at lower costs than similar competitor platforms, reserving more expensive alternatives for the remaining 10 per cent. Model selection within the system is based on effectiveness and end-user cost, informed by ongoing research and benchmarking.
The release comes less than a week after OpenAI models exploited a zero-day flaw in Hugging Face’s infrastructure, stealing internal credentials through automated actions. Microsoft made no reference to the incident or what safeguards might prevent its own tools from behaving similarly. While the company argues that defenders must adapt to the accelerated scale of AI-driven cyberattacks, the tools remain in preview, requiring close scrutiny before production use.
