Microsoft unveils MAI-Cyber-1-Flash and MDASH to cut AI security costs
The tech giant’s latest release targets the high token costs of vulnerability remediation by routing 90% of tasks to a leaner model, reserving larger systems for complex exploits.
Microsoft has announced the release of MAI-Cyber-1-Flash, a compact security model derived from the MAI-Thinking-1 lineage, alongside MDASH, a multi-agent harness designed for vulnerability identification and remediation. The integrated system claims to deliver world-class performance at 50% of the cost of leading models, achieving a 96% score on the CyberGym benchmark. This score exceeds competitors such as Mythos, Gemini, and GPT, marking the compact model as a significant shift in how defenders manage the rising costs of AI-driven security operations.
The solution is engineered to handle 90% of security tasks efficiently, reserving larger, more costly models for the remaining 10% of exceptionally complex issues. Specifically, the system allows MDASH to deploy larger models, such as GPT-5.4, only when necessary. This tiered approach results in a 50% cost saving compared to Microsoft’s current best offering in MDASH, which previously relied on a combination of GPT-5.4, 5.4 mini, and 5.3 codex.
MAI-Cyber-1-Flash is described as Microsoft’s first cyber model, built from scratch in-house on high-quality data. It is deeply integrated into MDASH, a harness tuned by industry experts to create over 100 agents using multiple leading models. The system is designed to find, validate, and remediate vulnerabilities, with agentic code scanning feeding into Project Perception, a new agentic security system for continuous monitoring and patching.
The model underwent rigorous evaluation by Microsoft’s AI Red Team, automated and expert-led adversarial exercises, and independent third-party assessment. Microsoft cites 1.6 million customers and more than 100 trillion security signals every day as part of its reinforcement learning loop, providing a foundation for models that improve continuously. The company argues that this scale allows it to connect actions to outcomes, distinguishing what was exploitable from what was contained.
MDASH includes enterprise-grade controls such as Role-Based Controls, tenant isolation, encryption, auditability, and sandboxed execution environments with no internet access. These features are intended to provide the governance and security controls that enterprises expect, ensuring that the powerful capabilities of the new models do not compromise operational safety or data privacy.


