Microsoft just dropped what might be the most consequential AI security tool of the year, and it has nothing to do with chatbots writing your emails. The company’s new MDASH system, short for Microsoft Security multi-model agentic scanning harness, uses more than 100 specialized AI agents working together to find vulnerabilities in code before attackers do.
In its debut, the system discovered 16 previously unknown vulnerabilities in Windows networking and authentication components. Four of those were critical remote code execution flaws. In English: the kind of bugs that let someone take over your machine from across the internet.
How MDASH actually works
Think of MDASH less like a single security scanner and more like an entire security team compressed into software. The system runs a multi-stage pipeline covering preparation, scanning, validation, deduplication, and proofing. Each stage uses different specialized AI models rather than relying on a single large language model to do everything.
The results speak for themselves. MDASH scored 88.45% on the public CyberGym benchmark, which tests real-world vulnerability detection capabilities. That’s roughly five points ahead of the nearest competitor. Internal testing was even more impressive: a 96% recall rate on historical clfs.sys cases and a perfect 100% on tcpip.sys tests. Zero false positives on 21 planted vulnerabilities.
















