In brief
Microsoft says MDASH scored 95.95% on CyberGym, topping GPT-5.5 Cyber, Mythos 5, GPT-5.6 Sol, and Gemini 3.5 Flash Cyber.
MAI-Cyber-1-Flash handles up to 90% of the workload, while MDASH sends the hardest cases to GPT-5.4.
The scanner is in private preview through Microsoft Defender, where teams can review findings and generate proposed fixes.
Microsoft has released its first dedicated cybersecurity model named MAI-Cyber-1-Flash and plugged it into MDASH, a vulnerability-hunting system that it says beats Anthropic’s Mythos 5 and OpenAI’s GPT-5.6 Sol while costing 50% less than Microsoft’s current best MDASH configuration, according to the company.The combined setup scored 95.95% on CyberGym, according to Microsoft. CyberGym is a benchmark that asks AI agents to reproduce 1,507 known vulnerabilities across 188 open-source projects, then scores them by the percentage successfully reproduced in a controlled environment.That put MDASH ahead of GPT-5.5 Cyber at 85.6%, Mythos 5 at 83.8%, GPT-5.6 Sol at 83.6%, and Gemini 3.5 Flash Cyber at 83.2%. The result is self-reported by Microsoft and had not appeared on CyberGym’s public leaderboard at publication time, though the benchmark uses a public test set and a defined success metric.MAI-Cyber-1-Flash does not work alone. Microsoft says it handles up to 90% of tasks, while MDASH routes the hardest 10% to GPT-5.4. That matters because tokens—the chunks of text an AI processes—cost money every time a model reads code or produces an answer.Image: MicrosoftThis is the first time a Microsoft model built for efficiency is capable of beating a dense state of the art model built with general capabilities in mind. “When combined with MDASH, (MAI-Cyber-1-Flash) delivers world-class performance at 50 percent of the cost of leading models,” Microsoft CEO Satya Nadella wrote.












