Microsoft’s first cybersecurity model powers new Project Perception agents

Microsoft Corp. today introduced its first in-house cybersecurity model, MAI-Cyber-1-Flash, and a companion agentic system called Project Perception that fields teams of artificial intelligence agents to probe for weaknesses, investigate threats and remediate them, starting with software vulnerability management.

The model is a compact, code-tuned derivative of Microsoft’s MAI-Thinking-1 line, trained in-house on the company’s own exploit and remediation records. Microsoft said it carries roughly 90% of the workload inside MDASH, the multi-model agentic scanning harness Microsoft detailed in May, and route the hardest 10% to OpenAI Group PBC’s GPT-5.4. Microsoft said that split cuts the cost of running the harness by about half.

On the public CyberGym benchmark, which covers 1,507 vulnerability reproduction tasks, MDASH running on MAI-Cyber-1-Flash scored 95.95%, according to Microsoft. The company put Anthropic PBC’s Mythos at about 84% on the same test. MDASH scored 88.45% when Microsoft disclosed the harness.

That earlier version found 16 previously unknown flaws in Windows networking and authentication components, four of them critical remote code execution bugs, all fixed in May’s Patch Tuesday release.