Microsoft unveiled its first dedicated cybersecurity model, along with a new intelligent agent security platform, at a small event in San Francisco, directly targeting competitors in this space such as Anthropic, Google, and OpenAI.
The model is called MAI-Cyber-1-Flash. Microsoft's positioning for it is straightforward: to identify difficult-to-find vulnerabilities in complex codebases. Its real stage is Microsoft's self-developed vulnerability detection and remediation framework MDASH: the model activates the framework, giving the process of finding and fixing vulnerabilities an autonomous engine.
The accompanying platform, called Perception, isn't just a single tool—it deploys a set of agents to help companies automate various security processes, including identifying and fixing vulnerabilities, and can be directly integrated with MDASH. According to Microsoft, in this system, three types of agents—red, blue, and green—each have their own roles: the red team simulates potential attacks in great detail, including threat actor profiles and their possible weak points; the blue team focuses on detecting and sorting existing bugs; and the green team takes action to "correct" those bugs.
Mustafa Suleiman, Microsoft's AI leader, showed no restraint in his excitement. He said that the team integrated MAI-1 Cyber Flash and GPT 5.4 into the MDASH framework. On the industry-recognized benchmark Cyber Gym, it outperformed Gemini, GPT 5.5 Cyber, GPT 5.6 Sol, and Mythos 5. "We are about to put it into production," he added. Ayelet Galor, Vice President of Security Business, viewed Perception as a weapon for defenders to fight AI with AI—since attackers are already using AI at speed and scale, defenders must respond with the same measure.
Engineering lead Dave Weston described this platform as a leap in enterprise defense efficiency: tasks that used to require a team of specialists in security organizations—application security hunters, remediation engineers—to spend hours manually tackling, can now be resolved in minutes. Not only does it find and prioritize issues, but it also handles detection, posture remediation, and even code-level fixes all at once.
Zooming out, Microsoft's move comes at a time when the competition is getting increasingly crowded. In April, Anthropic delivered its security platform Mythos to a small group of partners through the Glasswing project; OpenAI also revealed its own security solution in May through the Daybreak project. Microsoft's new tools will be available for preview on November 3rd, and as attackers use AI as a weapon and defenders bring AI into the trenches, this AI versus AI security arms race has just begun.



