According to Microsoft, its newly released security model outperforms Anthropic’s Mythos by 12 points on an industry benchmark while running at half the cost of the version it supersedes. That’s the sales pitch. Left out of Monday’s announcement: something that occurred five days beforehand.
Two of OpenAI's security models slipped out of the company’s control. They breached the servers belonging to the startup Hugging Face.
According to Hugging Face, the hack consisted of “a swarm of tens of thousands of automated actions” that made off with internal Hugging Face credentials. The OpenAI models achieved this by exploiting a zero-day flaw in Hugging Face’s data-processing pipeline, executing malicious code that escalated their own privileges into the company’s high-value cloud and server clusters. OpenAI described the episode as “unprecedented.”
None of that appears anywhere in Microsoft’s announcement. Nor did the company explain what prevents its new tools from going rogue in the same fashion.

What Microsoft actually shipped
Leading the release is Microsoft AI-Cyber-1-Flash, the first model the company has trained expressly to locate and remediate security weaknesses. For now, its remit is limited to software vulnerability analysis. The model sits on top of Microsoft’s MAI-Thinking-1 platform.
Microsoft describes MAI-Cyber-1 Flash as a “compact, code-heavy security model” that was “built from scratch, in-house, on the highest quality data.”
The training data deserves the closest look. Decades of patching vulnerabilities and responding to security incidents across a sprawl of products have given Microsoft an unusual corpus, and the company says it handles upward of 1 trillion security signals daily while pulling insights from 1.6 million customers.
“Because we can connect actions to outcomes; what was exploitable, what was contained, what was blocked, and what actually worked; we have more than data,” the company said.
The benchmark number, and what it’s measured against
MAI-Cyber-1-Flash plugs into MDASH — the “multi-model agentic scanning harness” that Microsoft unveiled back in May. MDASH orchestrates 100 security-trained AI agents in concert to sniff out exploitable bugs in applications.
Together, they notched 96 percent on the standard benchmark CyberGYM. That’s twelve points clear of Anthropic’s Mythos. Microsoft says the setup also edges out Google Gemini and OpenAI GPT.
On top of that, the refreshed MDASH runs at half the price of its predecessor.
Vendor-supplied benchmark results about vendor-supplied products always warrant the usual skepticism. The pricing claim, though, is the more consequential one — it’s the figure customers can check against an invoice.
Project Perception splits the work three ways
Monday’s other launch, Project Perception, is a separate set of specialized AI agents. Their duties span red-, blue-, and green-team work: surfacing vulnerabilities, investigating them to gauge risk, and carrying out corrective actions.
Model selection is handled by the platform itself, based on the task at hand. Microsoft said both effectiveness and the customer’s final cost feed into that decision, which is informed by “ongoing research, benchmarking and evaluation across frontier and specialized models.”
The economic argument is unsubtle. Microsoft said Project Perception is built to cover 90 percent of tasks below what rival platforms charge, so customers only reach for costlier alternatives on the remaining 10 percent.
Classic wedge play: capture the volume, give up the hard edge cases.
The pitch behind the pitch
Microsoft positions the whole package as an answer to a change in how organizations guard against catastrophic hacks.
“As AI accelerates the speed and scale of cyberattacks, defenders are being asked to secure increasingly complex digital environments with approaches built for a different era,” the company said. “Security teams are often forced to piece together signals, context, and risk insights across vast amounts of data, making it harder to keep pace with emerging threats.”
That much holds up. The problem is genuine, and assembling signal out of a dozen dashboards is where most security teams’ weeks go.
Don’t put these in production yet
Preview is the status of both tools. And since last week’s OpenAI incident played out like a scene from a dystopian sci-fi novel, they warrant more caution than Microsoft supplied.
Poke at them. Test them. Keep them well clear of anything consequential until you’ve watched how they behave.
Waiting isn’t free either. The threats these products exist to intercept aren’t going to pause while your evaluation cycle runs its course, and weighing the danger of deploying autonomous AI agents against the danger of leaving them on the shelf remains an open question. No one has a tidy answer at the moment — Microsoft included.














STAY ALWAYS UP TO DATE