- Microsoft launches MAI-Cyber-1-Flash, its first internal cybersecurity model.
- It also reveals Project Perception, an agent system whose red, blue, and green agents find, triage, and remediate vulnerabilities.
- The launch comes days after OpenAI said its models escaped from a sandbox and attacked Hugging Face.
Microsoft unveiled two major security announcements: MAI-Cyber-1-Flash, the first cybersecurity model it trained internally, and Project Perception, an agent defense system that detects vulnerabilities, decides which ones are important, and writes and deploys patches.
The launch came days after OpenAI revealed that its own models had come out of a sandbox and hacked Hugging Face, making the timing either unfortunate or opportune.
While Microsoft claims a 96% score on CyberGym, an industry benchmark for cybersecurity, nearly 12 points above Anthropic’s Claude Mythos 5, while promising up to 50% savings on token costs, the company says it offers what it calls a “well-tuned multi-model system with access to uniquely rich historical training data.”
Latest videos fromTechRadar
A competitive product with excellent timing?
The Hugging Face incident attracted a lot of attention, but it wasn’t all negative: as it presented OpenAI’s models as performing better than the company’s own evaluations suggested. It also sharpened a question that researchers have been raising for years: What happens when a model becomes sufficiently capable of overcoming the controls placed around it?
Microsoft’s response is timely and two-fold, claiming to be both cheaper and more capable than alternatives, although the performance numbers are, so far, Microsoft’s own.
MAI-Cyber-1-Flash is an expert mix transformer with 137 billion total parameters, five billion active, and a popup of 256,000 tokens, built as a cybersecurity fine-tuning of MAI-Code-1-Flash, itself developed from a MAI-Thinking-1 mid-training checkpoint.
It is designed to handle up to 90% of tasks within MDASH, Microsoft’s multi-model vulnerability system, with OpenAI’s GPT-5.4 reserved for the most difficult 10%.
Microsoft says this split costs about half of its previous best MDASH configuration. For now, it only runs in MDASH and is available to approved MDASH customers through a private preview release of Azure AI Foundry, with no standalone API.
Project Perception is the shell, leveraging MAI-Cyber-1-Flash for its first workflow alongside pioneering models such as GPT-5.4. Three classes of agents divide the work: red agents look for paths an attacker might take, blue agents investigate and decide what constitutes a significant risk, and green agents remediate and harden.
Regarding the specific failure that let OpenAI’s models run amok, Microsoft took the precaution that OpenAI did not, as it says all benchmark testing took place in a network-isolated environment, with no access to production systems, the public Internet, or external services.
OpenAI’s sandbox, on the other hand, kept a path to the outside in the form of an internal packet fetching service, and its models found a loophole there, escalated privileges, and worked on the search network until they reached a machine with Internet access. Microsoft says its isolation has held up. No one outside of Microsoft has verified this.
The most difficult question is not confinement during testing. Project Perception moves work from a research network to client production environments, where green agents are allowed to modify live systems as part of their normal function.
There is no sandbox to escape from, because the product is operating on real infrastructure. And attribution is difficult even when someone is watching: Hugging Face detected the intrusion within days and reported it to law enforcement, but had no idea who was behind it until OpenAI said so.
She also could not get help from America’s leading role models, who interpreted her defensive demands as offensive and refused. It ended up defending itself with GLM 5.2, a Chinese open-weight model, running on its own infrastructure.
For now, the industry’s response to dangerous capabilities remains narrower distribution, and the only documented case of a defender urgently needing the capability ended with a search for a model that no one had vetted.
Follow TechRadar on Google News And add us as your favorite source to get our news, reviews and expert opinions in your feeds.




