
Microsoft AI announced MAI-Cyber-1-Flash inside MDASH, reporting a 96% CyberGym score and lower operating costs. Microsoft and Axios also linked the model to a broader AI security push called Project Perception.
Microsoft AI announced MAI-Cyber-1-Flash inside MDASH, a cybersecurity-focused AI system that the company says improves automated vulnerability analysis across large codebases.
In a post titled “Introducing MAI-Cyber-1-Flash inside MDASH,” Microsoft AI said the combined system reaches 96% on CyberGym, a benchmark used to evaluate how AI systems reason over large codebases to find real vulnerabilities. Microsoft AI said that result is 12 percentage points above Anthropic’s Mythos and that the system reduces costs by 50%.
Microsoft repeated the same performance claim in its Official Microsoft Blog post, “Rethinking security for the age of AI,” saying MAI-Cyber-1-Flash inside MDASH delivers 96% on CyberGym and outperforms Mythos by 12 points.
Axios reported that Microsoft introduced MAI-Cyber-1-Flash alongside other agentic security tools, and said Microsoft’s MAI-Cyber-1-Flash plus GPT-5.4 scored 95.95% on CyberGym, compared with roughly 83% for Mythos and GPT-5.5-Cyber. Decrypt also reported the 95.95% CyberGym figure, adding that Microsoft’s MDASH setup with MAI-Cyber-1-Flash was ahead of GPT-5.5 Cyber, Mythos 5, GPT-5.6 Sol, and Gemini 3.5 Flash Cyber.
Those results should be read as Microsoft-reported benchmark claims. Decrypt specifically noted that the result was self-reported, and none of the provided source excerpts indicate an independent third-party evaluation of the benchmark run.
Microsoft’s Official Microsoft Blog placed MAI-Cyber-1-Flash in a wider security strategy for the AI era. The company said Project Perception will use a multi-model architecture, and Axios reported that Microsoft introduced both MAI-Cyber-1-Flash and Project Perception as part of its effort to counter cyber threats with AI-assisted tools.
The announcement reflects a growing focus on models designed for security workflows rather than general-purpose chat alone. In Microsoft’s framing, the relevant task is not simply answering questions about code, but reasoning across large software projects to identify exploitable vulnerabilities. CyberGym is presented by Microsoft AI as the benchmark for that kind of codebase-level security reasoning.
The headline claim is straightforward: Microsoft says MAI-Cyber-1-Flash inside MDASH achieved about 96% on CyberGym while lowering costs by 50%. Reputable coverage from Axios and Decrypt reports similar numbers, and Microsoft’s own blog reinforces the performance claim.
What is less clear from the available sources is how the tests were administered, whether competing systems were evaluated under identical conditions, and how well CyberGym results translate into day-to-day defensive security work. The sources also do not provide enough detail to judge how the 50% cost reduction was calculated.
For now, MAI-Cyber-1-Flash is best understood as a Microsoft-reported advance in AI-assisted cybersecurity benchmarking, tied to the company’s broader push to apply multi-model systems to vulnerability discovery and security operations.
Microsoft AI announced MAI Cyber 1 Flash inside MDASH, a cybersecurity focused AI system that the company says improves automated vulnerability analysis across large codebases.
Microsoft AI said that result is 12 percentage points above Anthropic’s Mythos and that the system reduces costs by 50%.
Decrypt also reported the 95.95% CyberGym figure, adding that Microsoft’s MDASH setup with MAI Cyber 1 Flash was ahead of GPT 5.5 Cyber, Mythos 5, GPT 5.6 Sol, and Gemini 3.5 Flash Cyber.
Continue reading