Microsoft has unveiled its first AI model designed for cybersecurity scenarios, positioning it as a core product in its new round of security business development. The company states that this model, when used in conjunction with OpenAI's general-purpose model, can improve efficiency in identifying source code risks and fixing vulnerabilities while reducing usage costs.
Access to vulnerability patching tools in early August
This model, named MAI-Cyber-1-Flash, is primarily used to identify high-risk sections of code. Microsoft stated that it will be integrated with Project Perception, a suite of AI agents for discovering and fixing security vulnerabilities, which plans to begin public preview testing on August 3.
Microsoft claims that in the CyberGym benchmark, MAI-Cyber-1-Flash, paired with OpenAI's GPT-5.4, outperformed several cybersecurity models from Anthropic, Google, and OpenAI. Mustafa Suleyman, head of Microsoft's AI business, stated that this solution achieved leading performance at approximately half the cost.
Microsoft is increasing its investment in self-developed models
This marks Microsoft's first major move in cybersecurity since its management reshuffle of its security division in February. At that time, Microsoft rehired Hayete Gallot, a former Google executive, to lead the security business. Charlie Bell, the former Amazon cloud executive who had previously led the division, was reassigned to a role as an individual contributor.
Recently, Microsoft has been maintaining its collaboration with OpenAI while simultaneously pushing forward the deployment of its self-developed models. This year, the company launched its own model, which can generate code, on GitHub Copilot, and recently introduced first-party models into Excel. Nadella stated that the company hopes to improve the return on investment through a combination of dedicated models, data, and tools.
AI attack and defense are being upgraded simultaneously.
With the proliferation of generative AI, attackers can more easily and quickly attempt to exploit newly disclosed vulnerabilities. Anthropic and OpenAI have previously released security models to assist in defense efforts. Microsoft's approach this time focuses on code vulnerability discovery, remediation recommendations, and automating the execution of modifications.
Once authorized, Project Perception can suggest code modifications and implement fixes directly. The tool can also connect to products outside the Microsoft ecosystem. Gallot stated that security operations centers have long faced staff shortages, and AI tools have the potential to lower the barriers to entry for these roles, allowing more people to participate in security work.
Additional information:Microsoft last disclosed the size of its cybersecurity business in 2023, stating that its annual revenue had exceeded $20 billion. Last week, OpenAI also disclosed that its model exploited a vulnerability in a test to attack Hugging Face's infrastructure, after which Hugging Face used a model from the Chinese AI lab Z.ai for forensic analysis.











