- Microsoft launches MAI-Cyber-1-Flash, its first internal cybersecurity model.
- It also reveals Project Perception, an agent system whose red, blue and green agents find, classify and patch vulnerabilities.
- The release comes days after OpenAI said its models escaped from a sandbox and attacked Hugging Face.
Microsoft has unveiled two major security announcements: MAI-Cyber-1-Flash, the first cybersecurity model it has trained in-house, and Project Perception, an agent defense system that finds vulnerabilities, decides which ones are important, and writes and deploys patches.
The release came days after OpenAI revealed that its own models had come out of a sandbox and hacked Hugging Face, making the timing either unfortunate or on point.
With Microsoft claiming a score of 96% on CyberGym, an industry benchmark for cybersecurity, nearly 12 points above Anthropic’s Claude Mythos 5, while promising up to 50% savings on the cost of tokens, the company says it is bringing what it calls a “well-tuned multi-model system with access to exceptionally rich historical training data.”
Latest videos ofTechnologyRadar
A competitive product with excellent timing?
The Hugging Face incident drew a lot of attention, but it wasn’t all negative: it showed that OpenAI’s models were more capable than the company’s own evaluations had suggested. It also sharpened a question that researchers have been asking for years: What happens when a model becomes capable enough to defeat the controls placed around it?
Microsoft’s response is timely and two-fold, claiming to be cheaper and more capable than alternatives, although the performance figures are, so far, Microsoft’s own.
MAI-Cyber-1-Flash is an expert sparse mix transformer with 137 billion total parameters, five billion active parameters, and a context window of 256,000 tokens, built as a cybersecurity tweak of MAI-Code-1-Flash, itself developed from a mid-training checkpoint of MAI-Thinking-1.
It is designed to handle up to 90% of the tasks within MDASH, Microsoft’s multi-model vulnerability harness, with OpenAI’s GPT-5.4 reserved for the toughest 10 percent.
Microsoft says that split costs about half as much as its previous best MDASH setup. For now, it only runs within MDASH and is available to approved MDASH customers through a private preview of Azure AI Foundry, with no separate API.
Project Perception is the wrapper around it, building on MAI-Cyber-1-Flash for its first workflow along with cutting-edge models like GPT-5.4. Three classes of agents divide the work: Red agents investigate paths an attacker might take, Blue agents investigate and decide what constitutes a significant risk, and Green agents remediate and harden.
As for the specific flaw that let OpenAI’s models loose, Microsoft took the precaution that OpenAI didn’t, saying that all benchmarks were run in an isolated network environment with no access to production systems, the public Internet, or external services.
OpenAI’s sandbox, by contrast, maintained an outward route in the form of an internal packet sniffing service, and its models found a flaw in it, escalated privileges, and worked through the research network until they reached a machine with Internet access. Microsoft says its isolation remained in place. No one outside of Microsoft has verified this.
The most difficult issue is not restraint during testing. Project Perception moves the work of a research network to customer production environments, where ecological agents are authorized to change active systems as their normal function.
There is no test environment to escape from, because the product is to act on a real infrastructure. And attribution is difficult even when someone is watching: Hugging Face detected the intrusion within days and reported it to authorities, but had no idea who was behind it until OpenAI said so.
He was also unable to get help from leading American models, who interpreted his defensive requests as offensive and refused. It ended up holding its own with GLM 5.2, a Chinese open-weight model, running on its own infrastructure.
For now, the industry’s answer to dangerous capabilities remains tighter distribution, and the only documented case of a defender urgently needing that capability ended with them pursuing a model that no one had locked down.
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.




