Microsoft AI · 2026-07-27 · major
Microsoft MAI-Cyber-1-Flash — 96% on CyberGym at half the price of the GPT-5.4 stack
MAI-Cyber-1-Flash is a compact security model derived from MAI-Thinking-1 that pushes Microsoft's MDASH scanning harness to 96% on CyberGym while cutting inference cost roughly in half versus the prior GPT-5.4-heavy stack.

Microsoft's new security-specialist model plugs into MDASH and finds bugs cheaper and better than a GPT-5.4 stack.
Quick facts
| Maker | Microsoft AI |
|---|---|
| Model | MAI-Cyber-1-Flash |
| Lineage | Derived from MAI-Thinking-1 |
| CyberGym (with MAI-Cyber-1-Flash) | 95.95% |
| CyberGym (combined with GPT-5.4) | 96% (+12 pts vs Mythos) |
| Cost | 50% less than the GPT-5.4 + 5.4 mini + 5.3 codex stack |
| Availability | Inside MDASH; not a standalone API |
What is it?
MAI-Cyber-1-Flash is a compact, code-heavy security model that Microsoft AI announced on 27 July 2026 and ships inside MDASH, its multi-agent vulnerability scanning harness. The model is derived from the MAI-Thinking-1 reasoning family and specialised for finding and patching code flaws.
How does it work?
Inside MDASH, more than a hundred agents explore a codebase, plan possible attacks, and try patches. MAI-Cyber-1-Flash carries out roughly 90% of those steps on its own, and only the hardest 10% of sub-tasks route to GPT-5.4, 5.4 mini, and 5.3 codex for a final call. Microsoft says the model was tuned on the ~100 trillion daily security signals it sees across its own infrastructure.
Why does it matter?
On CyberGym, the new MDASH stack scores 96% — about 12 points above Anthropic's Mythos — while cutting inference cost roughly in half versus the previous GPT-5.4-heavy configuration. For enterprise security teams that goal was previously out of reach on price: cheaper autonomous bug-finding means large SOCs can afford to scan critical codebases continuously instead of on a schedule.
Who is it for?
Enterprise security teams, SOC engineers, and red teamers on Microsoft 365 or Azure
Frequently asked questions
- Can I call MAI-Cyber-1-Flash directly?
- MAI-Cyber-1-Flash is not offered as a standalone API. Microsoft AI ships the model inside MDASH, its multi-agent scanning harness that finds and remediates code vulnerabilities. Enterprise teams get it as part of that platform, with role-based access controls, tenant isolation, encryption, auditability, and sandboxed execution built in.
- How does MAI-Cyber-1-Flash change MDASH's benchmark?
- MDASH driven by MAI-Cyber-1-Flash scores 95.95% on CyberGym, and the combined stack that routes the hardest 10% of steps to GPT-5.4 reaches 96%. Microsoft says that is about 12 points above Anthropic's Mythos and outperforms Gemini and GPT variants on the same code-vulnerability benchmark.
- Why is the new MDASH cheaper than the old one?
- MAI-Cyber-1-Flash is small and code-heavy, so it handles about 90% of MDASH's security steps on its own. Only the remaining 10% of the hardest sub-tasks route to GPT-5.4, 5.4 mini, and 5.3 codex. Microsoft says that mix cuts inference cost roughly in half versus running the previous, more GPT-heavy configuration.
- What is MAI-Cyber-1-Flash trained on?
- MAI-Cyber-1-Flash is a compact, code-heavy model derived from Microsoft's MAI-Thinking-1 reasoning family. Microsoft tuned it on the roughly 100 trillion daily security signals it sees across Windows, Azure, Microsoft 365, and its 1.6 million security customers, then specialised it for finding and patching software vulnerabilities.
Try it
Available inside Microsoft's MDASH platform (no standalone API)