Microsoft unveils new cyber model, agentic security tools to fight hackers
Add Axios as your preferred source to
see more of our stories on Google.

Illustration: Aïda Amer/Axios
Microsoft introduced a new cyber-specific AI model and AI-powered security agents designed to help organizations identify, prioritize and patch software vulnerabilities faster while responding more quickly to active cyber threats.
Why it matters: Cybersecurity and AI companies are racing to help defenders keep pace with attackers using increasingly capable AI models to automate hacking.
Driving the news: Microsoft unveiled its anticipated Project Perception platform at an event Monday in San Francisco.
- Project Perception is a security platform built around specialized AI agents that share security intelligence and work together to mirror the jobs performed by human security teams.
- The company introduced three initial agents — Red, Blue and Green — that can identify vulnerabilities, determine which flaws pose the greatest risk and write and deploy software patches.
- Microsoft also showed off MAI-Cyber-1-Flash, the first security model that the company has trained in-house.
- The model performs roughly 95% of the work done by Microsoft's MDASH vulnerability-finding system. More computationally intensive tasks are routed to GPT-5.4, David Weston, Microsoft's corporate vice president of AI security, told Axios.
The intrigue: Microsoft said combining MAI-Cyber-1-Flash with GPT-5.4 allows the system to achieve a 95.95% score on the CyberGym benchmark, which measures a model's ability to generate working proof-of-concept exploits for known software vulnerabilities.
- By comparison, competing models, including Anthropic's Mythos and OpenAI's GPT-5.5-Cyber, scored around 83%.
- Rather than releasing the model publicly, Microsoft will make MAI-Cyber-1-Flash available through Azure AI Foundry, using the company's existing customer vetting and GPU provisioning process, Weston said.
Between the lines: Weston said Microsoft intentionally built the smaller, specialized model to handle most vulnerability analysis, reserving larger frontier models only for the most difficult tasks, to reduce the cost of scanning large software repositories.
The big picture: Security vendors are increasingly rolling out specialized cyber models as organizations grapple with AI-driven attacks that can dramatically increase the speed of vulnerability discovery and exploitation. Microsoft follows similar announcements from Google and Cisco over the past week.
- "We're not going to let the attackers have all the productivity increase," Weston said.
Yes, but: Defenders remain cautious about turning security work over to autonomous AI agents.
- Weston said Microsoft expects organizations to gradually build trust in the technology before allowing agents to operate with greater independence, adding that the company still has to "earn the right" to make those systems more autonomous.
What's next: Microsoft said public preview of MAI-Cyber-1-Flash begins next week, and the company plans to expand Project Perception with additional specialized security agents over time.
