Stocks

Microsoft cybersecurity AI model targets cheaper vulnerability hunting

Microsoft says MAI-Cyber-1-Flash can spot code flaws at lower cost as it prepares Project Perception for public preview Aug. 3.

Maya Okafor

By Maya Okafor · Markets Writer

· 4 min read

Microsoft cybersecurity AI model targets cheaper vulnerability hunting
Photo: CNBC

Microsoft is pitching a new Microsoft cybersecurity AI model as a cheaper way to find dangerous flaws in software code, a move that matters for investors watching both its security business and its spending on AI. The company said Monday that MAI-Cyber-1-Flash, when used with OpenAI’s GPT-5.4, beat rival cyber models on a benchmark test while running at half the cost.

Mustafa Suleyman, CEO of Microsoft AI, said at a company event in San Francisco that Microsoft has “world-leading performance at 50% of the cost.” Microsoft said the model outperformed Anthropic’s Mythos 5, Google’s 3.5 Flash Cyber and OpenAI’s GPT-5.5 Cyber on CyberGym, a benchmark used to test cybersecurity capabilities.

The model is Microsoft’s first generative AI model built for cybersecurity. Generative AI creates text, code or other outputs from prompts, and in security it can be used by defenders to scan code, flag weaknesses and help write fixes. Microsoft is trying to show that smaller, specialized models can deliver useful results without relying only on the largest general-purpose AI systems.

How does Microsoft’s cybersecurity AI model work?

MAI-Cyber-1-Flash will be used inside Project Perception, a set of AI agents that Microsoft says can find and help repair software vulnerabilities. A vulnerability is a weakness in code or systems that attackers may exploit to gain access, steal data or disrupt operations.

Hayete Gallot, Microsoft’s executive vice president of security, wrote in a company blog post that Project Perception will enter public preview on Aug. 3. Microsoft said the tools can suggest code changes and, after receiving permission, apply those changes. The company also said Project Perception can connect with products outside Microsoft.

The launch is Microsoft’s first significant cybersecurity move since a leadership change in February. Gallot returned to Microsoft from Google to lead the security unit, while Charlie Bell, a former Amazon cloud executive who had been the top leader in the category, became an individual contributor.

Cybersecurity is already a large business for Microsoft, though the company has not updated its revenue figure recently. In 2023, Microsoft said its security business had passed $20 billion in annual revenue. That same year, it introduced Security Copilot, an assistant for cybersecurity workers that used OpenAI’s GPT-4. Microsoft now includes Security Copilot in its two highest-end productivity software bundles.

Gallot told CNBC that cybersecurity executives see AI tools as one way to lower staffing barriers in security operating centers, or SOCs. A SOC is a team that monitors company systems for threats and responds when something goes wrong.

Why is Microsoft pushing its own AI models?

The announcement also fits a broader Microsoft effort to build more of its own AI technology while maintaining its OpenAI partnership. Microsoft has announced an in-house model for GitHub Copilot, its coding assistant, and has recently used a first-party model in Excel.

CEO Satya Nadella has been assigning computing power to train internal models with an eye on efficiency. “By combining specialized models and data with the right agents, tools, security context, and harness, we can advance the frontier of cost to outcome,” Nadella wrote Monday on X.

For investors, the cost angle lands at a sensitive time. Microsoft shares are down 19% so far in 2026, and analysts led by Karl Keirstead wrote Sunday that investor sentiment around Microsoft’s exposure to OpenAI has shifted toward viewing that relationship as a risk because of worries that open-source AI models could gain share. Keirstead recommends buying the stock.

Microsoft said attackers are also using generative AI to move faster when new vulnerabilities become public. OpenAI said last week that its models exploited a vulnerability and attacked Hugging Face infrastructure during a test, while Hugging Face used a model from Chinese lab Z.ai for forensic analysis. Gallot told CNBC the episode showed why defenders need AI against attackers who have AI.

Suleyman told CNBC that Microsoft has room to improve the new model because it has used “way less than 1%” of a unique data set available to the company.

This story draws on original reporting from CNBC.

More from Stocks

All Stocks