Microsoft's MDASH AI Security System Unleashes 16 New Windows Vulnerabilities
Microsoft has developed an AI-powered security system called MDASH that uses over 100 specialized AI agents to find vulnerabilities in code before attackers do. In its debut, the system discovered 16 previously unknown vulnerabilities in Windows networking and authentication components, including four critical remote code execution flaws.
The system runs a multi-stage pipeline covering preparation, scanning, validation, deduplication, and proofing, using different AI models at each stage. This approach allows MDASH to outperform its competitors, scoring 88.45% on the public CyberGym benchmark, which tests real-world vulnerability detection capabilities.
Microsoft has also released a companion model called MAI-Cyber-1-Flash, which scored 96% on the same benchmark as a standalone system. All 16 newly discovered vulnerabilities were patched in the May 2026 Patch Tuesday update, demonstrating that MDASH is not just finding bugs in a lab but real-world issues that need to be addressed.
MDASH supports all major programming languages and can accommodate proprietary codebases, making it potentially useful for auditing Solidity, Rust, or Move-based smart contracts. The system is currently available in a limited private preview through Azure commercial cloud regions, with key partners like CyberOne already engaged.