Microsoft launches its first cybersecurity model, plus a new agentic cybersecurity system
Microsoft launches its first cybersecurity model, plus a new agentic cybersecurity system
微软发布首个网络安全模型及全新的智能体网络安全系统
Microsoft on Monday launched its first cybersecurity-specialized model alongside a new AI cybersecurity platform at a small event in San Francisco, taking a big swipe at major players in the space — namely Anthropic, Google, and OpenAI. 周一,微软在旧金山举行的小型发布会上推出了其首个网络安全专用模型,以及一个全新的 AI 网络安全平台,此举旨在向该领域的重量级竞争对手——即 Anthropic、谷歌和 OpenAI——发起强力挑战。
The company describes MAI-Cyber-1-Flash as a model that’s built “to find challenging vulnerabilities in complex codebases.” The model is built to animate MDASH, Microsoft’s harness dedicated to software vulnerability identification and remediation. 微软将 MAI-Cyber-1-Flash 描述为一款旨在“在复杂代码库中发现高难度漏洞”的模型。该模型旨在驱动 MDASH,即微软专门用于软件漏洞识别和修复的框架。
The new security platform is dubbed Perception, and it’s designed to deploy teams of agents to assist with and automate various security workflows, including identifying and remediating bugs. The platform can also integrate with MDASH. 这个全新的安全平台被命名为 Perception,旨在部署多个智能体团队,以协助并自动化各种安全工作流程,包括识别和修复漏洞。该平台还可以与 MDASH 集成。
The company claims MAI-Cyber-1-Flash is significantly more powerful (and more cost-effective) than competitor models, based on its performance on an established AI cybersecurity benchmark. 微软声称,基于其在权威 AI 网络安全基准测试中的表现,MAI-Cyber-1-Flash 比竞争对手的模型更强大(且更具成本效益)。
“We’re very very excited to announce our results,” said Mustafa Suleyman, the co-founder of DeepMind and current CEO of Microsoft AI. “We have MAI-1 Cyber Flash binded [sic] with GPT 5.4 inside of the MDASH harness — which beats out Gemini, GPT 5.5 Cyber, GPT 5.6 Sol, and Mythos 5 on Cyber Gym, which is the primary benchmark that we all use. The golden benchmark.” “We’re shipping this into production immediately,” he added. “我们非常、非常激动地宣布我们的测试结果,”DeepMind 联合创始人兼现任微软 AI 首席执行官 Mustafa Suleyman 表示,“我们将 MAI-1 Cyber Flash 与 GPT 5.4 绑定在 MDASH 框架内,在 Cyber Gym(我们共同使用的主要基准测试,即‘黄金基准’)上击败了 Gemini、GPT 5.5 Cyber、GPT 5.6 Sol 和 Mythos 5。”他补充道:“我们正立即将其投入生产环境。”
Noting that hackers are increasingly using AI in their cyberattacks, Hayete Gallot, Microsoft’s vice president for security, described Perception as a way for enterprise defenders to “defend against AI with AI at the scale and speed that the attackers have.” 微软安全副总裁 Hayete Gallot 指出,黑客正越来越多地利用 AI 发动网络攻击,她将 Perception 描述为企业防御者的一种手段,旨在“以攻击者所具备的规模和速度,利用 AI 来防御 AI”。
Perception uses agentic red teams, blue teams, and green teams. The red teams can provide detailed simulations of potential attacks — providing context about potential threat actors and the likely vulnerabilities that they might exploit. Blue teams are dedicated to detecting and triaging existing bugs, while green teams take “corrective actions” against those bugs. Perception 使用智能体红队、蓝队和绿队。红队可以提供潜在攻击的详细模拟,提供有关潜在威胁行为者及其可能利用的漏洞的背景信息。蓝队致力于检测和分类现有漏洞,而绿队则针对这些漏洞采取“纠正措施”。
Dave Weston, the lead engineer for Perception, described the platform as a massive efficiency upgrade for corporate defenders. “We’ve gone from this taking hours and hours of manual work from multiple specialized folks across the security organization — appsec hunters, remediation engineers, you name it — and in minutes, we have a fix for all of this. Not only do we discover the issues and prioritize them, but we have detection, posture fixing, and even a code fix.” Perception 的首席工程师 Dave Weston 将该平台描述为企业防御者效率的巨大提升。“过去,这需要安全组织中多名专业人员(如应用安全猎手、修复工程师等)耗费数小时的手动工作,而现在,我们只需几分钟就能解决所有问题。我们不仅能发现并优先处理问题,还能实现检测、安全态势修复,甚至直接提供代码修复。”
Though AI has offered new defensive capabilities to companies, its availability to cybercriminals has given rise to a dazzling array of potential threats. Microsoft’s new security tools, which the company said will be available in preview on November 3, will enter an increasingly crowded field of AI cybersecurity solutions. 尽管 AI 为企业提供了新的防御能力,但它对网络犯罪分子的可获取性也引发了令人眼花缭乱的潜在威胁。微软表示,其新的安全工具将于 11 月 3 日开启预览,并将进入一个竞争日益激烈的 AI 网络安全解决方案市场。
Earlier this year, Anthropic launched Mythos, a security platform that was released to a small coterie of partner organizations through a program called Glasswing. OpenAI has also launched its own security solution in May through a program called Daybreak. 今年早些时候,Anthropic 推出了 Mythos,这是一个通过名为 Glasswing 的项目向少数合作伙伴组织发布的安全平台。OpenAI 也在 5 月通过名为 Daybreak 的项目推出了自己的安全解决方案。