AI Cybersecurity
-
Microsoft MAI-Cyber-1-Flash + MDASH: a 5B model that found 16 Windows CVEs and hit 96% on CyberGym
Microsoft trained its first model built only for security. Not a general chatbot bolted onto a SOC — a cyber-specialized fine-tune of MAI-Code-1-Flash, sparse MoE, 137B total parameters but just 5B active, 256k context. Small and cheap on purpose. What it actually does MAI-Cyber-1-Flash lives inside MDASH, Microsoft’s multi-model vulnerability-scanning harness that discovers, validates, and… Continue reading
-
360 Tulongfeng & Yitianzhen — China’s cyber-AI agents fill the export-ban gap
The US banned non-Americans from Anthropic’s Mythos and Fable 5 on June 12. Two weeks later, Asia is building around the wall. What 360 actually shipped At ISC.AI 2026 in Beijing, 360 Security unveiled two AI agents. Tulongfeng hunts software vulnerabilities — point it at code and it finds exploitable flaws automatically. 360 claims it… Continue reading
-
Microsoft MDASH scores 88.45% on CyberGym, beating Anthropic Mythos and OpenAI GPT-5.5
Microsoft just put a number on the “agent swarm vs single super-model” debate, and the swarm won. MDASH — short for multi-model agentic scanning harness — hit 88.45% on the public CyberGym benchmark, about five points ahead of Anthropic’s Mythos (83.1%) and OpenAI’s GPT-5.5 (81.8%). What MDASH actually is Not a model. A cybersecurity agent… Continue reading
-
OpenAI Daybreak ships with five top security vendors — a direct shot at Claude Mythos
OpenAI dropped Daybreak on May 12 with Cisco, Cloudflare, CrowdStrike, Palo Alto Networks, and Zscaler signed on as launch partners. That lineup is the actual news. The product is OpenAI’s first dedicated cybersecurity platform — a Codex-Security-based agent that reads your repo, builds an editable threat model, and runs the exploits in a sandbox to… Continue reading
-
Anthropic Claude Security goes public beta after 500+ CVEs found in closed preview
Anthropic just moved Claude Security from closed preview to public beta. Claude Enterprise gets it first, Team and Max next. Opus 4.7 reads your entire codebase, traces data flows across files and modules, and tells you exactly where you’re bleeding. What the agent actually does It lives inside Claude Code on the web and runs… Continue reading
-
GPT-5.5-Cyber: OpenAI forks a security model with looser guardrails for vetted red teams
OpenAI shipped GPT-5.5-Cyber on May 7, 2026 — a fork of GPT-5.5 with the cybersecurity guardrails dialed back. Vetted defenders can have it write proof-of-concept exploits, run attack simulations, and validate vulnerabilities — work that gets a polite refusal in standard ChatGPT. How the split works Two tracks, one model family. Standard GPT-5.5 stays the… Continue reading
-
OpenAI Trusted Access for Cyber opens GPT-5.5 to offensive security work — for verified defenders only
OpenAI is splitting its safety stack. Trusted Access for Cyber is a verified-user tier that unlocks GPT-5.5’s offensive security capabilities — vulnerability research, exploit chain reasoning, red-team payload work — for vetted defenders. Codex is the first surface to ship it. First time a frontier lab has formalized a cyber-permissive track. Vetted users get a… Continue reading
