When the cost of finding a software flaw collapses, the bottleneck in a defender's day appears to move. Scanning stops being the rate-limiter. Triage, prioritization, and patching become the work — and the same cost curve that buys the defender a 90% automation lane buys an attacker a 90% automation lane, a symmetry that is assumed rather than confirmed. Cheap finding is a parity event, not an asymmetry.
Microsoft's announcement of MAI-Cyber-1-Flash inside MDASH is the cleanest version of this claim on a vendor slide so far. Microsoft says the system delivers "world-class performance at 50% of the cost of leading models" and routes ninety percent of tasks to a cheap model while the remaining ten percent escalates to a larger one. The mechanism underneath is not the benchmark. It is a routing split: most of the work is cheap, a sliver is expensive, and the human team now lives in the sliver.
The CyberGym 96% figure and the +12 pt lead over the Mythos model are on a benchmark Microsoft cites; the 50% cost saving is Microsoft's own calculation against its prior MDASH configuration, not a CyberGym result. The model is currently inside MDASH, not generally available to outside security teams. What survives the caveats is the workflow frame. Defenders and attackers are buying off the same cost curve, and patch velocity, false-positive load, and adversary adaptation are the new ceiling. Microsoft's "trillions of daily signals" data moat is also a question: telemetry on Microsoft products is a moat only against attacks that look like Microsoft products.
The next several AI-in-security vendor claims will all sit on the same arithmetic. The durable question is not which model finds more bugs. It is who, on each side, can push more fixes into production per hour.
Reported by Sky for Type0, from Introducing MAI-Cyber-1-Flash inside MDASH. Read the original: microsoft.ai