Top
Best
New

Posted by migmartri 3 hours ago

MAI-Cyber-1-Flash inside MDASH(microsoft.ai)
186 points | 98 comments
gste 2 hours ago|
> Data. Our deepest advantage. Decades of building world-class security systems now give us trillions of daily signals across identity, endpoint, cloud, and network, and an unmatched record of real exploits and remediations. No one can manufacture this history.

If I'm being frivolous, does this mean Microsoft's model is best at fixing Microsoft products because they have trillions of data points on problems with Microsoft products

tolugenius 2 hours ago||
> does this mean Microsoft's model is best at fixing Microsoft products

"You're absolutely right, I shouldn't have delete your entire C drive. That's on me."

In serious, this would be a good advantage for Microsoft to consider, I just doubt they'd do it well.

risyachka 1 hour ago||
Considering they can't fix their login for decades, I am with you on this one
wtfHN26 1 hour ago|||
> If I'm being frivolous, does this mean Microsoft's model is best at fixing Microsoft products because they have trillions of data points on problems with Microsoft products

Do they want to fix Microsoft Products ?

My laptop came with Windows 11. Windows update broke hibernate few weeks back. When laptop gets out of hibernate - Wifi works for a few minutes and then once in a while the Wifi Adapter isn't detected. I need to reboot to fix the issue, this has screwed up my workflow. Wasting a lot of time.

After troubleshooting a lot, I now only hope one day it gets fixed on it's own thanks to some new update.

If Microsoft has money to invest in AI models, they could sure fix Windows 11 which I assume is one of their core products.

I wish in a few years Microsoft realize that screwing over their Desktop users to chase Cloud and AI wasn't worth it. And by that time it's too late to get back the user base.

delecti 1 hour ago|||
> If Microsoft has money to invest in AI models, they could sure fix Windows 11 which I assume is one of their core products.

On the other hand, what's the return on investment for making Windows 11 better? Your laptop came with Windows 11. Most laptops that come with Windows can't not come with Windows (that is, most laptops are only available in SKUs that ship with Windows).

wtfHN26 25 minutes ago||
> what's the return on investment for making Windows 11 better?

Windows OS is what keeps most users in Microsoft's ecosystem.

I am still on Windows as some software I need to use aren't on Linux.

I am waiting for the day that I can get rid of Windows completely.

When I do that what Microsoft product do you think I will still use ? Office ? Azure ? Copilot ? :)) Outlook ?

No MSFT product ever!

Will I ever recommended Microsoft's products to my clients - Never

Sure, Microsoft has a grip on Enterprise.

Let's see how long that lasts if Windows keeps going downhill.

cyanydeez 1 hour ago|||
Escaping their programming ability, Window's major issue is everything has backwards compability, so they design everything with spaghetti because they have no choice.
wtfHN26 16 minutes ago|||
> Escaping their programming ability, Window's major issue is everything has backwards compability, so they design everything with spaghetti because they have no choice.

I do agree with you on this.

But as a consumer that's not my concern.

I am at least a Windows user since three decades, I know my way around the OS and did extensive troubleshooting. What happens to a normal Windows user ?

I have developed habits and workflow on my machine to optimize my time. Now every time I get back to work I am hoping that it works coming out of hibernate.

Is that how a modern OS should be ?

I have a Windows 10 machine that has stopped getting updates. I am satisfied with that.

I consider that Windows 10 machine 'reliable' now that Microsoft isn't breaking things for me.

AnthonyMouse 55 minutes ago||||
Backwards compatibility was the one thing Windows got right. It was the only real reason to use it.

But backwards compatibility isn't actually that hard if you're not horrendously mismanaged to begin with. You have some ancient miserable APIs from the 1990s that you still have to support, fine, but that's not actually that bad. Old APIs tend to be small because computers were small that far back, you write a compatibility layer and can keep using it. By definition the old stuff never changes so you only have to do it once.

The actual problem is that Microsoft is full of little fiefdoms. Because what they should do, after becoming a huge behemoth with the resources to do it (which has been the case for more than two decades), is to design a set of good, modern APIs, also only once. Something that you're happy to support forever because you took the time to get it right. Then you only have to support that and the little compatibility layer for truly ancient software.

Instead, they have an army of middle managers who are practically at war with each other to show that they can introduce some kind of novel "improvement", the vast majority of which quickly fall out of favor but then have to be supported indefinitely if you don't want to break backwards compatibility. And that makes backwards compatibility a huge ordeal because every year there is more poorly-engineered rubbish you have to support forever.

gkbrk 1 hour ago|||
Wine has better backwards-compatibility than Windows these days.
genxy 39 minutes ago||
The Windows Compatibility Layer for Windows will be Wine someday.
omosubi 1 hour ago|||
what company would be better positioned for this than MS? almost every company out there runs their most important workflows on MS software
theDoug 2 hours ago||
I do hope they also use it to that effect.
bonoboTP 1 hour ago||
Poking one hole in the walls will always be easier than guarding the entire frontier.

To defend properly, you need either either much more formally mathematically verified layers, or always-on online monitoring and intrusion detection running alongside the service. Like the immune system, or like guarding an empire's borders, since you can't put a guard on every meter of border. But you can detect when someone broke in and deploy your soldiers to respond. Currently we are trying to defend by building really hard walls that we hope cannot be pierced anywhere, which isn't realistic.

zurfer 2 hours ago||
It looks cool but how can I use it? Somehow i don't want to go hunting for access through the rabbit hole that is Microsofts Corporate blog.
SwellJoe 2 hours ago||
All the US companies are keeping their "cyber" models locked down for special customers. So, it seems like anyone who isn't at a Fortune 500 or whatever qualifies for access, will be using Chinese models for vulnerability research.
ronsor 1 hour ago||
And the Chinese models are great because they don't nag you
bvttf 2 hours ago|||
You probably can't, they say they're adding it to MDASH, which is (I think) still in a limited preview: https://www.microsoft.com/en-us/security/blog/2026/05/12/def...
adrian_b 2 hours ago||
Yes, it says:

"Sign up to join the private preview"

superloika 2 hours ago|||
It's a big club, and you ain't in it!
fallingbananna 2 hours ago||
MAI-Code-1-Flash is available via GitHub Copilot.

I wouldn't be surprised if they added MAI-Cyber 1 there too.

cbg0 2 hours ago||
I would, most of these cybersecurity models have not been made available to the public and the larger models have guardrails in place for certain cybersecurity tasks unless you've been specifically approved.
eat 2 hours ago||
[flagged]
low_tech_punk 2 hours ago||
> Three things matter today: Model. Data. Harness.

*knee jerk*

smallmancontrov 2 hours ago|||
To whoever got rid of the emoji bullet points: if we ever meet, I owe you a beer. Keep up the good work.
testdelacc1 2 hours ago|||
Guys, I just had a brilliant idea. Hear me out. What if … I wrote the release post of the model with the model itself???
binsquare 2 hours ago||
And we can have the model read and train on it too, completing the loop!
cwillu 1 hour ago||
It's not just a loop; it's a knot!
phoghed 1 hour ago|||
Author dismayed to find the semicolon find and replace in fact did not trick anyone
walrus01 1 hour ago|||
Cue the Steve Ballmer "developers developers developers developers" video. Bonus points if extra sweaty.
drakythe 1 hour ago|||
I want to sit down with a sales person who doesn't work in tech day to day and see if they can recognize this kinda thing or if its only people looking for it and who have experience in the domain.
cmrdporcupine 2 hours ago||
It's bad enough the cringe-word "cyber" being tossed around willy nilly. Now it's robots doing the tossing, in Claude-slop sentences.

(Having lived through the late 90s .com stuff, I can't see the word "cyber" without immediately assuming the person who wrote it is a clueless baby boomer. Unfortunately it seems to have become accepted into the lexicon. I guess by us now-clueless GenXers?)

bigfishrunning 1 hour ago|||
The government uses the word 'cyber' all over their security documents, and have since the mid-90s. It is indeed very cringe.
eterm 1 hour ago||
I think it's kinda cool, it's Gibsonesque, and that usage is old enough now it's rolled from awkwardly dated back to cool, especially now that people no longer tend to talk about "cybersex" and many of the other uses of "cyber".

You've got to call it something, and calling it "cyber" differentiates it from all the other kinds of security. I doubt it means much to talk about "security" to the government, that could as much mean a missile system, but I don't know, that's not my area of work.

To us developers who work with computing all day it feels cringe because the cyber part is implied, and "security" is the differentiator., so you can just talk about working in "security" or "infosec".

Is "cyber" a bit of a relic that dates when the government started taking it seriously? Of course, but I don't know if there is a good alternative that doesn't have other connotations. It probably also acts as a bit of a shibboleth in both directions, "cyber" for those in the government sphere, "infosec" in the commercial.

tigerlily 1 hour ago|||
I expect the gen xers are using the word in a cynical sense.
tesdinger 1 hour ago||
> Decades of building world-class security systems now give us trillions of daily signals across identity, endpoint, cloud, and network

Let's say i use a linux endpoint and some hardware vendor starting with Cisc on the network. Can your product help me or not? I'm pretty sure none of these have been meant by Microsoft..but they fall into this category

ecshafer 1 hour ago|
Azure is the second largest cloud, and run majority linux. So probably.
Oras 2 hours ago||
Take anything from Microsoft with grain of salt. Remember Phi?

They can’t decide on naming their product in Azure, let alone creating something useful or usable

shmed 21 minutes ago||
Phi was pretty revolutionary for its time. The accompanying paper https://arxiv.org/abs/2306.11644 has been pretty instrumental in pushing the idea of highly curated synthetic dataset to train model. The lead scientist behind Phi-1 is now VP at OpenAI and leading their own synthetic training dataset effort.
weberer 2 hours ago|||
Remember Tay AI?

https://knowyourmeme.com/sensitive/memes/sites/tay-ai

paulmist 1 hour ago||
I love this video on Tay

https://www.youtube.com/watch?v=HsLup7yy-6I

vessenes 44 minutes ago|||
Phi was smart (or had a smart training architecture, more precisely), and arguably pushed the conversation forward globally on the value of curated training data.
samuelknight 2 hours ago||
Phi was cool for what it was. But it's not 2024 anymore.
LorenDB 2 hours ago||
Open weights, please? Otherwise Cisco's Antares models are more interesting to me.
lucrbvi 2 hours ago||
Seems like MAI models from Microsoft are not going to be open-weight soon, but they are sharing a lot of details in the making of these models, which is a weird position.
tolugenius 2 hours ago||
I think the idea is show in-house progress and perhaps position MAI models as the "microsoft office of AI." My take is they might open source models 2-3 release cycles later, given this is supposed to be some new product line.
SwellJoe 2 hours ago||
They haven't even released the "big" version of Anteres, yet (and the "big" version is only 3B, so there's no way it's competitive with general purpose frontiers for vulnerability research). It seems like a research project. Maybe it's good for rapid triage and CI usage, but almost certainly not at all useful for general "find bugs" usage.
beyonddream 1 hour ago||
I wish they took some time to reflect on how best to name a model. Like, would it make sense to add the model version at the end like every other artifacts labelled in software engineering!
drevil-v2 2 hours ago||
This feels like it was written by Claude. I noticed several "it's not x, not y, it's z" claude-isms in the blog post.

And I am 90% sure that Claude design was used to build the website.

debesyla 2 hours ago||
It also can be human author, influenced by LLM writing. Though I'm not sure which is worse.
saadn92 2 hours ago||
we have a lot of upper management using AI to write their messages now and it's pretty obvious. not sure how I feel about it.
drevil-v2 2 hours ago||
> not sure how I feel about it

Same. I feel amused, disgusted and disdain at the same time.

Sprinkle in some irritation that even for a big product launch not a single human in the chain could be bothered to sit down and devote their attention to writing a page on why this product matters and why we should care..

chvid 1 hour ago|
How much of this security related stuff is open source? Models, training data, evaluation benchmarks?
More comments...