Update: Microsoft's Project Perception security agents hit preview
MAI-Cyber-1-Flash scores 95.95% on CyberGym at half the cost; red/blue/green agents auto-patch through Defender and Azure AI Foundry, with human sign-off.

Copy markdown
A custom model, MAI-Cyber-1-Flash, does the heavy lifting
The new MAI-Cyber-1-Flash — a code-tuned MAI-Thinking-1 derivative trained on Microsoft's exploit and remediation records — handles about 90% of the vulnerability workload, deferring to GPT-5.4 for the hardest 10%. It scores 95.95% on CyberGym's 1,507 reproduction tasks, roughly 12 points over Claude Mythos, at about half the cost of leading models.
Red probes, blue triages, green patches
Three agent classes run continuously across endpoints, identities, clouds and apps: red agents attack like adversaries, blue agents investigate and rank the real threats, and green agents write and deploy the fixes. Actuators let them act rather than just alert — but high-impact changes still need a human to sign off.
How to try it, and what it meters
Preview opens today inside Microsoft Defender, with API access on Azure AI Foundry the same day, subject to customer vetting. Billing is consumption-based in Security Compute Units (SCUs), so different agents burn credits at different rates depending on how intense the task is.
Elsewhere: Google pulls Earth's AI image tool in a day
Google removed the new Gemini-powered image generator from Google Earth less than 24 hours after launch, after it fabricated satellite imagery including a nonexistent nuclear facility. If you were eyeing AI-generated geospatial imagery for a build, that door just closed for now.