MAI-Cyber 1

(microsoft.ai)

111 points | by migmartri 1 hour ago

13 comments

  • gste 24 minutes ago
    > Data. Our deepest advantage. Decades of building world-class security systems now give us trillions of daily signals across identity, endpoint, cloud, and network, and an unmatched record of real exploits and remediations. No one can manufacture this history.

    If I'm being frivolous, does this mean Microsoft's model is best at fixing Microsoft products because they have trillions of data points on problems with Microsoft products

    • tolugenius 20 minutes ago
      > does this mean Microsoft's model is best at fixing Microsoft products

      "You're absolutely right, I shouldn't have delete your entire C drive. That's on me."

      In serious, this would be a good advantage for Microsoft to consider, I just doubt they'd do it well.

    • theDoug 18 minutes ago
      I do hope they also use it to that effect.
  • eat 45 minutes ago
    > Cybersecurity is not just a data-rich domain; it is a live reinforcement learning loop.

    *twitch*

    • low_tech_punk 41 minutes ago
      > Three things matter today: Model. Data. Harness.

      *knee jerk*

      • smallmancontrov 28 minutes ago
        To whoever got rid of the emoji bullet points: if we ever meet, I owe you a beer. Keep up the good work.
      • testdelacc1 35 minutes ago
        Guys, I just had a brilliant idea. Hear me out. What if … I wrote the release post of the model with the model itself???
        • binsquare 30 minutes ago
          And we can have the model read and train on it too, completing the loop!
  • drevil-v2 5 minutes ago
    This feels like it was written by Claude. I noticed several "it's not x, not y, it's z" claude-isms in the blog post.

    And I am 90% sure that Claude design was used to build the website.

    • saadn92 0 minutes ago
      we have a lot of upper management using AI to write their messages now and it's pretty obvious. not sure how I feel about it.
    • debesyla 2 minutes ago
      It also can be human author, influenced by LLM writing. Though I'm not sure which is worse.
  • zurfer 48 minutes ago
    It looks cool but how can I use it? Somehow i don't want to go hunting for access through the rabbit hole that is Microsofts Corporate blog.
    • SwellJoe 16 minutes ago
      All the US companies are keeping their "cyber" models locked down for special customers. So, it seems like anyone who isn't at a Fortune 500 or whatever qualifies for access, will be using Chinese models for vulnerability research.
    • superloika 3 minutes ago
      It's a big club, and you ain't in it!
    • bvttf 35 minutes ago
      You probably can't, they say they're adding it to MDASH, which is (I think) still in a limited preview: https://www.microsoft.com/en-us/security/blog/2026/05/12/def...
    • fallingbananna 39 minutes ago
      MAI-Code-1-Flash is available via GitHub Copilot.

      I wouldn't be surprised if they added MAI-Cyber 1 there too.

      • cbg0 30 minutes ago
        I would, most of these cybersecurity models have not been made available to the public and the larger models have guardrails in place for certain cybersecurity tasks unless you've been specifically approved.
  • mawadev 23 minutes ago
    I love this pretentious design the Ai people use on their websites, its pleasing to the eye
    • udbhavs 19 minutes ago
      I've been noticing the uptick of beige + serif fonts + art with rough textures in this space. It feels like an attempt to humanize the technology and make it more palatable to people. Anthropic is the biggest example of this language with its ads and promotions.
    • stronglikedan 11 minutes ago
      > its pleasing to the eye

      Which is precisely why I've preferred the Solarized Light Theme for years now.

  • Oras 26 minutes ago
    Take anything from Microsoft with grain of salt. Remember Phi?

    They can’t decide on naming their product in Azure, let alone creating something useful or usable

  • LorenDB 50 minutes ago
    Open weights, please? Otherwise Cisco's Antares models are more interesting to me.
    • lucrbvi 43 minutes ago
      Seems like MAI models from Microsoft are not going to be open-weight soon, but they are sharing a lot of details in the making of these models, which is a weird position.
      • tolugenius 17 minutes ago
        I think the idea is show in-house progress and perhaps position MAI models as the "microsoft office of AI." My take is they might open source models 2-3 release cycles later, given this is supposed to be some new product line.
    • SwellJoe 14 minutes ago
      They haven't even released the "big" version of Anteres, yet (and the "big" version is only 3B, so there's no way it's competitive with general purpose frontiers for vulnerability research). It seems like a research project. Maybe it's good for rapid triage and CI usage, but almost certainly not at all useful for general "find bugs" usage.
  • thallavajhula 39 minutes ago
    Is it just me or do all the proprietary AI model companies have their blogs styled to have earthy calming tones? This seems like a strategy.

    Exhibit A-C

    A. https://claude.com/blog B. https://microsoft.ai/news/introducing-mai-cyber-1-flash-insi... C. https://cursor.com/grok

    Only OpenAI's blog looks like the WordPress _Twenty Twenty Five_ theme.

    • andhug 15 minutes ago
      and it seems this site was generated with ai and then not reviewed before publishing. the layout of the content below the header doesn't really make sense and the "LI X FB" for LinkedIn, X, and Facebook is super unintuitive until you click one - and even after clicking one, i thought it was a collaboration between LinkedIn and Facebook tbh. then the animations are jarring and don't obey my reduced motion system settings, which isnt uncommon but i would expect it from Microsoft. finally, the "Explore all jobs" button at the bottom is just bizarrely designed and animated.
    • caminanteblanco 29 minutes ago
      The Gemini team uses the standard Google blue and white, which I would have though Microsoft would be inclined to do as well
      • udbhavs 17 minutes ago
        Not surprising considering out of all the things MS is known for, UX consistency is certainly not one of them. They have probably the weakest commitment to a design language across all the big tech cos.
    • smallmancontrov 12 minutes ago
      It's better than Corporate Memphis, at least.
    • udbhavs 8 minutes ago
      It's a trend that signals a form of non-chronically-online intellectualism. Feels reminiscent of intellectual slop [1] content on the web that is in vogue

      https://www.youtube.com/shorts/dEYvdnwB4MM

  • pranshuchittora 17 minutes ago
    WTH is this sloppy UI design
    • dkeners 2 minutes ago
      I know... Hovering over Accessibility Mode in the bottom left displays like it is clickable, but alas, only the tiny off button inside the pill is really clickable. I clicked on the text one too many times before realizing it wasn't actually selectable...
  • antondd 4 minutes ago
    Ignoring my first immediate knee-jerk reaction to the blog and taking it at face value - I do tend to agree with Alex Karp on data becoming the moat for enterprises. Hyperscalers and the like are not different - it makes 0 sense to make swaths of business’s alpha available to potential future competitors. Even if MS and OAI are “friends”. Balkanization of cyber seems inevitable.
  • bflesch 28 minutes ago
    I can't even joke about Microsoft, I just feel pity for them. So long at the game and reduced from a dominating software house to slop fabric with no professional honor to deliver a product with certain quality level.

    Their cash cow customers are doofuses that decide over government contracts to be wined & dined, their best employees use macbooks, it's a sad shell of what has been.

  • nttylock 33 minutes ago
    [flagged]
  • solenoid0937 49 minutes ago
    [flagged]
    • behole 33 minutes ago
      Exactly correct! I can see you have already been down-voted by the HN Elite. Bound to happen.