> Data. Our deepest advantage. Decades of building world-class security systems now give us trillions of daily signals across identity, endpoint, cloud, and network, and an unmatched record of real exploits and remediations. No one can manufacture this history.
If I'm being frivolous, does this mean Microsoft's model is best at fixing Microsoft products because they have trillions of data points on problems with Microsoft products
> If I'm being frivolous, does this mean Microsoft's model is best at fixing Microsoft products because they have trillions of data points on problems with Microsoft products
Do they want to fix Microsoft Products ?
My laptop came with Windows 11. Windows update broke hibernate few weeks back.
When laptop gets out of hibernate - Wifi works for a few minutes and then once in a while the Wifi Adapter isn't detected.
I need to reboot to fix the issue, this has screwed up my workflow. Wasting a lot of time.
After troubleshooting a lot, I now only hope one day it gets fixed on it's own thanks to some new update.
If Microsoft has money to invest in AI models, they could sure fix Windows 11 which I assume is one of their core products.
I wish in a few years Microsoft realize that screwing over their Desktop users to chase Cloud and AI wasn't worth it.
And by that time it's too late to get back the user base.
It's bad enough the cringe-word "cyber" being tossed around willy nilly. Now it's robots doing the tossing, in Claude-slop sentences.
(Having lived through the late 90s .com stuff, I can't see the word "cyber" without immediately assuming the person who wrote it is a clueless baby boomer. Unfortunately it seems to have become accepted into the lexicon. I guess by us now-clueless GenXers?)
All the US companies are keeping their "cyber" models locked down for special customers. So, it seems like anyone who isn't at a Fortune 500 or whatever qualifies for access, will be using Chinese models for vulnerability research.
I would, most of these cybersecurity models have not been made available to the public and the larger models have guardrails in place for certain cybersecurity tasks unless you've been specifically approved.
I've been noticing the uptick of beige + serif fonts + art with rough textures in this space. It feels like an attempt to humanize the technology and make it more palatable to people. Anthropic is the biggest example of this language with its ads and promotions.
Seems like MAI models from Microsoft are not going to be open-weight soon, but they are sharing a lot of details in the making of these models, which is a weird position.
I think the idea is show in-house progress and perhaps position MAI models as the "microsoft office of AI." My take is they might open source models 2-3 release cycles later, given this is supposed to be some new product line.
They haven't even released the "big" version of Anteres, yet (and the "big" version is only 3B, so there's no way it's competitive with general purpose frontiers for vulnerability research). It seems like a research project. Maybe it's good for rapid triage and CI usage, but almost certainly not at all useful for general "find bugs" usage.
curious-- does anyone have experience with the remediation capabilities of MDASH? they mention it a few times, but the test on CyberGym only gives me pause-- that is only for creating POCs, nothing to do with creating patches.
I know... Hovering over Accessibility Mode in the bottom left displays like it is clickable, but alas, only the tiny off button inside the pill is really clickable. I clicked on the text one too many times before realizing it wasn't actually selectable...
Same. I feel amused, disgusted and disdain at the same time.
Sprinkle in some irritation that even for a big product launch not a single human in the chain could be bothered to sit down and devote their attention to writing a page on why this product matters and why we should care..
Not surprising considering out of all the things MS is known for, UX consistency is certainly not one of them. They have probably the weakest commitment to a design language across all the big tech cos.
MAI is supposed to have its own design language/brand identity that is unrelated to the overall Microsoft brand. It has its own fonts, logo, colors, etc. The weird thing is that consumer Copilot, which is (or was) developed at MAI (as opposed to business/M365 Copilot which is developed in Redmond and designed based on the regular Microsoft stuff) also has its own design language which is different from the regular Microsoft stuff and different from the MAI stuff.
tbh all of this has always struck me as an ego thing from the MAI team, who are mostly based in Silicon Valley, not Redmond, and think of themselves as too cool for Microsoft
and it seems this site was generated with ai and then not reviewed before publishing. the layout of the content below the header doesn't really make sense and the "LI X FB" for LinkedIn, X, and Facebook is super unintuitive until you click one - and even after clicking one, i thought it was a collaboration between LinkedIn and Facebook tbh. then the animations are jarring and don't obey my reduced motion system settings, which isnt uncommon but i would expect it from Microsoft. finally, the "Explore all jobs" button at the bottom is just bizarrely designed and animated.
It's a trend that signals a form of non-chronically-online intellectualism. Feels reminiscent of intellectual slop [1] content on the web that is in vogue
Ignoring my first immediate knee-jerk reaction to the blog and taking it at face value - I do tend to agree with Alex Karp on data becoming the moat for enterprises. Hyperscalers and the like are not different - it makes 0 sense to make swaths of business’s alpha available to potential future competitors. Even if MS and OAI are “friends”. Balkanization of cyber seems inevitable.
I can't even joke about Microsoft, I just feel pity for them. So long at the game and reduced from a dominating software house to slop fabric with no professional honor to deliver a product with certain quality level.
Their cash cow customers are doofuses that decide over government contracts to be wined & dined, their best employees use macbooks, it's a sad shell of what has been.
> Data. Our deepest advantage. Decades of building world-class security systems now give us trillions of daily signals across identity, endpoint, cloud, and network, and an unmatched record of real exploits and remediations. No one can manufacture this history.
If I'm being frivolous, does this mean Microsoft's model is best at fixing Microsoft products because they have trillions of data points on problems with Microsoft products
> If I'm being frivolous, does this mean Microsoft's model is best at fixing Microsoft products because they have trillions of data points on problems with Microsoft products
Do they want to fix Microsoft Products ?
My laptop came with Windows 11. Windows update broke hibernate few weeks back. When laptop gets out of hibernate - Wifi works for a few minutes and then once in a while the Wifi Adapter isn't detected. I need to reboot to fix the issue, this has screwed up my workflow. Wasting a lot of time.
After troubleshooting a lot, I now only hope one day it gets fixed on it's own thanks to some new update.
If Microsoft has money to invest in AI models, they could sure fix Windows 11 which I assume is one of their core products.
I wish in a few years Microsoft realize that screwing over their Desktop users to chase Cloud and AI wasn't worth it. And by that time it's too late to get back the user base.
> does this mean Microsoft's model is best at fixing Microsoft products
"You're absolutely right, I shouldn't have delete your entire C drive. That's on me."
In serious, this would be a good advantage for Microsoft to consider, I just doubt they'd do it well.
I do hope they also use it to that effect.
> Cybersecurity is not just a data-rich domain; it is a live reinforcement learning loop.
*twitch*
> Three things matter today: Model. Data. Harness.
*knee jerk*
To whoever got rid of the emoji bullet points: if we ever meet, I owe you a beer. Keep up the good work.
Guys, I just had a brilliant idea. Hear me out. What if … I wrote the release post of the model with the model itself???
And we can have the model read and train on it too, completing the loop!
It's bad enough the cringe-word "cyber" being tossed around willy nilly. Now it's robots doing the tossing, in Claude-slop sentences.
(Having lived through the late 90s .com stuff, I can't see the word "cyber" without immediately assuming the person who wrote it is a clueless baby boomer. Unfortunately it seems to have become accepted into the lexicon. I guess by us now-clueless GenXers?)
I expect the gen xers are using the word in a cynical sense.
The government uses the word 'cyber' all over their security documents, and have since the mid-90s. It is indeed very cringe.
It looks cool but how can I use it? Somehow i don't want to go hunting for access through the rabbit hole that is Microsofts Corporate blog.
All the US companies are keeping their "cyber" models locked down for special customers. So, it seems like anyone who isn't at a Fortune 500 or whatever qualifies for access, will be using Chinese models for vulnerability research.
And the Chinese models are great because they don't nag you
You probably can't, they say they're adding it to MDASH, which is (I think) still in a limited preview: https://www.microsoft.com/en-us/security/blog/2026/05/12/def...
Yes, it says:
"Sign up to join the private preview"
It's a big club, and you ain't in it!
MAI-Code-1-Flash is available via GitHub Copilot.
I wouldn't be surprised if they added MAI-Cyber 1 there too.
I would, most of these cybersecurity models have not been made available to the public and the larger models have guardrails in place for certain cybersecurity tasks unless you've been specifically approved.
I love this pretentious design the Ai people use on their websites, its pleasing to the eye
I've been noticing the uptick of beige + serif fonts + art with rough textures in this space. It feels like an attempt to humanize the technology and make it more palatable to people. Anthropic is the biggest example of this language with its ads and promotions.
It's very corporate hotel chain lobby restaurant inspired, which probably resonates with the C-suite people signing the checks on this stuff.
> its pleasing to the eye
Which is precisely why I've preferred the Solarized Light Theme for years now.
Take anything from Microsoft with grain of salt. Remember Phi?
They can’t decide on naming their product in Azure, let alone creating something useful or usable
Remember Tay AI?
https://knowyourmeme.com/sensitive/memes/sites/tay-ai
Phi was cool for what it was. But it's not 2024 anymore.
How much of this security related stuff is open source? Models, training data, evaluation benchmarks?
Open weights, please? Otherwise Cisco's Antares models are more interesting to me.
Seems like MAI models from Microsoft are not going to be open-weight soon, but they are sharing a lot of details in the making of these models, which is a weird position.
I think the idea is show in-house progress and perhaps position MAI models as the "microsoft office of AI." My take is they might open source models 2-3 release cycles later, given this is supposed to be some new product line.
They haven't even released the "big" version of Anteres, yet (and the "big" version is only 3B, so there's no way it's competitive with general purpose frontiers for vulnerability research). It seems like a research project. Maybe it's good for rapid triage and CI usage, but almost certainly not at all useful for general "find bugs" usage.
curious-- does anyone have experience with the remediation capabilities of MDASH? they mention it a few times, but the test on CyberGym only gives me pause-- that is only for creating POCs, nothing to do with creating patches.
WTH is this sloppy UI design
I know... Hovering over Accessibility Mode in the bottom left displays like it is clickable, but alas, only the tiny off button inside the pill is really clickable. I clicked on the text one too many times before realizing it wasn't actually selectable...
This feels like it was written by Claude. I noticed several "it's not x, not y, it's z" claude-isms in the blog post.
And I am 90% sure that Claude design was used to build the website.
It also can be human author, influenced by LLM writing. Though I'm not sure which is worse.
we have a lot of upper management using AI to write their messages now and it's pretty obvious. not sure how I feel about it.
> not sure how I feel about it
Same. I feel amused, disgusted and disdain at the same time.
Sprinkle in some irritation that even for a big product launch not a single human in the chain could be bothered to sit down and devote their attention to writing a page on why this product matters and why we should care..
Is it just me or do all the proprietary AI model companies have their blogs styled to have earthy calming tones? This seems like a strategy.
Exhibit A-C
A. https://claude.com/blog B. https://microsoft.ai/news/introducing-mai-cyber-1-flash-insi... C. https://cursor.com/grok
Only OpenAI's blog looks like the WordPress _Twenty Twenty Five_ theme.
The Gemini team uses the standard Google blue and white, which I would have thought Microsoft would be inclined to do as well
Not surprising considering out of all the things MS is known for, UX consistency is certainly not one of them. They have probably the weakest commitment to a design language across all the big tech cos.
MAI is supposed to have its own design language/brand identity that is unrelated to the overall Microsoft brand. It has its own fonts, logo, colors, etc. The weird thing is that consumer Copilot, which is (or was) developed at MAI (as opposed to business/M365 Copilot which is developed in Redmond and designed based on the regular Microsoft stuff) also has its own design language which is different from the regular Microsoft stuff and different from the MAI stuff.
tbh all of this has always struck me as an ego thing from the MAI team, who are mostly based in Silicon Valley, not Redmond, and think of themselves as too cool for Microsoft
and it seems this site was generated with ai and then not reviewed before publishing. the layout of the content below the header doesn't really make sense and the "LI X FB" for LinkedIn, X, and Facebook is super unintuitive until you click one - and even after clicking one, i thought it was a collaboration between LinkedIn and Facebook tbh. then the animations are jarring and don't obey my reduced motion system settings, which isnt uncommon but i would expect it from Microsoft. finally, the "Explore all jobs" button at the bottom is just bizarrely designed and animated.
It's better than Corporate Memphis, at least.
It's a trend that signals a form of non-chronically-online intellectualism. Feels reminiscent of intellectual slop [1] content on the web that is in vogue
https://www.youtube.com/shorts/dEYvdnwB4MM
I despise that kind of shorts/reels/videos. Like who talks that fast and my brain immediately lose interest and it's obnoxious and unnatural.
I love how the discussion here isn't taking ms seriously lol
Ignoring my first immediate knee-jerk reaction to the blog and taking it at face value - I do tend to agree with Alex Karp on data becoming the moat for enterprises. Hyperscalers and the like are not different - it makes 0 sense to make swaths of business’s alpha available to potential future competitors. Even if MS and OAI are “friends”. Balkanization of cyber seems inevitable.
I can't even joke about Microsoft, I just feel pity for them. So long at the game and reduced from a dominating software house to slop fabric with no professional honor to deliver a product with certain quality level.
Their cash cow customers are doofuses that decide over government contracts to be wined & dined, their best employees use macbooks, it's a sad shell of what has been.