ProBackend
agentic ai security risks
1 day ago6 min read

Microsoft's AI Security Push: FORGE Labs, Perception, and a Bug-Hunting Model

Microsoft announced MAI-Cyber-1-Flash, Project Perception, and FORGE Labs — a multi-model bug-hunting system hitting 95.95% on CyberGym benchmarks while cutting costs by half, alongside an unrestricted AI safety research initiative.

Microsoft's AI Security Push: FORGE Labs, Perception, and a Bug-Hunting Model

Microsoft's security event this week delivered three distinct announcements — a security-specialized AI model, an agentic defense system, and a new offensive research lab — but the most interesting angle is the company's decision to fund AI safety research without strings attached. The rest of the stack is impressive too, of course. The multi-model bug-hunting system, which Microsoft claims hit a 95.95 percent success rate on the CyberGym benchmark while costing roughly half what competing systems charge, is worth examining on its own merits. But the FORGE Labs initiative, led by VP of Security Research Taesoo Kim, signals something deeper: Microsoft wants to shape how AI security research happens across academia and industry, not just inside its own products.

That's the kind of long-game thinking that rarely makes headlines, but it might matter more than any single product announcement.

The Bug-Hunting Pipeline: MAI-Cyber-1-Flash Meets GPT-5.4

At the center of Microsoft's product announcements sits MAI-Cyber-1-Flash, a security-specialized model built on top of the company's internally developed MAI-Thinking-1 reasoning architecture. Microsoft stuffed this model into its MDASH bug-hunting harness and then paired it with GPT-5.4 — a much larger model, roughly ten times the size — to handle the harder queries.

Here's the architecture in practice. MAI-Cyber-1-Flash handles about 90 percent of all queries inside MDASH, detecting vulnerabilities, patching them, and confirming the fixes actually work. The remaining 10 percent — the ones that stump the smaller model — get handed off to GPT-5.4. The handoff isn't just a cost optimization. According to Mustafa Suleyman, CEO of Microsoft AI, the combined system delivers "better performance than all of the other models combined" while costing roughly half what other commercial alternatives charge.

"Really quite a remarkable result," Suleyman said during the Monday presentation. Those are his exact words, and whether you read that as understatement or deliberate modesty depends on who's writing the security budget.

The numbers from benchmarking firm CyberGym back up the claim, at least on paper. MAI-Cyber-1-Flash plus GPT-5.4 achieved a 95.95 percent success rate. OpenAI's GPT-5.5 Cyber scored 85.6 percent. GPT-5.6 Sol managed 83.6 percent. Anthropic's Mythos 5 hit 83.8 percent on real-world vulnerabilities. Google's Gemini 3.5 Flash Cyber in CodeMender achieved 83.2 percent.

That's a ten-point gap over the nearest competitors. In vulnerability hunting, where false negatives translate directly into exploited systems, that margin is worth paying attention to. (For context on how AI evaluation benchmarks themselves can be manipulated, see our coverage of the deception benchmarks revealing pervasive evaluator manipulation.)

Project Perception: Coordinated Agents for an Aggressive Threat Landscape

Also announced Monday was Project Perception, Microsoft's response to the accelerating pace of AI-driven attacks. Hayete Gallot, Microsoft's executive vice president of Security, put it bluntly: "We need to make sure that the defenders can defend at the scale and the speed of the attackers."

Her solution is a system that coordinates three types of autonomous agents. Red team agents find and simulate attack paths. Blue team agents investigate and determine risk levels. Green team agents actually remediate the issues. It's the kind of coordinated approach that's been discussed in security circles for years but rarely delivered on in practice.

"You need a new cyber stack. So we built it. This is what we call Perception," Gallot said. Whether Perception lives up to that ambition will depend on real-world deployments, not demo-day slides. (This mirrors the broader shift toward autonomous AI models reshaping the security frontier, as we explored in our analysis of agentic AI defense. It also raises the question of how organizations should approach securing autonomous agents when they become the primary line of defense.)

FORGE Labs: An Offensive Research Arm Goes Public

Beyond products, Microsoft announced something that gets less press attention but might have longer-lasting implications: Microsoft Security FORGE (Frontier Offensive Research and Generative Exploration) Labs. The name itself is a mouthful — FORGE stands for something, at least — but the direction it points is clear. Microsoft is investing in offensive security research at scale, and it's doing so through a dedicated organizational unit.

The lab is led by Taesoo Kim, Microsoft's VP of Security Research. Its mandate isn't to directly improve Microsoft's own products. Instead, it's focused on advancing offensive security research more broadly, which should benefit the entire security ecosystem.

This is where things get interesting. FORGE doesn't operate in isolation. It's paired with the External Red Team Alliance, or EXTRA, a two-part initiative that Microsoft's AI red team lead Ram Shankar Siva Kumar described in a blog post.

The first part of EXTRA involves "unrestricted gifts" to 18 university labs across six continents. The funding is deliberately unrestricted. As Siva Kumar put it: "The objective is not to direct research outcomes toward product requirements or predefined deliverables."

Some universities are examining how AI systems themselves can be attacked, manipulated, or abused in operational environments. Others are exploring the inverse problem — how AI can assist defenders and improve cyber operations. That split in research directions suggests Microsoft is trying to cover both sides of the AI security equation, which is a smart move given how fast the landscape shifts. (Against this backdrop of AI-amplified threats, including how autonomous agents can accelerate ransomware, the need for dedicated offensive research becomes even more apparent.)

The second part of EXTRA aims to build a distributed network of specialists who can participate in red teaming across very specific domains. "That includes researchers, practitioners, and regional experts who understand specific attack classes, languages, cultural contexts, or technical domains that internal teams may not fully cover alone," Siva Kumar wrote.

The Patch Tuesday Context

All of this comes against a backdrop of increasingly chaotic Patch Tuesday cycles. Microsoft itself recently warned customers that AI will mean busier Patch Tuesdays, and last month the company set a new record with 622 CVEs across its product lines. AI is finding countless previously hidden vulnerabilities at a rate that's keeping security teams up at night — and making Patch Tuesday (kinda) fun again, if you're into that sort of thing.

In that context, Microsoft's investment in both offensive research (FORGE) and defensive AI (MAI-Cyber-1-Flash, Perception) starts to look less like a product launch and more like an acknowledgment that the security landscape has fundamentally changed. The old playbook of reactive patching isn't working fast enough.

What This All Means

Microsoft's announcements paint a picture of an organization betting heavily on AI to solve problems that AI itself created. It's a circular approach, sure, but one that's becoming increasingly hard to ignore as threats grow more sophisticated and defense teams grow more stretched.

The cost advantages of the MAI-Cyber-1-Flash approach are compelling, especially for organizations that can't afford to throw unlimited compute at every security challenge. The 95.95 percent benchmark, while not perfect, puts Microsoft ahead of the competition on the metrics that matter most: catching real vulnerabilities before attackers do.

FORGE Labs and EXTRA represent a longer-term play. By funding unrestricted research across 18 universities and building a distributed red team network, Microsoft is trying to shape the AI security research ecosystem rather than just participating in it. That kind of influence, if it pans out, could be more valuable than any single product.

Whether these systems hold up in production remains to be seen. Demo results are one thing. Real-world deployments at scale are another. But for now, Microsoft has given security teams a new stack to evaluate, a new research community to participate in, and a reasonable argument that AI might actually be part of the solution rather than entirely the problem.

The Register, "Microsoft's solution to AI security: more AI and more acronyms," July 27, 2026.

More blogs