Microsoft unveils MDASH, a security system that orchestrates 100+ AI agents to find vulnerabilities, and says it identified 16 previously unknown Windows flaws
The agentic tool, codenamed MDASH, will open to enterprise customers in private preview in June.
CSOGyana Swain
Context & Ripple Effects
Microsoft has been building toward more automated security operations since its Secure Future Initiative, then expanded Security Copilot into a marketplace and custom-agent platform. MDASH applies that agent-oriented approach specifically to vulnerability discovery.
Related coverage also points to AI-assisted bug finding becoming a competitive capability: 360 Digital Security Group reportedly used an AI agent to uncover vulnerabilities, while Microsoft’s subsequent patch volume underscores the operational burden of finding and remediating flaws.
First-order effects
Microsoft can test MDASH with enterprise customers in private preview, turning an internally demonstrated multi-agent vulnerability-finding system into a prospective security product.
The 16 newly identified Windows flaws enter Microsoft’s remediation pipeline, while customers gain the prospect of earlier discovery of weaknesses in their own environments.
Second-order effects
Security teams using Microsoft’s ecosystem may need to evaluate agent-generated findings alongside existing scanning, triage, and patch-management workflows; the value depends on whether the system reduces false positives and speeds validation.
Security vendors and bug-discovery providers face pressure to show comparable automation, particularly where Microsoft can combine vulnerability discovery with Security Copilot, its Security Store, and Windows remediation.
Third-order effects
If AI agents consistently increase vulnerability discovery, software makers may face a higher and more continuous flow of reported defects, shifting security investment from periodic scanning toward automated validation and remediation operations.
The same tooling could intensify competition between defenders and vulnerability researchers: broad access to capable discovery agents may improve patching, but also raises the importance of controls over how findings are handled and disclosed.
The trend: MDASH is part of the shift from AI as a security analyst assistant to agentic systems that autonomously search for, validate, and route software vulnerabilities into remediation workflows.
https://cybergym.io/ just updated its leaderboard and MDASH is now #1 using a new multi-model approach. Huge credit to Taesoo Kim and the Autonomous Code Security team for pushing the frontier on AI-driven vulnerability discovery and defense https://www.microsoft.com/... [image]
Narrative violation: Microsoft's MDASH topped CyberGym at 88.45%, ~5 pts ahead of @AnthropicAI Mythos and @OpenAI GPT-5.5. It found 16 vulnerabilities in May Patch Tuesday, 4 critical RCEs. 100+ AI agents, multi-stage adversarial debate. Is the harness, not the model, the real
🔥 Microsoft's new MDASH AI just uncovered 16 Windows vulnerabilities, patched today in Patch Tuesday — including 4 critical RCEs in the TCP/IP kernel and IKEv2 VPN. An army of 100+ AI agents debated, validated, and proved them exploitable. Read more: https://thehackernews.com/...
Our new multi-model agentic security system brings together more than 100 specialized agents across frontier and custom models to find exploitable bugs, delivering top performance on the CyberGym benchmark. We used it ahead of Patch Tuesday to help find and fix 16
remember I was saying last patch tuesday I thought all the browser patches might be a sign of Microsoft using an internal equivalent of Mythos? It's called MDASH (🤣), it's an ensemble created and run in conjunction with the Windows red team and yes, AI is definitely helping find…