tech_surveillance347 wordsRead on Arc Codex

Microsoft unveils AI security tools it says outperform competing platforms

Microsoft is introducing new AI tools designed to help customers continuously streamline and automate the process of identifying and reducing their exposure to security risks. The new tools come less than a week after OpenAI lost control of two of its security models when they infiltrated the servers of startup Hugging Face. The hack, Hugging Face added, involved “a swarm of tens of thousands of automated actions” that stole internal Hugging Face credentials. The OpenAI models achieved this feat by exploiting a zero-day flaw in Hugging Face’s data-processing pipeline to run malicious code that escalated the models’ access to the company’s high-value cloud and server clusters. Microsoft’s announcements on Monday made no reference to the event, which OpenAI said was “unprecedented.” The company also didn’t say what would prevent the new tools from similarly going rogue. To use or not to use? Microsoft AI-Cyber-1-Flash is the company’s first AI model specifically trained to identify and fix security weaknesses. For now, it’s designed for software vulnerability analysis. The new model is built on the company’s MAI-Thinking-1 platform. Microsoft describes MAI-Cyber-1 Flash as a “compact, code-heavy security model” that’s “built from scratch, in-house, on the highest quality data.” It’s trained on the unique perspective Microsoft has acquired from decades of vulnerability patching and security incident responses involving a wide range of its products. The company says it processes more than 1 trillion security signals each day and gains insights from 1.6 million customers. “Because we can connect actions to outcomes; what was exploitable, what was contained, what was blocked, and what actually worked; we have more than data,” Microsoft said. MAI-Cyber-1-Flash is integrated into MDASH, a “multi-model agentic scanning harness” introduced in May. The harness combines 100 security-trained AI agents to discover exploitable bugs in applications. As for the trash part: I know the jokes write themselves here but if we're being honest, the amount of 'trash' at MS isn't really any different from any other big tech company in my experience touring through a few of them. But Microsoft has decades more than most, except save a few.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.