ai-cybersecuritytrade-pressNewsThe Broadside1 min read

Microsoft puts MDASH vulnerability-hunting AI into Azure Government

The limited preview names no agencies, provides zero vulnerability counts, and offers no benchmarks, an announcement in search of evidence.


TL;DR

Microsoft placed MDASH, an AI vulnerability-hunting system that deploys more than 100 AI agents to find exploitable software flaws, into limited preview on Azure Government. Both defense and civilian agencies are testing it, though Microsoft named none. The company's CTO said the tool is "uncovering previously unknown vulnerabilities and significantly improving the quality of the underlying code", then provided zero examples and zero counts to back the claim.

Microsoft's MDASH preview lands in a competitive field. Since April, Anthropic's Mythos model has driven the conversation around AI-powered vulnerability discovery, White House discussions about giving CISA access, Project Glasswing partners getting early looks, agency CIOs frustrated by the lack of guidance from ONCD. Microsoft is now planting its own flag in the same territory, with a different approach: more than 100 AI agents each hunting different weakness categories, and a second agent group verifying whether flagged flaws are actually reachable and exploitable.

But the announcement carries none of the evidence a CISO would need to evaluate it.

No vulnerability counts. No examples. No named agencies. No comparison benchmarks. Steve Faehl, Microsoft's CTO for U.S. public sector, offered the kind of quote that reads well in a press release and tells a practitioner nothing: the tool is "uncovering previously unknown vulnerabilities and significantly improving the quality of the underlying code." Trust us.

The multi-agent architecture is genuinely interesting as a structural hedge against the hallucination and false-positive problems that plague single-model vulnerability scanning. A hundred agents looking at the same codebase from different angles, with a verification layer, that's a real design choice worth watching when the data arrives.

For the security engineer or compliance director at a defense contractor: nothing changes Monday. MDASH is a limited preview with no procurement vehicle; last September's OneGov agreement didn't cover it, and Microsoft hasn't announced a timeline. When general availability comes, the question is whether the company ships benchmarks or just more adjectives.


Published ·Deep Fathom

Microsoft puts MDASH vulnerability-hunting AI into Azure Government — The Broadside