

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- How much of this security related stuff is open source? Models, training data, evaluation benchmarks?by chvid
- This feels like it was written by Claude. I noticed several "it's not x, not y, it's z" claude-isms in the blog post.
And I am 90% sure that Claude design was used to build the website.
by drevil-v2 - It also can be human author, influenced by LLM writing. Though I'm not sure which is worse.by debesyla
- we have a lot of upper management using AI to write their messages now and it's pretty obvious. not sure how I feel about it.by saadn92
- I wish they took some time to reflect on how best to name a model. Like, would it make sense to add the model version at the end like every other artifacts labelled in software engineering!by beyonddream
- All these different names and version numbers are too confusing. Just name every single model "Copilot". /sby ooterness
- I can't even joke about Microsoft, I just feel pity for them. So long at the game and reduced from a dominating software house to slop fabric with no professional honor to deliver a product with certain quality level.
Their cash cow customers are doofuses that decide over government contracts to be wined & dined, their best employees use macbooks, it's a sad shell of what has been.
by bflesch - I think Microsoft is the terminal state of a big tech company. Big tech companies will all eventually carcinize into Microsoft given enough time.by mherkender
- Ignoring my first immediate knee-jerk reaction to the blog and taking it at face value - I do tend to agree with Alex Karp on data becoming the moat for enterprises. Hyperscalers and the like are not different - it makes 0 sense to make swaths of business’s alpha available to potential future competitors. Even if MS and OAI are “friends”. Balkanization of cyber seems inevitable.by antondd
- > Decades of building world-class security systems now give us trillions of daily signals across identity, endpoint, cloud, and network
Let's say i use a linux endpoint and some hardware vendor starting with Cisc on the network. Can your product help me or not? I'm pretty sure none of these have been meant by Microsoft..but they fall into this category
by tesdinger - Microsoft's security suite has been available for Linux for a long time, so I would imagine they have a tremendous amount of data. Sentinel connectors have been available for Cisc- since the beginning.by jhickok
- Azure is the second largest cloud, and run majority linux. So probably.by ecshafer
- Open weights, please? Otherwise Cisco's Antares models are more interesting to me.by LorenDB
- They haven't even released the "big" version of Anteres, yet (and the "big" version is only 3B, so there's no way it's competitive with general purpose frontiers for vulnerability research). It seems like a research project. Maybe it's good for rapid triage and CI usage, but almost certainly not at all useful for general "find bugs" usage.by SwellJoe
- Seems like MAI models from Microsoft are not going to be open-weight soon, but they are sharing a lot of details in the making of these models, which is a weird position.by lucrbvi
- Take anything from Microsoft with grain of salt. Remember Phi?
They can’t decide on naming their product in Azure, let alone creating something useful or usable
by Oras - Phi was cool for what it was. But it's not 2024 anymore.by samuelknight
- Remember Tay AI?by weberer
- Phi was smart (or had a smart training architecture, more precisely), and arguably pushed the conversation forward globally on the value of curated training data.by vessenes
- Phi was pretty revolutionary for its time. The accompanying paper https://arxiv.org/abs/2306.11644 has been pretty instrumental in pushing the idea of highly curated synthetic dataset to train model. The lead scientist behind Phi-1 is now VP at OpenAI and leading their own synthetic training dataset effort.by shmed
- Poking one hole in the walls will always be easier than guarding the entire frontier.
To defend properly, you need either either much more formally mathematically verified layers, or always-on online monitoring and intrusion detection running alongside the service. Like the immune system, or like guarding an empire's borders, since you can't put a guard on every meter of border. But you can detect when someone broke in and deploy your soldiers to respond. Currently we are trying to defend by building really hard walls that we hope cannot be pierced anywhere, which isn't realistic.
by bonoboTP - It looks cool but how can I use it? Somehow i don't want to go hunting for access through the rabbit hole that is Microsofts Corporate blog.by zurfer
- I've seen it come up in GitHub Copilot as a model.
- MAI-Code-1-Flash is available via GitHub Copilot.
I wouldn't be surprised if they added MAI-Cyber 1 there too.
- It's a big club, and you ain't in it!by superloika
- You probably can't, they say they're adding it to MDASH, which is (I think) still in a limited preview: https://www.microsoft.com/en-us/security/blog/2026/05/12/def...by bvttf
- All the US companies are keeping their "cyber" models locked down for special customers. So, it seems like anyone who isn't at a Fortune 500 or whatever qualifies for access, will be using Chinese models for vulnerability research.by SwellJoe
- > Data. Our deepest advantage. Decades of building world-class security systems now give us trillions of daily signals across identity, endpoint, cloud, and network, and an unmatched record of real exploits and remediations. No one can manufacture this history.
If I'm being frivolous, does this mean Microsoft's model is best at fixing Microsoft products because they have trillions of data points on problems with Microsoft products
by gste - I do hope they also use it to that effect.by theDoug
- what company would be better positioned for this than MS? almost every company out there runs their most important workflows on MS softwareby omosubi