News

Microsoft unveils MDASH AI security platform after finding 16 Windows flaws

Microsoft has unveiled MDASH, a new AI-powered vulnerability discovery platform that has already helped its researchers identify 16 previously unknown flaws in Windows components, including four critical remote code execution vulnerabilities.

The platform, short for Multi-Model Agentic Scanning Harness, was built by Microsoft’s Autonomous Code Security Team in partnership with the Windows Attack Research and Protection group. Microsoft says the system orchestrates more than 100 specialised AI agents to analyse code, reason about possible vulnerabilities, validate findings and support remediation at scale.

The vulnerabilities found by MDASH affected a range of Windows networking and authentication components, including the Windows TCP/IP stack, IKEEXT IPsec service, HTTP.sys, Netlogon, DNS resolution and the Telnet client. Ten of the flaws were in kernel mode and six were in user mode.

Among the most serious were four critical remote code execution vulnerabilities. Two highlighted flaws include CVE-2026-33827, a remote unauthenticated use-after-free issue in tcpip.sys, and CVE-2026-33824, a double-free vulnerability in the IKEv2 service reachable over UDP port 500. The flaws were patched as part of Microsoft’s May security updates.

Microsoft says MDASH is designed to reduce one of the biggest problems in vulnerability discovery: false positives. During testing, researchers planted 21 vulnerabilities and the system reportedly found all of them without generating false positives. The company also reported strong benchmark results, including 96 per cent recall against five years of confirmed Microsoft Security Response Center cases in clfs.sys, 100 per cent recall in tcpip.sys, and an 88.45 per cent score on the public CyberGym benchmark of 1,507 real-world vulnerabilities.

The system is now being used internally by Microsoft security engineering teams and is being tested by a small group of customers in private preview. Microsoft has framed MDASH as part of a shift from AI security research into production-grade defensive tooling.

The announcement comes as major technology companies race to apply advanced AI systems to cybersecurity. Anthropic’s Mythos Preview has attracted attention for its ability to identify complex software flaws, while OpenAI has also been expanding trusted access to cyber-focused model capabilities for verified defenders. Microsoft’s announcement suggests the competition may not rest on any single model, but on the systems built around models to coordinate tasks, validate findings and turn research into patches.

For defenders, the implications are significant. AI tools that can help find vulnerabilities faster may reduce the time dangerous flaws remain hidden in widely used software. But the same class of technology also raises concern that attackers could accelerate their own vulnerability discovery, making patching speed, secure development and defensive readiness more important.

MDASH also shows that AI is unlikely to replace human security teams outright. Microsoft’s results depended on a system of specialised agents, validation steps, engineering workflows and expert oversight. The value is not simply in asking a model to find bugs, but in building a structured process that can turn AI reasoning into reliable security outcomes.

The broader lesson for businesses and individuals is clear: cybersecurity is changing quickly, and the skills needed to understand and respond to modern threats are changing with it.

Knowledge is power. Upskill your cybersecurity awareness and strengthen your digital defences with The Hack Academy’s online courses: https://training.thehackacademy.com/course/

Leave a Reply

Your email address will not be published. Required fields are marked *