OFICIAL Microsoft Source

Codename MDASH brings agentic AI cybersecurity to the US government

What happened
Based on Microsoft Source · Sep 08, 2026

Microsoft introduces codename MDASH, an AI-driven agentic scanning system for US government agencies to proactively detect and address software vulnerabilities in critical systems.

Codename MDASH brings agentic AI cybersecurity to the US government
Microsoft Source — Microsoft
Key points
·
Codename MDASH deploys on Microsoft Azure Government for select US government customers and authorized partners.
·
The system uses over 100 AI agents to detect vulnerabilities and a second group to validate findings, reducing false positives.
·
Codename MDASH scored 96.55 on the CyberGym benchmark for real-world vulnerabilities.

Microsoft unveiled codename MDASH, a multi-model agentic scanning system designed to identify subtle software vulnerabilities in government systems that traditional tools often miss. Deployed on Microsoft Azure Government, it is accessible to select US government customers and authorized partners, aiming to shift the advantage to defenders against sophisticated cyber threats. The system focuses on complex flaws that could be exploited by well-resourced attackers, addressing weaknesses invisible to pattern-based scanners.

Codename MDASH operates as an agentic code scanner, reasoning about software like an expert security researcher to validate exploitable vulnerabilities. It employs over 100 specialized AI agents, each trained to detect different categories of weaknesses, followed by a second group of agents that debate the validity of each suspected flaw. The system merges and deduplicates results, and where possible, demonstrates flaws rather than merely asserting them, reducing false positives for security teams.

The system scored 96.55 on the CyberGym benchmark for real-world vulnerabilities and has produced similar results on Microsoft’s historical cases. Its multi-model, multi-step approach allows for robust analysis, increased cost effectiveness, and flexibility to adopt newer models without redesigning the system. Disagreement or agreement between models enhances confidence in findings, ensuring agencies benefit from continuous improvements in AI capabilities.

Codename MDASH is available in Azure Government as part of Microsoft Defender, integrated with FedRAMP High-authorized Microsoft Foundry service. This ensures agency source code and analysis remain within approved boundaries for handling sensitive data. Microsoft has used the system internally for months, and government agencies are now exploring its capabilities to reduce the time gap between vulnerability discovery and patching.

Original source → Deals on Clipraptor.com →