MDASH

Microsoft
2026-08-22 17:32:46

Microsoft patches critical Entra ID flaw tied to potential remote code execution

Microsoft has disclosed and fixed a critical security flaw in Microsoft Entra ID, its cloud-based identity and access management platform formerly known as Azure Active Directory. The bug, tracked as CVE-2026-69836, received a CVSS score of 10.0, the highest possible severity rating. According to Microsoft’s advisory, the vulnerability could have allowed an unauthorized attacker to execute code remotely over a network without existing privileges and without any user interaction, while requiring only low attack complexity. Microsoft said it identified and remediated the issue before publishing the CVE. In a statement to Decrypt, a company spokesperson said the fix had already been put in place and that customers do not need to take any additional action. The company also said researchers later changed the exploitation status from “Yes” to “No,” describing the update as an informational revision and saying the flaw was neither publicly disclosed nor exploited in the wild. The disclosure also lands in a broader context: AI is taking on a larger role in vulnerability discovery. The report points to recent examples involving Anthropic’s Claude models and Microsoft’s own MAI-Cyber-1-Flash model inside MDASH, a system that uses more than 100 AI agents to identify and validate software vulnerabilities.

310
Microsoft patches critical Entra ID flaw tied to potential remote code execution
Nvidia
2026-07-28 09:33:08

Nvidia launches open secure AI alliance as Anthropic stays out of both letter and coalition

Nvidia CEO Jensen Huang used what the source describes as his second-ever X post to announce the Open Secure AI Alliance, a new coalition with 37 founding members spanning chipmakers, cloud companies, security firms, and open-source communities. The alliance argues that closed and open models should coexist, but says open models and testing harnesses are essential for cybersecurity work. The source draws a sharp contrast between the alliance roster and an earlier open-weight letter backed by 32 companies. Nvidia, Microsoft, Meta, Cisco, Dell, Hugging Face, IBM, Palantir, and SpaceXAI are described as backing both efforts. OpenAI and Google later signed the public letter but did not join the alliance. Anthropic, according to the report, did neither. The article also links the alliance’s case to a July security incident disclosed by Hugging Face and later claimed by OpenAI on July 21. In that account, commercial frontier models refused to analyze attack logs because of guardrails, while Hugging Face used the open-source model GLM 5.2 on its own infrastructure to review more than 17,000 actions and cut forensic work from days to hours. The source further argues that Nvidia’s push for open models also aligns with its interest in expanding the market for local GPU computing as major AI customers pursue in-house chips.

1340
Nvidia launches open secure AI alliance as Anthropic stays out of both letter and coalition
Microsoft
2026-07-27 19:01:04

Microsoft unveils MAI-Cyber-1-Flash, says MDASH tops Mythos and GPT-5.6 Sol on CyberGym

Microsoft has introduced MAI-Cyber-1-Flash, its first dedicated cybersecurity model, and integrated it into MDASH, the company’s vulnerability-hunting system. Microsoft said the combined setup scored 95.95% on the CyberGym benchmark, ahead of GPT-5.5 Cyber at 85.6%, Anthropic’s Mythos 5 at 83.8%, OpenAI’s GPT-5.6 Sol at 83.6%, and Gemini 3.5 Flash Cyber at 83.2%. The company also said the new configuration delivers that result at half the cost of its current best MDASH setup. CyberGym asks AI agents to reproduce 1,507 known vulnerabilities across 188 open-source projects and scores them by successful reproduction rate in a controlled environment. Microsoft said MAI-Cyber-1-Flash handles up to 90% of tasks, while MDASH routes the hardest 10% to GPT-5.4. The result was self-reported and had not appeared on CyberGym’s public leaderboard at publication time. Microsoft is rolling out MDASH in private preview through Microsoft Security Exposure Management in the Defender portal. Customers can scan Git repositories, review findings ranked from unlikely to proven, and use Defender CLI to generate proposed code fixes. The preview currently caps repositories at roughly 256MB and allows one concurrent scan per tenant.

1180
Microsoft unveils MAI-Cyber-1-Flash, says MDASH tops Mythos and GPT-5.6 Sol on CyberGym
NVIDIA
2026-07-27 13:46:29

NVIDIA, Microsoft and peers launch Open Secure AI Alliance

NVIDIA and Microsoft have joined other major technology companies to launch the Open Secure AI Alliance, a new group focused on promoting open-source AI for cybersecurity use cases. The alliance says open and closed AI systems should work together to strengthen cyber defenses rather than be treated as opposing approaches. Founding members named in the announcement include IBM, Cisco, Cloudflare, CrowdStrike, and Hugging Face. The group plans to build several tools, including NVIDIA’s NOOA agent framework, Microsoft’s MDASH vulnerability scanning system, and secure coding tools. It also urged regulators to treat open-source AI as a defensive resource and to invest in shared AI security infrastructure instead of imposing blanket restrictions on open models. The development was reported by CryptoBriefing and cited by Techub News.

1230
NVIDIA, Microsoft and peers launch Open Secure AI Alliance
NVIDIA
2026-07-27 09:18:00

NVIDIA and founding members launch Open Secure AI Alliance for AI and cyber defense

NVIDIA said it has formed the Open Secure AI Alliance with a group of founding members including Adobe, CrowdStrike, IBM, Microsoft, Red Hat, SpaceXAI and organizations such as the Linux Foundation, according to the NVIDIA Blog. The alliance is focused on building and sharing open-source models, agent harnesses and security tools for cybersecurity and AI safety defense. Initial contributions named by the group include NVIDIA’s NOOA agent framework, the SPIFFE/SPIRE zero-trust identity standard with HPE participation, Hugging Face’s Safetensors model weight format, IBM and Red Hat’s Lightwell supply-chain signing patch, Microsoft’s MDASH multi-model vulnerability scanning system, and SpaceXAI’s open-source Grok Build coding agent alongside plans to open Grok model weights. The alliance also called on regulators to treat open models and tools as defensive assets rather than as a regulatory burden.

1200
NVIDIA and founding members launch Open Secure AI Alliance for AI and cyber defense