Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Theory Professional arrived at InfoComm 2026 with two new loudspeaker products, but the SR-221.3 was the one that made it difficult to ignore the company’s booth. The extreme output, full range sound reinforcement loudspeaker is the latest addition to Theory Professional’s SR Series, designed for installations and portable applications that require serious scale, wide coverage, and the kind of dynamic headroom that makes most conventional commercial speakers sound rather polite.
Do not confuse Theory Professional with Theory Audio Design. The two brands share the same corporate umbrella and the engineering vision of founder Paul Hales, but they serve different masters. Theory Audio Design is focused on premium residential and custom installation systems, while Theory Professional takes that same emphasis on compact form factors, high output, advanced drivers, and refined voicing into commercial venues, hospitality spaces, houses of worship, entertainment installations, and live sound reinforcement.

First previewed at ISE 2026 in Barcelona, the SR-221.3 made its InfoComm debut as the flagship statement piece in that strategy. With dual 21 inch low frequency drivers, four 10 inch carbon fiber midrange drivers, and a 5 inch ring radiator compression driver, it is essentially Theory Professional’s argument that a single enclosure can deliver rock concert scale without requiring a small army of boxes and a spreadsheet to deploy them. For a deeper look at the SR-221.3 and the wider SR Series, refer to our report from ISE 2026.
At InfoComm 2026, Theory Professional also debuted the p9 Pendant Loudspeaker, a second new product shown alongside the SR-221.3.
The p9 expands Theory Professional’s pendant loudspeaker lineup, building on the existing ic6 PENDANT. With this new model, Theory is targeting premium commercial spaces that require more output, wider bandwidth, and greater placement flexibility than a conventional compact pendant speaker can typically provide.

The p9 combines high output capability and dynamic range with a slender, design-conscious form factor. Inside its black anodized aluminum enclosure is a 9-inch driver system featuring Theory’s Theorem axi-symmetric waveguide and a carbon fiber sandwich low-frequency diaphragm. Theory specifies a frequency range of 45Hz to 20kHz, which means that many foreground music installations may not require a separate subwoofer.
The p9 is also designed to maintain 120-degree dispersion through the upper frequencies, creating broad and consistent coverage in spaces where listeners may be spread across a wide area. That could prove particularly useful in restaurants, hotels, retail environments, and other installations with lower ceilings, where fewer loudspeakers and broader coverage can simplify system design.
Its driver provides the radiating surface area of a 9-inch unit while fitting within an 8-inch chassis, helping Theory keep the overall enclosure compact. The bezel-free industrial design further minimizes its visual footprint, allowing the p9 to blend more naturally into hospitality, wellness, retail, and other architecturally sensitive environments.
Theory Professional positions the p9 as an answer to a growing mismatch in commercial AV: increasingly refined spaces are still too often fitted with loudspeakers that prioritize utility over both sound quality and appearance. The p9 is intended to give dealers, integrators, architects, and designers a more upscale pendant option without sacrificing output or coverage. It is expected to ship in Q4 2026 in passive 16-ohm/70V and PoE versions.
Under Paul Hales, Theory Professional continues to pursue a very specific corner of the market: compact loudspeakers that do not surrender dynamics, bandwidth, or intelligibility simply because the installation needs to look civilized.
The p9 is not aimed at projects that require the cheapest possible 70V pendant speaker. Its appeal is the attempt to combine wide 120-degree coverage, useful low-frequency extension, high output capability, and a compact, architecturally friendly enclosure in one product. For restaurants, hotels, retail spaces, spas, clubs, and premium residential or light-commercial projects with exposed ceilings, that could mean fewer speakers, less visual clutter, and potentially no subwoofer for foreground music systems.
Theory has confirmed that the p9 and SR-221.3 will be shown and demonstrated at CEDIA Expo 2026 in Denver, giving the eCoustics team a chance to hear both products in person. That matters, because the specification sheet is promising, but the real question is whether the p9 can deliver the scale, tonal refinement, and broad coverage Theory is claiming without becoming another expensive pendant speaker that looks better than it sounds. We also expect CEDIA to bring clearer details regarding final specifications, availability, and pricing.
The p9 will be available in Q4 2026 in both passive (16-ohms/70V) and PoE versions through Theory Professional commercial and residential partners.
Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks.
The vulnerability, tracked as CVE-2026-16812, is an unauthenticated OS command injection flaw with severity scores of 10.0, the maximum score that can be given to flaws.
VeloCloud Orchestrator, also known as VCO, is a centralized management platform used to configure, monitor, and manage VeloCloud SD-WAN deployments and associated edge devices.
According to an Arista security advisory published Monday, the vulnerability allows remote attackers to access privileged functionality that was intended only for internal use and should not be remotely accessible.
“Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator,” Arista warned.
The company says VCO is supposed to be exposed by default, with no configuration option that can prevent this exposure. Attackers only require network access to the VCO web interface, and no VCO tenant or operator credentials are needed to exploit the flaw.
Arista says CVE-2026-16812 was discovered externally and is known to be actively exploited, but has not shared when the attacks began, who is behind them, or how the vulnerability is being exploited. BleepingComputer has contacted the company with these questions.
The following VeloCloud Orchestrator on-premises versions are affected:
VeloCloud Orchestrator Hosted and Dedicated deployments were patched before the advisory was published and are not affected. VeloCloud Gateway and VeloCloud Edge products are also not vulnerable to the flaw.
The company says the flaw is fixed in VCO versions 5.2.3.14, 6.1.3.4, and 6.4.2.4 and later. The affected software list also indicates that VCO 7.0.0.1 and later releases are not vulnerable.
Arista warns that end-of-support software versions have not been assessed to determine if they are vulnerable. Customers running unsupported release trains are advised to contact the Arista Technical Assistance Center to discuss available upgrade options.
The U.S. Cybersecurity and Infrastructure Security Agency has also added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog, confirming that the flaw is being used in attacks.
CISA has ordered U.S. federal civilian executive branch agencies to mitigate the vulnerability by Thursday, July 30, 2026, as required by Binding Operational Directive 22-01.
While patches are being deployed, administrators should restrict access to the VCO web interface to administrative networks, monitor for connections from known malicious IP addresses, and review recent administrator activity for unusual changes.
Arista shared three IP addresses that were seen exploiting the vulnerability:
Administrators are advised to block these IP addresses and review their logs for previous connections. However, it is possible that devices could have been compromised from other IPs, so this list is not definitive.
Organizations should review VCO logs for signs of exploitation, including:
If compromise is suspected, organizations should preserve all logs and filesystem timestamps before remediation.
Potentially affected organizations should rotate credentials, review administrator activity, validate managed devices, and consider restoring or replacing compromised instances.
As successful exploitation can compromise both the orchestrator host and the data it manages, installing the security update may not be enough for systems that have already been breached.
Arista warns that compromising a VeloCloud Orchestrator instance could also give attackers access to VeloCloud Edge devices as well.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Peacock Premium ($11/month) will be included free with YouTube Premium from early 2027. It is Peacock’s largest wholesale distribution deal. NBC Sports will produce live events for YouTube.
Peacock Premium will be included with YouTube Premium in the US at no extra cost starting in early 2027. The deal, announced on Sunday by NBCUniversal and YouTube, is Peacock’s largest wholesale distribution partnership to date and immediately expands its reach to millions of existing YouTube Premium subscribers. Peacock Premium currently costs $10.99 per month on its own. YouTube Premium recently increased to $16 per month for individuals and $27 for families.
The bundle gives YouTube Premium subscribers access to Peacock’s full catalogue: NFL Sunday Night Football, the Olympics, NBA, MLB, Premier League, WNBA, and college sports alongside series including The Office, Saturday Night Live, Law & Order: SVU, Love Island USA, and blockbuster Universal films. Subscribers can upgrade to the ad-free Peacock Premium Plus tier. Peacock Premium will also be available as a standalone add-on through YouTube Primetime Channels starting later this summer.
The partnership extends well beyond the bundle. NBCUniversal’s multi-year distribution deal with YouTube TV, the largest and fastest-growing pay TV provider in the US, is renewed. NBC Sports will produce select live sporting events for YouTube. Some live events from NBCUniversal will stream on NBC Sports’ YouTube channel. The deal also expands Universal+ and Hayu to YouTube Premium subscribers in select international markets and deepens the companies’ advertising technology collaboration through FreeWheel. Google has been rebuilding its products around AI and engagement, and bundling a major streaming service with YouTube Premium turns the subscription from an ad-removal tool into a full entertainment package.
Peacock just turned its first quarterly profit, six years after launch. The YouTube bundle accelerates its next growth phase by trading per-subscriber revenue for scale. Alphabet raised its capex guidance to $205 billion this year as it invests across AI and content, and the Peacock deal positions YouTube Premium as a competitor to Apple One and Amazon Prime’s bundled offerings. “This partnership brings NBCUniversal’s world-class content to YouTube’s unmatched scale,” said Comcast co-CEO Mike Cavanagh. For YouTube, the value is retention: subscribers who get NFL, Premier League, and The Office alongside ad-free YouTube are much harder to cancel.
Microsoft said MDASH with MAI-Cyber-1-Flash received a 96 percent score on CyberGYM, a standard benchmark test. The rating is 12 points higher than Anthropic’s Mythos and also beats Google Gemini and OpenAI GPT. The new MDASH costs half as much to use as the previous MDASH offering.
The second tool Microsoft announced on Monday is named Project Perception. It too is a collection of specialized AI agents that perform red-, blue-, and green-team functions for finding vulnerabilities, investigating them to determine their risk, and taking corrective actions, respectively. Microsoft said the platform selects the models to use based on the assigned task. Considerations that go into the decision include the model’s effectiveness and the end cost to the customer. Microsoft said the decisions are shaped by “ongoing research, benchmarking and evaluation across frontier and specialized models.”
Microsoft said Project Perception is designed to perform 90 percent of tasks for lower costs than similar platforms from competitors. That means customers can turn to the more expensive alternatives only for the remaining 10 percent of tasks.
Microsoft said the new tools respond to a seismic shift in how organizations secure their networks against catastrophic hacks.
“As AI accelerates the speed and scale of cyberattacks, defenders are being asked to secure increasingly complex digital environments with approaches built for a different era,” the company said. “Security teams are often forced to piece together signals, context, and risk insights across vast amounts of data, making it harder to keep pace with emerging threats.”
With last week’s OpenAI incident evoking troubling scenes straight out of the most dystopian sci-fi novels, the tools, which are currently in preview mode, deserve a healthy dose of caution that Microsoft made no mention of. They should be closely scrutinized and evaluated before being used in production. On the other hand, there are clear risks for not adopting such tools. Balancing the risks of using AI agents versus the threat of avoiding them is a work in progress with no clear answers for now.
Apple’s iOS 26.6 update stops attackers from using iPhone Mirroring, Siri, and more to gain user data. Here’s what you need to know.
On Monday, just under a month following the arrival of the security-focused iOS 26.5.2, Apple made iOS 26.6 available to the general public. The latter includes over 75 security enhancements, 14 of which address kernel-related vulnerabilities.
10 of the now-patched kernel issues allowed apps to trigger unexpected system terminations, while others let apps access sensitive user data and write kernel memory. Apple resolved these issues through improved memory handling, memory management, state management, bounds checks, and more.
Additionally, iOS 26.6 prevents attackers from using iPhone Mirroring to access sensitive user data, as an Accessibility issue was resolved through state management improvements. Similar App Store and FrontBoard issues were resolved through improved checks and the use of HTTPS, respectively.
Apple also stopped apps from accessing user information through Game Center by improving data protection. Enhanced state management was used to fix similar Managed Configuration and WorkoutKit vulnerabilities.
iOS 26.6 also removed vulnerable Siri code, resolving an information disclosure issue that gave apps access to sensitive information about the user. Entitlement checks were employed to fix an NSColorPanel issue, once again preventing apps from leaking user data.
The Contacts app received three security enhancements as well, as processing a maliciously crafted contact will no longer leak sensitive user data, thanks to the iOS 26.6 update. Additionally, apps can no longer add contacts without user authorization, thanks to validation improvements.
Apple also took security measures to ensure that attackers with physical access to locked devices can’t gain user data, as the company fixed a DriverKit and Wi-Fi issue.
iOS 26.6 also addresses a significant MediaRemote issue. The now-patched path handling vulnerability gave apps root privileges. Similarly. the iOS 26.6 update contains an Apple Books fix that prevents apps from accessing protected parts of the filesystem.
Multiple Model I/O issues were resolved as well, meaning that remote attackers can no longer cause unexpected app crashes on iOS 26.6. Three now-patched Scene I/O exploits enabled arbitrary code execution.
Apple also took measures to prevent apps from escaping their sandbox. The company did so by resolving Game Center and libc vulnerabilities with improved path validation and input validation, respectively.
Monday’s iOS update also stops apps from using a WebKit issue to escape their sandbox. In total, iOS 26.6 contains eight WebKit fixes, meant to keep your data safe while browsing the web.
Notably, iOS 26.6 includes a fix that stops websites from knowing the user visited a specific link. Apple also made UI improvements, as maliciously framed websites were found to spoof select UI elements.
As for the other WebKit patches, one of them prevents denial-of-service attacks, while two prevent Safari crashes on iOS 26.6. Apple similarly included fixes for mDNSResponder and Heimdal to prevent denial-of-service attacks.
Monday’s software update contains a multitude of security enhancements. As Apple’s website notes, fixes for Pro Res, WebRTC, AuthKit, the Apple Neural Engine, and more are present in iOS 26.6.Unlike other iOS releases, however, iOS 26.6 doesn’t include fixes for vulnerabilities that were used in targeted attacks.
Even so, AppleInsider recommends installing it to ensure your devices have the latest security enhancements. Unlike the iOS 27 developer betas, which may contain bugs, glitches, and performance issues, the iOS 26.6 update should be installed by all users.
On Sunday, Microsoft CEO Satya Nadella doubled down on the shocking warning he issued earlier this month to businesses that use AI, taking it a step further this time. Companies that rely wholly on the proprietary AI labs for their AI needs ultimately won’t survive, he predicts.
That’s what he said on CNN’s “Fareed Zakaria GPS.” When Zakaria asked Nadella to explain what constitutes a company sharing too much with an AI model provider, Nadella said businesses need to be wary of everything they hand over, from their data to their prompts.
Nadella called for a setup where “every time you use the model, all of the metadata around it is retained by you, so that you could use all of that to train perhaps your own weights or your own open model.” (Weights are a model’s trained parameters — essentially its brain. Nadella’s point: Companies should hold on to their own usage data so they can eventually build a model of their own.)
“Any firm that doesn’t have this control, I will claim will not remain a firm because you’ve essentially outsourced your thinking,” he added.
In short: Companies without their own models — or without a layer of AI infrastructure known as AI gateways to separate their prompts from the model itself — will be in trouble, Nadella says.
He specifically wants companies to stop relying on AI labs’ built-in coding tools, known as harnesses.(Anthropic’s Claude Code and OpenAI’s ChatGPT Codex are examples of these.)
“By keeping the harness separate from the model and the context and memory separate from the model, you absolutely can use multiple models for what they’re great at. At the same time, any one model can go away, and you can still continue to be in control of your own destiny,” Nadella said.
Mind you, Microsoft is an investor in the two largest AI labs, Anthropic and OpenAI. Coding agents are a particularly popular way for enterprises to use AI models and by all accounts are earning the model makers gobs of money.
And yet, Nadella is telling enterprises not to rely too heavily on them. Microsoft, naturally, would benefit from that warning, as its cloud business is now also selling the kind of alternative infrastructure he’s recommending.
Despite the obvious self-serving fear tactic, he’s not wrong. Enterprises are increasingly realizing that they need many model options, particularly cheaper options, and are turning to open-weight models — models whose underlying code is publicly available — that they can fine-tune and run on their own hardware. That, in turn, means they will also need ways to manage multiple models, as well as coding agents that aren’t tied to a specific model provider.
But Nadella’s observation isn’t just about runaway budgets. He anticipates that once a company has “outsourced its thinking” to a model, there’s little to stop the AI lab from eventually offering a competing service of its own. This risk grows as enterprises adopt AI agents and give them access to the innards of the company.
It’s the kind of warning that the startup industry has been shuddering about for years: What’s to stop model makers from wiping out startups by copying and competing with them?
In May, for example, when OpenAI CEO Sam Altman offered to invest in every Y Combinator startup in its latest cohort by offering them AI credits, seed investor Jason Calacanis issued a similar buyer-beware, posting: “If you take these tokens, there’s a non-zero chance that OpenAI will study exactly what your startup is doing, copy your idea and put your app into their free offering. This is the classic platform playbook — be careful, founders!” he posted.
Now Nadella is making that same case to enterprises.
One caveat: Nadella’s concern about oversharing with AI models applies only to businesses — not individuals. When Zakaria specifically asked Nadella how everyday people could protect themselves, Nadella shrugged it off, saying that sharing data is simply the price consumers pay for using a service, especially a free one.
“To some degree there’s got to be some value exchange in the consumer space where you’re getting something for free, maybe for your data. That’s sort of how the advertising business model has worked,” Nadella said.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Photo credit: Kelsonik
Nikita Chuicko works under the name kelsonik and spends his time turning existing cars into the versions manufacturers never quite got around to building. His latest set of renderings takes the Tesla Model S and stretches it into a shooting brake while adding a full widebody kit. Everything is finished in solid black, the stance is dropped, and the proportions feel deliberate rather than forced.

Tesla has finally closed the book on the Model S and Model X, but it has left a tiny window open to make one last shot at a limited Signature Series of the two cars, complete with Gold badges and a price tag to match, before moving on to the next thing. Chuicko, on the other hand, saw and appreciated a chance. As far as he could tell, the shape of that iconic vehicle still had life in it. So he preserved the Model S design but went a little further with the roof, elevating it well over the back axle and squaring off the back end to give it a functional hatch, ultimately changing it into a car that sits somewhere between a grand tourer and a high-speed hauler.

Out front, the design is reminiscent of the newer Model Y, with two independent headlights flanking a continuous LED light strip that spans the entire front of the vehicle. The bumper is nice and low and clean, with just enough going on to keep the face from looking plain, and then there are those enormous front wheel flares that push the front wheels out and give it a planted aspect even when it’s just sitting in the driveway. The Black concave Y-spoke wheels, which run way down into the flares, help to secure those wheels.

Along the sides, the extra width stands out. The size of the flares suggests that they are structural rather than purely aesthetic. There is still a high beltline that protects the glass area from looking stretched out, as well as a modest small roof spoiler that sits right above the back window. That spoiler works in tandem with the second one positioned on the hatch. At the back, there’s a translucent full-width LED light bar that runs down the tailgate, lit in a mellow crimson that really shows out against the matte black paint. Then, beneath that, there is this quite aggressive diffuser that caps off the edge of the lower paneling and connects the entire rear track.

The entire car is finished in a single deep black color that absorbs light rather than reflecting it back out. There are no bright particles to be found breaking up the surface. The end effect is a car that is both silent and hefty, with a finish that makes the extra width appear to be there by design. Looking at it from the back three quarters, you can see that the elevated roof, two spoilers, and flared arches give the car a low, purposeful appearance while still allowing for a load behind the rear seats.
[Source]

Gamers looking to start off the week by relaxing with their Xbox might need to find something else to do. On Monday, Microsoft reported that several issues were preventing gamers from using the platform. According to the Xbox Live Status page, the problems range from sign-in issues to difficulty viewing games in the Xbox store. And as of 2 p.m. PT, the problems were continuing.
The latest post from the official Xbox Support account on X, posted around 1:40 pm PT on Monday, said, “Thanks for your continued patience. Our engineers are still working to identify a fix, and we’ll share more as soon as we can.”
An earlier post Monday on the status page warned that players might not be able to sign in to their Xbox profiles, might be disconnected while signed in, or face other related problems. It also said that “features that require sign-in, like most games, apps and social activity, won’t be available.”
A Microsoft representative didn’t immediately respond to a request for comment.
The Xbox Live Status page says a resolution for all issues is “pending,” but no further detail or timing is listed.
“We are aware that some users are encountering errors when attempting to sign in, see your game library, or launch games,” the official Xbox Support account on X posted early Monday. “Our engineers are actively working to mitigate the issue.”
Microsoft later posted two updates, neither of which offers any real news on progress.
“Another update on the game library, sign-in, and game launch issue: Our teams are focused on multiple investigation angles and remain hard at work,” one update reads. “Thanks for your patience while teams keep working — we’ll share more details as they become available here or at http://support.xbox.com.”
OFFBEAT
Tekever AR5 drone regarded as more up-to-date answer to provide battlefield surveillance for soldiers
The UK Ministry of Defence (MoD) is investing up to £400 million in new surveillance drones to replace the British Army’s troublesome Watchkeeper fleet.
The MoD has selected the Tekever AR5 uncrewed aerial vehicle (UAV) for a fleet of “spy-in-the-sky” aircraft intended to provide real-time intelligence, protect troops, and inform battlefield decisions.

The initial order will be for six AR5 drones, with up to 24 expected by 2029. The aircraft will be built at a soon-to-open manufacturing facility in Swindon and, subject to contract signature and final approval, will begin entering service later this year. Support is expected to continue for at least five years, with options to extend it.
Tekever is a small aerospace and defense biz based in Portugal, but with a number of manufacturing and test facilities in the UK. One of its other products has already been adopted by the Royal Air Force as the basis for the StormShroud electronic warfare drone.
The AR5 is a medium-endurance UAV that resembles a small conventional light aircraft. It is 4 m (13 ft) long with a 7.3 m (24 ft) wingspan and is powered by a pair of 170 cc two-stroke boxer piston engines, so it isn’t going to break any speed records. It is capable of carrying a 50 kg (110 pounds) payload, with an endurance of up to 20 hours, and can take off and land on rough ground.
The newcomer is expected to replace the Watchkeeper in British Army service, a drone system perhaps best known to Reg readers for its tendency to not remain in the air.
According to Janes, Watchkeeper only saw brief operational service at the end of the conflict in Afghanistan, and was also used to track refugee boats in the English Channel in 2020. Other than that, it has largely been used for training, which may explain why at least seven are known to have been lost in incidents.
Former defence secretary John Healey announced in 2024 that Watchkeeper was set to be retired, despite the system having entered service only in 2014 and being expected to serve the Army until 2042.
The reasons for this should be obvious: the war in Ukraine has seen airborne drone technology advance significantly over the past several years, and Watchkeeper was already seen as not up to snuff.
The British Army began the procurement process for Watchkeeper’s successor last year under the codename Project Corvus.
Newly appointed defence secretary Wes Streeting said the chosen replacement has already been put to good use by Ukraine’s military.
“Proven in Ukraine and designed to protect British soldiers globally, we’ve chosen the UK-based Tekever AR5 drone to supply our personnel with kit that will keep them ahead of emerging threats,” he said.
It offers significantly improved endurance, sensor capability, and reliability, according to the MoD.
Payload options include electro-optical and infrared sensors, maritime radar, signals intelligence equipment, and search-and-rescue capability.
Tekever UK managing director Karl Brew insisted that this wouldn’t be about supplying a point solution, but helping the Army to stay one step ahead of its adversaries.
“Tekever aims to create a new type of partnership between government and industry where we will ensure a constant cycle of capability evolution that delivers decisive advantage to our end users,” he claimed. ®
Microsoft opened a new front in the AI security wars on Monday, unveiling its first custom-built cybersecurity model and a sweeping agentic defense platform — and making an argument that could reshape how enterprises buy AI: the future belongs not to the biggest model, but to the cheapest one that’s good enough, routed intelligently.
The company announced MAI-Cyber-1-Flash, a compact security model developed in-house by its Microsoft AI (MAI) division, embedded inside MDASH, Microsoft’s multi-agent harness for finding and fixing software vulnerabilities. Together, the company says, the system scores 96% on CyberGym — a benchmark measuring how well AI systems reason over large codebases to find real vulnerabilities — beating frontier models including Mythos, Gemini, and GPT, while cutting costs roughly in half compared to Microsoft’s own current production configuration.
Alongside the model, Microsoft introduced Project Perception, an agentic security system that coordinates “red team” agents that hunt for paths to compromise, “blue team” agents that investigate and triage risk, and “green team” agents that remediate and harden defenses. Project Perception enters public preview on August 3.
In a wide-ranging interview with VentureBeat, Microsoft AI CEO Mustafa Suleyman made clear the company sees Monday’s announcement as the opening move in a much longer campaign.
“We really do have a pretty significant data and harness and expertise moat, and that is enabling us to train models which are faster, better, cheaper, and I think this is genuinely the tip of the iceberg,” Suleyman said. “We haven’t been working on this for long. The next model is going to be pretty phenomenal.”
The most technically revealing detail in the announcement is not the model itself but how Microsoft deploys it. MAI-Cyber-1-Flash was designed to handle up to 90% of security tasks efficiently, while MDASH escalates the remaining 10% of exceptionally difficult problems to a larger frontier model — which, notably, is OpenAI’s GPT-5.4. In other words, Microsoft’s flagship security AI still leans on its longtime partner-turned-rival for the hardest work.
Asked to explain that relationship, Suleyman pointed to the harness, the orchestration layer that routes each incoming problem to the right model. “The harness is like a router,” he told VentureBeat. “It’s kind of like guardrails and a rule set of an organizing logic, which matches queries to… incoming problems to a model that suits the problem.” The system has three components, he explained: the harness, the small and fast MAI-Cyber-1-Flash handling the bulk of queries, and GPT-5.4 sitting alongside as “just a generalist coding model.”
Pressed on how a system reliant on OpenAI’s model can outperform frontier competitors, Suleyman argued the performance comes from the whole system, not any single model. “These are very complicated, long, agentic loops which require storing state, drawing on another database, consulting best practice… handing back to a small model, writing a bunch of code, validating that that was correct,” he said. “There’s like hundreds of steps to solve that, and that’s why it’s really the system together that delivers the better performance.”
And why GPT-5.4 specifically for the escalation tier? Cost, again. “GPT-5.6 is expensive. GPT-5.4 is incredibly good relative to its cost,” Suleyman said. “The whole game here is to reduce the costs. Mythos and so on are extremely expensive models… we want to be able to deliver better performance for cheaper. That’s what customers want.” The arrangement captures Microsoft’s evolving posture toward OpenAI: still a customer of the partnership that drew regulatory scrutiny in Brussels and Washington in 2024, but increasingly determined to own the layers of the stack where it believes it holds durable advantages.
The economics may matter more than the benchmark. Microsoft says the new configuration delivers roughly 50% cost savings against the current MDASH setup, which runs a blend of GPT-5.4, 5.4 mini, and 5.3 codex. In security — an always-on workload processing enormous volumes of signals — token costs compound relentlessly, and Microsoft argues they have become the binding constraint for defenders.
Suleyman frames the cost issue as downstream of a harder physical limit. “The key barrier to adoption is access to chips, and cost is a function of chips,” he said. “No matter how much money you’ve got, there’s actually a limited supply of chips. Then trying to squeeze more model output on fewer chips is clearly super valuable.”
He also described a broader enterprise backlash against frontier-model pricing. Companies initially maxed out on the best available models, he said, but “then they realize they’re sort of paying… a phenomenal amount of money, and people are absolutely token maxing everywhere across their business. So there’s a massive pushback to reduce cost everywhere.”
That positions Microsoft to ride a market trend rather than fight it. Cost-efficient, near-frontier models have proliferated over the past year — from xAI’s recent Grok release to a wave of Chinese models built on the same premise — and Microsoft is betting that as a platform company it can align itself with enterprise cost pressure. “The top model providers want you to use the most expensive model continuously, whereas because we are a platform, we’re on the side of the enterprise,” Suleyman said. “There’s no point asking… Mythos what the capital of France is.”
Every AI lab claims differentiation. Microsoft’s claim in security rests on something genuinely hard to copy: telemetry. The company processes more than 100 trillion security signals daily — a figure consistent with its 2025 Digital Defense Report, which also cited 4.5 million new malware files blocked and 5 billion emails screened per day — and draws operational insight from 1.6 million customers.
“We have trillions and trillions of data points going back decades,” Suleyman said. “It is, I think, the largest longitudinal cybersecurity dataset around,” in part because Microsoft’s customer base includes governments “who have been consistently attacked for years, and we have been consistently attacked.” Asked directly whether this constitutes an advantage no competitor can match, Suleyman didn’t hedge: “That is definitely a moat for us. Both the data and the expertise, and just the experience in the institution of going through that process.”
The strategic logic is that cybersecurity functions as a live reinforcement-learning loop: defenders act, outcomes are observed, models improve. Microsoft argues that connecting actions to outcomes — what was exploited, what was contained, what was blocked — yields training signal that pure model labs simply cannot buy or manufacture.
There is real substance here, but the usual caveats apply. The CyberGym results come from Microsoft’s own evaluation, the fine print shows the headline “96%” is actually 95.95%, and vendor-run benchmarks that pit an entire tuned agentic system against competitors’ base models are not apples-to-apples comparisons. What Microsoft has measured is a full harness-plus-models configuration against what customers might otherwise assemble — arguably the commercially relevant comparison, but not a controlled model-versus-model test.
A model built to find challenging vulnerabilities in complex codebases is, by definition, a model that could find vulnerabilities for attackers. This is not a theoretical concern. Microsoft’s own threat intelligence team, in joint research with OpenAI published in February 2024, documented nation-state actors from Russia, North Korea, Iran, and China probing large language models for reconnaissance, scripting, and vulnerability research. Its 2025 Digital Defense Report went further, warning that AI agents could eventually automate the entire attack lifecycle.
Suleyman said Microsoft is gating access accordingly. “We’re very strict about who gets access to the model, and we’re very careful about that,” he said. “We constantly monitor the API and usage.” An approved user, he added, “has to be seen to be having good intent, but also have technical competence.” The rollout will be deliberately staged: “It’s not going to be thousands next week. There will be tens, and then hundreds, and then thousands.”
Microsoft says the model was evaluated by its AI Red Team, subjected to automated and expert-led adversarial exercises, and independently assessed by a third party, with deployment wrapped in tenant isolation, auditing, and sandboxed execution environments with no internet access.
Suleyman also offered a candid acknowledgment of Microsoft’s positioning relative to the bleeding edge — one that doubles as a pitch to risk-averse buyers. “Even though we might be a few months behind the absolute cutting edge at any given moment… it matters that we’re doing it very carefully and thoughtfully, and we have a track record of doing that,” he said. For a company that spent 2024 absorbing hard security lessons — from delaying its Recall feature over privacy concerns to convening an industry summit after the CrowdStrike outage disabled some 8.5 million Windows devices — that trust-first framing is both strategy and necessity.
Suleyman described a rapidly accelerating MAI roadmap, roughly nine months after Microsoft stood up its superintelligence team. “We have the compute that we need. We certainly have the data we need. We have the talent,” he said. “Our momentum is accelerating rapidly.” The top enterprise demand he’s hearing is for “agents that can produce arbitrary code to solve whatever problem they direct them at,” as vibe-coded internal tools graduate from experiments into production. The next phase, he said, pulls voice, transcription, image, and coding models “all integrated into the same harness.”
Notably, Suleyman expressed skepticism about the industry’s default assumption that everything eventually converges into one giant unified model. “It remains to be seen whether one giant model that is fully multimodal is actually able to deliver additional transfer learning benefit because of the integration,” he said, “or whether it’s just a big lumbering expensive giant.”
That skepticism is the through line of the entire announcement. Microsoft is wagering that the unit of competition in enterprise AI is no longer the model at all — it’s the system: the router, the specialized small models, the frontier fallback, and the proprietary data feeding the loop. In security, where Microsoft controls both the telemetry flowing in and the products that act on it, that wager is at its strongest. Whether it holds in domains where the company’s data advantage is thinner remains the open question hanging over the MAI roadmap.
For now, though, Microsoft has offered the industry a preview of how it intends to fight the next phase of the AI race: not by building the biggest brain, but by building the best machine around it. As Suleyman put it, this is the tip of the iceberg — and Microsoft is betting everything on what sits below the waterline.
Microsoft has a new AI cybersecurity model called MAI-Cyber-1-Flash, and when it’s combined with agentic security system MDASH and OpenAI’s GPT-5.4 model, it outscores Anthropic’s Claude Mythos 5 by 12 points on a key benchmark. The security product is designed for “using AI to defend against AI,” Microsoft says.
The combination of MAI-Cyber-1-Flash with MDASH — which launched in May — is called Project Perception, and it enters public preview on Aug. 3, built directly into Microsoft Defender. It will slowly roll out to all Microsoft Security products.
According to benchmarks posted by Microsoft on Monday, the combination scored 96% on CyberGym, compared with Mythos 5 at 84%.
Microsoft
Pricing is consumption-based, measured by the number of security compute units you use. As AI agents run scenarios, they consume SCUs, so the more work performed, the more you pay — but Microsoft says cost savings are almost 50% of the current MDASH configuration on the market now.
Speaking at a Microsoft briefing on Monday morning, Mustafa Suleyman, CEO of Microsoft AI, explained the handover process between MAI-Cyber-1-Flash and GPT-5.4.
“MAI-Cyber-1-Flash handles about 90% of the queries. It detects the vulnerabilities, it patches them, ships them and then proves that it was actually a valid and correct solve. And then it basically defers about 10% of the queries to GPT-5.4, which is obviously a larger model, about 10x larger, and it solves those,” Suleyman said. “In conjunction, as the models hand off between each other, they’re actually not just able to deliver better performance than all of the other models combined — they do so at 50% of the cost.”
Suleyman called the CyberGym benchmark result “quite a remarkable result.”
It follows the launch of Anthropic’s Claude Fable 5 last month, the first publicly available model from the Mythos family. At the time, Anthropic said Mythos was so good at finding cybersecurity flaws that it could break the internet if used unchecked — and Anthropic was forced to walk back the Fable 5 and Mythos 5 launches within days because the US government said it was aware of a way to “jailbreak” the model and bypass limits. When Mythos was first announced, it was released only to select government agencies and tech professionals.
“Microsoft has long been the trusted steward of some of the most valuable, important government and enterprise data in the world over many decades. We’ve accrued a phenomenal amount of data in that time,” Suleyman said Monday. “It’s that data combined with the expertise that we have from the world-class cybersecurity experts in the company that we’ve been able to really drive this combined model.”
Weekend Open Thread: Brooks Brothers
Grayscale Files For Worldcoin ETF, WLD Registers Sharp Rise
How a former Blue Peter presenter stunned America’s Got Talent judges
Intel is reversing course and bringing hyper-threading back to its server chips
Sail Virtually Aboard The “Itanic” With IA-64 Emulator
Turtle Beach Command Series KB7 review: a nifty screen-equipped gaming keyboard
New Jersey voter registration controversy explained: How 6,600 noncitizens got on the rolls, and what happens next
Johnny Depp’s R-Rated Gothic Cult Classic Gets New Release Ahead of Sydney Sweeney Remake
Ethics, other provisions in crypto Clarity Act to be further discussed
Luke Littler dismantles Gerwyn Price to retain title in Blackpool
Shanghai science forum photos show China’s AI and robotics advances in rivalry with US
Commonwealth Games boxing: Jadumani Singh seals dominant 5-0 win over Pakistan’s Sumama Rehman to enter quarter-finals | Commonwealth Games News
2026 3M Open leaderboard: Scottie Scheffler finds putter in Round 1, sits three back
The Peugeot Family: How 200 Years of an “Old Money” Dynasty Died in A Boardroom
16 Dresses for the High Summer Event
Spain sweeps the board at 2026 World Cup with individual awards
Andrew Cuomo joins OKX board as crypto exchange expands in U.S.
A New Post-Apocalyptic Gundam Anime Series Blasts Into SDCC
BITCOIN JUST ENTERED THIS CRITICAL ZONE…
XRP Ledger adds $2.6B as RWA inflows rank second
You must be logged in to post a comment Login