Skip to main content

Tel: 01244 535527

Could AI Stop Attacks Before They Start

TL;DR: Microsoft has built an AI system called MDASH that uses over 100 specialised AI agents to hunt for hidden vulnerabilities inside Windows before attackers find them. It has already uncovered several previously unknown flaws, some of them critical. It's an early-stage, internal tool for now, and it won't replace the basics. Strong passwords, patching, MFA, backups and staff awareness still stop far more attacks than any AI ever will.

Most cyber security tools are built to react.

Something suspicious happens, the system flags it, and a response kicks in to limit the damage. That's valuable work, but it's still playing catch-up.

Microsoft has been testing something with a different aim: finding the weaknesses before anyone gets the chance to exploit them.

The system is called MDASH. It's a platform built from more than 100 specialised AI agents, each one assigned to examine a different part of Windows, test it for weaknesses, and flag anything that looks like a potential vulnerability.

In effect, Microsoft has automated the kind of deep, exhaustive vulnerability hunting that would take human researchers far longer to do manually.

Early results suggest the approach is paying off. During testing, MDASH reportedly surfaced several previously unknown vulnerabilities in core parts of Windows, including some that could theoretically be exploited remotely over the internet. A number of these were rated critical, meaning a successful exploit could hand an attacker control of a system or let them run malicious code on it.

The part worth paying attention to is accuracy. AI-driven security tools have a long history of drowning teams in false positives, flagging hundreds of "possible issues" that turn out to be nothing. That noise wastes time and makes security teams less effective, not more. Microsoft says MDASH has managed to avoid a lot of that noise while still catching genuine risks.

Embed Code

Not sure where to start?

Let's talk it through.

Have a quick, no-obligation call with our team.
No pitch, just answers.

None of this means AI is about to solve cyber security.

MDASH is currently an internal tool used by Microsoft's own engineers. It's early, and even as tools like it become more widely available, they won't replace the fundamentals that actually keep most businesses safe day to day.

That's because most successful attacks still come through the same ordinary gaps:

- Weak or reused passwords
- Unpatched systems and software
- Someone clicking the wrong link
- Poor access controls
- Missing or untested backups

Those five issues cause more breaches than any zero-day exploit. AI-driven vulnerability hunting will likely become a genuinely useful extra layer, particularly for large organisations running huge, complex environments. Agents constantly scanning for hidden weaknesses before criminals find them is a sensible direction for the industry to be heading in.

But right now, the basics still do most of the work. A business with fully patched systems, strong passwords, multi-factor authentication switched on, tested backups and staff who know what a phishing email looks like will be safer than a business chasing the newest AI security headline without those foundations in place.

AI will keep showing up on both sides of this fight, helping defenders find flaws faster and, unfortunately, helping attackers too. The technology will move on. What stops most attacks won't. Reducing risk, closing off easy opportunities and getting the simple things right, consistently, is still where good security starts.

If you want a second opinion on where your own security stands, get in touch. No pitch, just answers.

Blog Category