CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

MDASH

tool · tool:microsoft-mdash-2026

Microsoft's multi-model agentic vulnerability-discovery harness; found 16 Windows CVEs in network-stack kernel components.

Coverage
1
first 2026-05-13 → last 2026-05-13
Latest activity
2026-05-13
Microsoft MDASH, multi-model agentic vulnerability-discovery harness finds 16 Windows CVEs in network-stack…
Peak priority
notable
1 notable
Targets
·
no sector or region stated
Sources cited
2
2 hosts

Defender insights

What each entry about MDASH tells a defender to do, newest first.

2026-05-13NOTABLEMicrosoft MDASH, multi-model agentic vulnerability-discovery harness finds 16 Windows CVEs in network-stack kernel components

Story timeline

  1. 2026-05-13Microsoft MDASH, multi-model agentic vulnerability-discovery harness finds 16 Windows CVEs in network-stack kernel components
    research

Hunting pivots

ATT&CK techniques (2 across 2 tactics)

2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExternal Remote Services · Exploit Public-Facing Application
  • PersistenceExternal Remote Services

Initial Access TA0001

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-05-13/microsoft-mdash-multi-model-agentic-vulnerability-discovery · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-05-13/microsoft-mdash-multi-model-agentic-vulnerability-discovery · ATT&CK page ↗

Persistence TA0003

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-05-13/microsoft-mdash-multi-model-agentic-vulnerability-discovery · ATT&CK page ↗

Entries about MDASH (1)

2026-05-13 · view entry permalink →

NOTABLE

Microsoft MDASH, multi-model agentic vulnerability-discovery harness finds 16 Windows CVEs in network-stack kernel components

Microsoft's Autonomous Code Security team published a detailed technical disclosure on 2026-05-12 of MDASH, an AI-orchestrated vulnerability-discovery pipeline running over 100 specialised agents across an ensemble of frontier and distilled models (Microsoft Security Blog, 2026-05-12). The pipeline executes a five-stage prepare → scan → validate → dedup → prove loop that ends with an automated end-to-end exploitability proof before a finding is sent to engineering, meaning every MDASH-disclosed CVE was validated as practically exploitable, not just theoretically reachable. In MDASH's first production run against Windows the harness produced 16 previously unknown CVEs concentrated in the network-exposed kernel attack surface, tcpip.sys (Windows TCP/IP stack), ikeext.dll (the Windows IKEv2 keying service for DirectAccess and Always-On VPN), netlogon.dll, and dnsapi.dll, split as 10 kernel-mode and 6 user-mode bugs, including four Critical RCEs. The harness scored 88.45% on the public CyberGym benchmark (1,507 real-world CVEs across 188 open-source projects) and achieved 100% recall on the tcpip.sys historical-CVE corpus (The Register, 2026-05-13). Microsoft has scheduled a customer-facing preview of the harness for June 2026.

research13 May 05:00Zmulti-sourceOpen finding →

explore in graph

Where this entity is cited

  • Research1

Source distribution

  • microsoft.com1 (50%)
  • theregister.com1 (50%)