2026-05-13NOTABLEMicrosoft MDASH, multi-model agentic vulnerability-discovery harness finds 16 Windows CVEs in network-stack kernel components
MDASH
tool · tool:microsoft-mdash-2026
Microsoft's multi-model agentic vulnerability-discovery harness; found 16 Windows CVEs in network-stack kernel components.
Coverage
1
first 2026-05-13 → last 2026-05-13
Latest activity
2026-05-13
Microsoft MDASH, multi-model agentic vulnerability-discovery harness finds 16 Windows CVEs in network-stack…
Peak priority
notable
1 notable
Targets
·
no sector or region stated
Sources cited
2
2 hosts
Defender insights
What each entry about MDASH tells a defender to do, newest first.
Story timeline
Hunting pivots
ATT&CK techniques (2 across 2 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExternal Remote Services · Exploit Public-Facing Application
- PersistenceExternal Remote Services
Initial Access TA0001
T1133External Remote Services×1
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.
Evidence: 2026-05-13/microsoft-mdash-multi-model-agentic-vulnerability-discovery · ATT&CK page ↗
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-05-13/microsoft-mdash-multi-model-agentic-vulnerability-discovery · ATT&CK page ↗
Persistence TA0003
T1133External Remote Services×1
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.
Evidence: 2026-05-13/microsoft-mdash-multi-model-agentic-vulnerability-discovery · ATT&CK page ↗
Entries about MDASH (1)
Where this entity is cited
Source distribution
- microsoft.com1 (50%)
- theregister.com1 (50%)
All cited sources (2)
- microsoft.comMicrosoft Security Blog, 2026-05-12https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-finds-16-new-vulnerabilities/
- theregister.comThe Register, 2026-05-13https://www.theregister.com/patches/2026/05/13/doozy-of-a-patch-tuesday-includes-30-critical-microsoft-cves/5239224