AI - Microsoft's Project Perception and Google's Wiz Atlas
Yesterday, I mentioned that there was more amusing news in the world of AI security. This story is funny for a different reason than OpenAI’s Codex Security CLI announcement, which acknowledged that the news had leaked before the official reveal.
This time, two major corporations, Microsoft and Google-owned Wiz, announced similar AI security systems on the same day, with both claiming industry-leading results 🤣
Microsoft reported the higher CyberGym score, but Wiz Atlas was sitting at the top of CyberGym’s public leaderboard at the time of publication. In other words, Microsoft had the higher self-reported result, while Wiz had the stronger publicly verifiable claim. Of course, this field is changing incredibly quickly, so the leaderboard may have moved again by the time you read this!
Merill Fernando made a great post about this situation:
Microsoft Project Perception
From Microsoft’s own blog:
Project Perception is based on a simple idea: effective defense requires continuous understanding of how an attacker sees the world, how a defender evaluates risk and how protections are improved over time. To accomplish this, Perception coordinates three classes of specialized agents.
Red team agents identify potential paths to compromise before an attacker can exploit them.
Blue team agents investigate, reason over context and determine what represents meaningful risk.
Green team agents take corrective actions and strengthen defenses across the environment. Working together, these agents form a closed-loop system that continuously discovers, evaluates and improves an organization’s security posture.
What is Microsoft Project Perception?
Microsoft Project Perception is an agentic security system designed to help organisations defend against AI-driven threats. It coordinates specialised AI agents that continuously identify attack paths, assess meaningful risks and take corrective action. This enables security teams to respond at machine speed while keeping people in control.
Project Perception is the broader security platform. Microsoft’s CyberGym result relates specifically to MDASH, its multi-model agentic scanning system, using MAI-Cyber-1-Flash and other models.
Google Wiz Atlas
From the Wiz blog:
Over the past several months, the Wiz Research team has built and tested Atlas, an autonomous AI system for vulnerability research, against some of the world’s most heavily audited open-source projects.
Today Atlas ranks #1 on CyberGym - the public benchmark for AI-driven vulnerability work - with a 90.9% success rate, and in our own testing it has uncovered more than 200 previously unknown vulnerabilities in widely used open-source code that has been fuzzed and reviewed for decades.
What is Wiz Atlas?
Atlas is Wiz’s autonomous AI vulnerability researcher. It analyses codebases, identifies potential security flaws, challenges its own findings and validates genuine vulnerabilities by producing working proof-of-concept exploits.
This could help security teams discover complex vulnerabilities faster while reducing the number of false positives that developers and security analysts must investigate.
So, who was actually number one?
It depends on what is being compared.
Microsoft reported that an MDASH configuration achieved approximately 96% on CyberGym, which is higher than Atlas’s 90.9%. However, Wiz Atlas was ranked first on CyberGym’s public leaderboard at the time, while Microsoft’s newer result was not publicly listed there.
So Microsoft could claim the higher reported score, while Wiz could claim the number-one position on the public leaderboard.
Clear? Not entirely. Entertaining? Definitely 🤣
Useful links
#Blog #AI #Wiz #Google #Microsoft #Atlas #Project Perception