A ransomware group doesn’t want your firm’s bank password. It wants the settlement terms sitting in a case file, the deposition nobody’s supposed to see yet, the merger nobody’s announced. That’s worth more to them than whatever’s in an account, because it’s worth more to your firm to keep quiet.
That’s the backdrop worth keeping in mind when a headline like “Microsoft’s new AI platform hunts security flaws” comes across your desk. It’s a genuinely interesting development. It’s also not the thing standing between your firm and the next attack.
What Microsoft actually built
Microsoft calls it MDASH, short for Multi-Model Agentic Scanning Harness. It coordinates more than 100 specialized AI agents to hunt for security flaws hidden inside Windows itself, before attackers find them, instead of waiting for something to go wrong and reacting after the fact.
It’s already turned up real results. MDASH found 16 previously unknown vulnerabilities across core parts of Windows, including the TCP/IP stack and the IPsec service used for secure connections. Four were rated critical, including two remote code execution flaws that could theoretically have let an attacker take over a system over the internet without a password. Both were fixed in a regular May update, delivered through the same Windows Update your firm’s machines already receive.
In testing, researchers planted 21 known vulnerabilities and MDASH found every one of them with zero false alarms, which is the part that’s historically undercut AI security tools. A tool that floods a security team with false positives gets ignored. This one apparently didn’t.
Why this doesn’t change your firm’s exposure this year
MDASH is running inside Microsoft right now, used by its own engineers, with a small number of outside customers in private preview. There’s no version a law firm can buy today, and no announced date for when that changes.
Even once something like it reaches the market, it’s built to catch a specific kind of problem: flaws buried in code before anyone else finds them. That’s valuable, but it’s not how most firms actually get breached. The more common path is a phishing email dressed up as a court notice or opposing counsel, a password that was too easy to guess, a paralegal with access to every matter in the firm instead of just their own, a server that missed a few months of updates, or backups nobody tested until the day they needed them.
That gap matters for a specific reason beyond risk. The duty to safeguard client information doesn’t pause because the threat is sophisticated. Under the ABA Model Rules, Rule 1.6(c) requires reasonable efforts to prevent unauthorized access to information relating to a client’s representation, and reasonable, in practice, still means the basics, not the newest AI headline.
What actually protects your firm today
Patch on a real schedule, not a delayed one. Even Microsoft’s most advanced security tool still ships its fixes through an ordinary monthly update, which only helps if that update actually gets installed. Put multi-factor authentication on email specifically, since business email compromise aimed at wire transfers and settlement funds is one of the most common ways firms lose real money. Limit case file access to the people actually working the matter, not the whole office. And test your backups against an actual ransomware scenario, not just confirm they exist.
None of that is new advice, and that’s the point. It’s also the reason a ransomware group would rather find an unpatched server or a phished paralegal than wait for someone to discover a flaw MDASH already caught. If you want a clear picture of where your firm actually stands on the basics, that’s the audit we do.


