
Anthropic's Mythos AI model is discovering software bugs in Microsoft products faster than Microsoft can patch them, with the company finding hundreds of critical and important vulnerabilities in widely-used tools like SharePoint and Microsoft 365. A leaked internal meeting and documents show Microsoft faced a May 31 deadline to patch flaws before adversaries gained access to similar AI tools, but the deadline appears to have passed. Security experts warn that Microsoft's strategy of deferring low and moderate-severity bugs is risky because AI can chain multiple minor flaws together to enable major attacks.
Summaries like this, in your inbox every morning.
Sign up free →What happened
Microsoft engineers gathered in mid-May to discuss Claude Mythos Preview, an AI model developed by Anthropic that is finding bugs in Microsoft software faster than the company can fix them. In April alone, Mythos uncovered 90 critical bugs and 141 important ones in SharePoint; by July 14, Microsoft released patches for more than 600 bugs in a single month—an all-time high. Engineers faced a deadline of May 31 to patch vulnerabilities before adversaries would gain access to similar AI tools.
Why it matters
The speed of AI-powered vulnerability discovery has outstripped Microsoft's capacity to respond, creating a security window that may already be closing. Vinh Nguyen, a former NSA AI chief and adviser to Anthropic, warned that Microsoft's traditional triage strategy—prioritizing critical and important bugs while deferring low and moderate ones—underestimates risk because AI can chain together multiple low-severity flaws to execute devastating attacks. With Microsoft's products used worldwide by governments and businesses, the backlog of unpatched bugs poses espionage and sabotage risks.
What to watch
Microsoft acknowledged the vulnerability volume "will not be plateauing for a bit" and said it has "invested heavily in both people as well as AI-powered triage solutions." The broader software industry faces similar pressures, particularly open-source projects maintained by volunteers. Security experts suggest companies may need to dedicate staff to patching the full spectrum of vulnerabilities, not just the highest-priority ones.
On an afternoon in mid-May, dozens of Microsoft engineers and managers gathered at the company's Redmond headquarters to discuss Project Glasswing—an effort to patch exploits uncovered by Anthropic's Mythos AI before hackers could weaponize them. Mythos, a new AI model developed by Anthropic, had been given access to select organizations to identify and fix software vulnerabilities before adversarial governments like China could use similar tools for espionage and sabotage.
One manager confirmed that Claude Mythos Preview, the version Microsoft was using, was "surfacing bugs faster than the tech giant could patch them," putting engineers in "a mad dash" to close the gap. A presentation slide revealed the scale: in April alone, Mythos had uncovered 90 critical bugs and 141 important ones in SharePoint, Microsoft's widely-used collaboration software used by governments and businesses worldwide. Engineering manager Hans Andersen urged the group to prioritize April bugs, saying they had roughly two weeks "to find as many things and do as much good as we can with this access." The reason for the urgency was stark: May 31, he explained, "is considered the day when the rest of the world will have caught up." When one engineer asked whether releasing bugs after June 1 meant adversaries would exploit them on June 2, the answer was unambiguous: "Yep."
The Five Eyes alliance—the US, Australia, Canada, New Zealand, and the UK—had warned in late June that a window of opportunity to fix flaws would close "in a matter of months." But internal documents and the May meeting recording suggest that window may have already passed. The presentation outlined a grueling schedule: the SharePoint team would work through the highest-priority critical bugs first, then tackle important ones in August, before turning to roughly 300 moderate-severity flaws. Across Microsoft's broader product suite—Microsoft 365, Teams, and Copilot—hundreds of critical and important bugs had been identified since the company started using Mythos earlier in the year, and most remained unpatched as of mid-May.
Vinh Nguyen, a senior technical adviser to Anthropic and former NSA chief AI officer, highlighted a fundamental problem with Microsoft's triage approach. Traditional vulnerability management prioritizes critical and important flaws while deferring low and moderate ones—a sensible strategy when vulnerabilities are discrete. But Mythos has the ability to chain together multiple low and moderate-severity bugs to create devastating attacks. "If you're Microsoft, the current triage strategy may be underpricing risks," Nguyen said. "The problem now is that you can chain four low-level flaws, and that can equal a high severity." Andersen, the engineering manager, acknowledged that the bugs Mythos found were "not profound and exotic, but they're real. And a lot of them are exploitable."
Public evidence of Microsoft's struggle emerged in monthly patch releases. In June, the company released patches for more than 200 bugs—an all-time high at that time. But on July 14, Microsoft released patches for more than 600 bugs, with only seven categorized as low or moderate-severity (one of which hackers were actively exploiting), according to Dustin Childs, leader of TrendAI's Zero Day Initiative bug bounty program. "Well folks. Here we are. The bug apocalypse has fully descended upon us," Childs wrote. Microsoft told ProPublica the volume "will not be plateauing for a bit" but said the company has "invested heavily in both people as well as AI-powered triage solutions that scale quickly." However, Microsoft declined to answer how many bugs engineers had patched since the May presentation.
The challenge extends across the entire software industry. J. Michael Daniel, former cybersecurity adviser to President Barack Obama and president of the Cyber Threat Alliance, noted that "nobody has really figured out how to deal with this, and everybody is casting around for what they need to do." The pressure affects not only major vendors but also open-source software—typically maintained by volunteers—that underpins Internet infrastructure and is incorporated into much of the world's modern technology. Ben Edwards, a data scientist specializing in vulnerability management, captured the scale: "It was like drinking from a garden hose on the jet setting before, and now it's like drinking from a fire hose. They might have had the teams that could handle that garden hose. Whether they can handle the fire hose is something else."
Project Glasswing, revealed publicly in April, represents a fundamental shift in how software vulnerabilities are discovered. By handing Anthropic's Mythos AI to select organizations including Microsoft, the goal was to identify and patch flaws before adversaries—including nation-states like China—gained access to comparable AI tools. The internal Microsoft meeting in mid-May exposed the tension at the heart of this strategy: the AI is working too well. In just one month, Mythos identified 231 bugs of critical or important severity in SharePoint alone, forcing engineers into what managers called "a mad dash" to close the gap.
The scale of the challenge extends beyond the raw numbers. Vinh Nguyen, the NSA's former AI chief, introduced a critical insight: in the AI era, vulnerability triage—the traditional medical-triage model of treating the sickest patients first—may be fundamentally broken. When low and moderate-severity bugs can be chained together to create high-severity exploits, deferring them is no longer safe. Yet Microsoft's internal documents indicate the company planned to address moderate-severity flaws "eventually" and made no mention of low-severity bugs. This gap between what AI can now expose and what humans can patch reflects not just a staffing problem but a strategic one.
The Five Eyes intelligence alliance warned in late June that the window to fix vulnerabilities before adversaries caught up would close "in a matter of months." But leaked Microsoft records suggest that window may already be closing or closed. By July 14, Microsoft released patches for over 600 bugs—more than three times the previous June record—signaling the company is in reactive mode. The broader implication extends beyond Microsoft: the software industry, including open-source projects maintained by volunteers, now faces an unprecedented volume of newly exposed flaws. As one security expert put it, vulnerability management has shifted from "drinking from a garden hose" to "drinking from a fire hose."
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
No comments yet. Be the first to share your thoughts!
Log in to join the discussion


Get curated AI news from 200+ sources delivered daily to your inbox. Free to use.
Get Started FreeFree · takes 30 seconds · unsubscribe anytime