Anthropic's Mythos Is Finding Microsoft Bugs Faster Than They Can Be Fixed, Report Says

Anthropic's Mythos Is Finding Microsoft Bugs Faster Than They Can Be Fixed, Report Says

Microsoft engineers are racing to address a surge of software vulnerabilities uncovered by Anthropic's AI model, Mythos, according to internal documents and a recording of a company meeting reviewed by ProPublica. The materials show Microsoft's security teams using the model as part of Project Glasswing, an initiative that gave select software companies early access to Anthropic's technology to identify and patch security flaws before comparable AI tools become widely available.

During a mid-May meeting, engineers discussed whether Claude Mythos Preview had met expectations. When one engineer asked if the model had "live up to the hype that Anthropic claimed it would have had," a manager responded, "Yes."

According to presentation slides shown during the meeting, Mythos identified 90 critical vulnerabilities and 141 important vulnerabilities in SharePoint during April alone. The model uncovered even more during the first half of May, creating a growing backlog for engineering teams responsible for issuing security updates.

Engineering manager Hans Andersen urged teams to accelerate remediation efforts before Anthropic's advantage disappeared.

"Please, please, please if your org has any April bugs, drive those down," Andersen said. He added that engineers had roughly two weeks "to find as many things and do as much good as we can with this access."

Andersen described May 31 as "the day when the rest of the world will have caught up," prompting one engineer to ask, "So basically you're saying if it's released on June 1, then on June 2 the adversaries will have our bugs?"

"Yep," colleagues replied.

Project Glasswing was publicly announced in April as a program that provided early access to Anthropic's bug-finding model to selected software developers. The objective was to give defenders time to identify and correct vulnerabilities before similar AI capabilities became available to attackers.

Internal Microsoft documents reviewed by ProPublica suggest the volume of discoveries has outpaced the company's ability to deploy fixes. Microsoft has prioritized vulnerabilities it classifies as critical and important while leaving hundreds of moderate-severity issues for later remediation. The documents also indicate that low-severity vulnerabilities were not included in the remediation plans reviewed by ProPublica.

The challenge extends beyond SharePoint. According to the internal records, Mythos has also identified hundreds of critical or important vulnerabilities across Microsoft 365, Teams, and Copilot since Microsoft began using the model earlier this year. As of mid-May, most had not yet been patched.

"They're not profound and exotic, but they're real," Andersen said during the meeting. "And a lot of them are exploitable."

Microsoft said its vulnerability triage process considers multiple factors, including exploitability and customer impact. The company also noted that vulnerability chaining "has long been considered as part of vulnerability assessment and risk analysis."

The discussion reflects a broader concern among cybersecurity experts that AI models capable of discovering software flaws at scale may be changing long-established security practices. Rather than exploiting a single severe vulnerability, modern AI systems can identify combinations of lower-severity issues that together create more significant attack paths.

"The problem now is that you can chain four low-level flaws, and that can equal a high severity," said Vinh Nguyen, a senior technical adviser to Anthropic and senior fellow for AI at the Council on Foreign Relations. "If you're Microsoft, the current triage strategy may be underpricing risks."

Microsoft defended its response, saying the company "feels a sense of urgency to help our customers at this time."

"What was heard on that call and is true today is that security is Microsoft's most important priority and teams across the company are prioritizing using AI to discover and remediate vulnerabilities as quickly as possible."

The increase in vulnerabilities has become visible through Microsoft's monthly Patch Tuesday releases. The company issued fixes for more than 200 vulnerabilities in June before releasing patches for more than 600 vulnerabilities on July 14. According to Dustin Childs, leader of the Zero Day Initiative bug bounty program at TrendAI, only seven of those vulnerabilities were categorized as low or moderate severity, with one already under active exploitation.

"Well folks. Here we are. The bug apocalypse has fully descended upon us," Childs wrote.

Microsoft acknowledged that AI-assisted vulnerability discovery is forcing the industry to reconsider how security flaws are evaluated.

The company said it is "always going to be reevaluating and considering whether things that were previously lows or moderates be upgraded or thought about differently. With these AI systems, it makes us rethink some of these things. Across the industry, we're all looking to see how drastic of a change it will be."

Cybersecurity experts say the challenge extends well beyond Microsoft. AI-powered vulnerability discovery is increasing the number of flaws software vendors must investigate and remediate, while also raising questions about whether existing patch prioritization systems remain sufficient as AI models become capable of linking multiple lower-risk vulnerabilities into larger attack chains.

"Nobody has really figured out how to deal with this, and everybody is casting around for what they need to do," said J. Michael Daniel, president of the Cyber Threat Alliance. "Our tech debt is coming due."

This analysis is based on reporting from PROPUBLICA.

Image courtesy of ArmorCode.

This article was generated with AI assistance and reviewed for accuracy and quality.

Last updated: July 29, 2026

About this article: This article was generated with AI assistance and reviewed by our editorial team to ensure it follows our editorial standards for accuracy and independence. We maintain strict fact-checking protocols and cite all sources.

Word count: 862Reading time: 0 minutes
Browse All Articles
Share this article:
Next Article

AI News Daily

Breaking Intelligence • Since 2023

Join hundreds of thousands of AI professionals who start their day with our curated newsletter. Get breaking news, expert analysis, and exclusive insights.

Stay Ahead of AI

Get the latest AI breakthroughs, tools, and insights delivered to your inbox every week.

Free forever Unsubscribe anytime No spam guarantee

Go Premium

Unlock unlimited AI tools and an ad-free reading experience designed for AI professionals.

• Ad-free experience• Premium AI tools
Start Free Trial

14-day free trial • Cancel anytime
Plus $9/mo • Pro $90/yr (2 months free)

Follow Our Community

ChatAI

Breaking Intelligence

Your daily briefing on what matters in AI. Trusted by developers, researchers, executives, and AI enthusiasts worldwide.

© 2026 ChatAI. All rights reserved.