Skip to main content
Live
Main content

Anthropic's Mythos AI is finding Microsoft bugs faster than engineers can patch them

Internal Microsoft meeting reveals Project Glasswing engineers in a race against a June 1 deadline when adversaries catch up.

Jaeden Schafer
Editor in Chief · · 5 min read
Anthropic logo

Anthropic's new bug-hunting model, Mythos, is surfacing security flaws in Microsoft software faster than Microsoft can patch them. In April alone, Mythos uncovered 90 critical bugs and 141 important ones in SharePoint, and engineers were in what one manager called "a mad dash" to patch them before adversaries built comparable tools. The scramble is happening inside a project code-named Glasswing, run out of Microsoft's Redmond, Washington headquarters.

The scale of the discovery haul is now showing up in Microsoft's public patch cadence. In June, the company released fixes for more than 200 bugs — at the time called an all-time high. On July 14, it shipped patches for more than 600. Only 7 of those were low- or moderate-severity, and one of the seven was already being actively exploited by hackers, according to Dustin Childs of the Zero Day Initiative at TrendAI.

A recording of a mid-May internal Microsoft meeting, obtained by ProPublica, captures the tone inside the company. Asked whether Mythos lived up to Anthropic's advance billing, a manager answered "Yes." Engineering manager Hans Andersen told the team they had roughly two weeks left before what he described as the day "the rest of the world will have caught up" — May 31.

So basically you're saying if it's released on June 1, then on June 2 the adversaries will have our bugs?
Unnamed Microsoft engineer, SharePoint engineering team

Key facts

  • 01Anthropic's Mythos model uncovered 90 critical and 141 important SharePoint bugs in April 2026, plus roughly 300 moderate-severity flaws now queued for later patching.
  • 02Microsoft released fixes for more than 600 bugs on July 14, blowing past the June record of 200 that industry experts had called an all-time high.
  • 03Of the July 14 patch batch, only 7 were low- or moderate-severity, and one was already being actively exploited by hackers.
  • 04A May Microsoft meeting flagged May 31 as the internal deadline before adversaries would catch up, part of a program dubbed Project Glasswing.
  • 05The Five Eyes alliance warned in late June that the window for defenders to out-patch AI-equipped attackers is closing within months.

Anthropic gave Claude Mythos Preview access to a small number of software makers under Project Glasswing, which was made public in April 2026. The idea was to give US and allied companies a head start finding vulnerabilities before hostile governments, including China, built equivalent capabilities. In late June, the Five Eyes intelligence alliance — the US, UK, Canada, Australia, and New Zealand — issued a joint warning that the window was closing within months. Internal Microsoft documents suggest it may already be closed.

Microsoft is triaging the flood by severity, working through critical bugs first, then important, then a queue of roughly 300 moderate-severity SharePoint bugs. The company said its SharePoint team will "be busy for months," with important bugs slated for August. Low-severity flaws did not appear in the internal remediation plans reviewed by ProPublica.

That triage approach is standard industry practice, but Vinh Nguyen — a senior Anthropic adviser and the National Security Agency's former chief AI officer — argues it no longer matches the threat. Mythos and similar systems can chain multiple low-severity flaws into a single high-severity exploit path, which means the bottom of the triage queue is now more dangerous than the framework was designed to handle.

The problem extends across Microsoft's stack, not just SharePoint. Internal documents indicate Mythos has found hundreds of critical or important bugs across Microsoft 365, Teams, and Copilot since the company began using the model earlier this year. As of mid-May, most had not been patched. "They're not profound and exotic, but they're real," Andersen said in the recorded meeting. "And a lot of them are exploitable."

Microsoft, in emailed responses, defended its triage methodology and said chaining "has long been considered as part of vulnerability assessment and risk analysis." A spokesperson said the company "feels a sense of urgency to help our customers at this time" and has "invested heavily in both people as well as AI-powered triage solutions that scale quickly to handle the growing number of vulnerabilities." The company declined to say how many bugs its engineers had patched since the May meeting.

Well folks. Here we are. The bug apocalypse has fully descended upon us.
Dustin Childs, Leader of the Zero Day Initiative at TrendAI
Related · from this week
Anthropic ships Claude Fable 5 with hard blocks on cyber, bio, and chemistry queries
Jaeden Schafer · 5 min read →

The volume, Microsoft told ProPublica, "will not be plateauing for a bit." The company also acknowledged that AI-driven discovery is forcing a rethink of severity classifications themselves — flaws previously rated low or moderate may need to be upgraded once chaining is factored in. Anthropic declined to comment.

Part of Microsoft's exposure is structural. Its products run on decades of legacy code carrying long-accumulated technical debt, and their global install base makes them a preferred target. But the underlying dynamic — an AI defender's model matched, then eventually surpassed, by attackers using equivalent tools — is not specific to Microsoft. It applies to every large software vendor and, more acutely, to the open-source projects maintained by volunteers.

For the AI market, this is the first concrete stress test of the argument that offensive and defensive AI capabilities cancel out. So far, the data cuts the other way: a single model gave one defender enough surface area to overwhelm its own patch pipeline, and the patch pipeline is where users actually get protected. If Anthropic's Mythos generation is what a controlled-access preview looks like, the second-order question is what happens when equivalent capability is not access-controlled. Microsoft's July Patch Tuesday tripling to 600 fixes is the leading indicator, and every other major software vendor should assume its own numbers are next.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Anthropic logo
Security

Anthropic ships Claude Fable 5 with hard blocks on cyber, bio, and chemistry queries

The publicly available Mythos-class model routes sensitive prompts back to Opus 4.8 and costs 67-100% more than GPT-5.5.

Jaeden Schafer5 min read
Anthropic logo
Security

Anthropic expands Claude Mythos vulnerability hunt to 150 organizations across 15+ countries

Project Glasswing now covers power, water, healthcare, and hardware codebases — a day after Anthropic filed confidentially for an IPO.

Jaeden Schafer4 min read
Anthropic logo
Models

Anthropic releases Claude Fable 5, its first public Mythos-class model

The lab once said Mythos was too dangerous to ship. New safeguards route 5% of risky prompts back to Opus 4.8.

Jaeden Schafer5 min read