Anthropic's AI model finds software bugs faster than Microsoft can patch them

Reviewed byNidhi Govil

2 Sources

Share

Anthropic's Mythos AI model is uncovering software vulnerabilities at an unprecedented rate, leaving Microsoft engineers in a "mad dash" to fix them. In April alone, the AI discovered 90 critical and 141 important bugs in SharePoint, raising concerns about a shrinking window before adversaries gain similar capabilities.

Anthropic's AI Model Mythos Outpaces Microsoft's Patching Efforts

Microsoft engineers gathered in mid-May at the company's Redmond, Washington headquarters for an urgent discussion about Project Glasswing, facing a reality they hadn't fully anticipated. Anthropic's AI model known as Mythos was discovering software bugs faster than Microsoft could fix them, creating what one manager described as "a mad dash" to close the gap

1

. When asked if the AI-powered bug-finding tool lived up to expectations, a manager confirmed simply: "Yes." The Claude Mythos Preview version was surfacing vulnerabilities at an unprecedented rate of bug discovery that threatened to overwhelm the tech giant's patching efforts

2

.

Source: ProPublica

Source: ProPublica

Internal presentation slides revealed the scale of the challenge facing Microsoft's internal efforts. In April alone, Anthropic's AI model Mythos identified 90 critical and important bugs classified as critical, plus 141 marked as important in Microsoft's SharePoint, the widely used collaboration software

1

. The first half of May brought even more discoveries, prompting engineering manager Hans Andersen to implore his team: "Please, please, please if your org has any April bugs, drive those down." The urgency stemmed from a looming deadline—May 31 was considered the day when adversaries including China would likely have caught up with similar AI-driven vulnerability discovery capabilities

2

.

A Shrinking Window of Opportunity

The recording of the Microsoft meeting, obtained by ProPublica, captured engineers grappling with a troubling timeline. One engineer summarized the predicament bluntly: "So basically you're saying if it's released on June 1, then on June 2 the adversaries will have our bugs?" Two colleagues responded affirmatively

1

. This exchange underscores a critical shift in the cybersecurity landscape. National security experts had predicted a window of opportunity for the U.S. to fix flaws before hostile actors developed similar tools. The Five Eyes intelligence alliance—comprising the U.S., Australia, Canada, New Zealand and the U.K.—issued an unusual joint warning in late June that this window would close within months. But internal documents suggest that day of reckoning may already be here

2

.

Anthropic developed Mythos and granted early access to select organizations that produce software used by regular people, companies and governments worldwide. The goal was straightforward: find and fix vulnerabilities before hackers and adversarial governments could exploit them for espionage and sabotage. Yet the sheer volume of discoveries has forced Microsoft to adopt a triage approach, focusing first on patching those bugs it considers most dangerous

1

.

The Risk of Vulnerability Chaining

Microsoft's strategy of prioritizing critical and important bugs follows industry-standard triage practices, similar to how emergency rooms treat the sickest patients first. Internal records indicate plans to eventually address moderate-severity flaws, though documents made no mention of low-severity bugs

2

. This approach carries significant risk in the AI-powered bug-finding era. Mythos can chain together multiple lower-severity vulnerabilities that build on one another, potentially enabling devastating attacks.

"The problem now is that you can chain four low-level flaws, and that can equal a high severity," explained Vinh Nguyen, a senior technical adviser to Anthropic and senior fellow for AI at the Council on Foreign Relations who formerly served as chief AI officer and chief data scientist at the National Security Agency. "If you're Microsoft, the current triage strategy may be underpricing risks"

1

. While a Microsoft spokesperson told ProPublica that vulnerability chaining "has long been considered as part of vulnerability assessment and risk analysis," the company presentation did not mention this technique

2

.

National Security Implications and What's Next

Microsoft defended its approach in emailed responses, stating that triaging decisions consider multiple factors including exploitability and customer impact. The company downplayed the significance of the May 31 deadline, noting that "accelerated targeting and exploitation of new vulnerabilities is not a new phenomenon." However, a spokesperson acknowledged that comments during the meeting reflect how Microsoft "feels a sense of urgency to help our customers at this time"

1

. As AI models continue advancing their bug-hunting capabilities, software companies face mounting pressure to accelerate patching timelines while adversaries race to develop comparable tools for offensive purposes.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved