Anthropic’s Mythos model has been finding software vulnerabilities in Microsoft products faster than Microsoft can fix them, according to a ProPublica investigation published July 29 based on internal Microsoft documents and a recording of an internal meeting.
In April alone, Claude Mythos Preview uncovered 90 “critical” bugs and 141 “important” ones in SharePoint, Microsoft’s collaboration software used by governments and businesses worldwide, according to a presentation reviewed by ProPublica. The first half of May produced even more.
Project Glasswing
Microsoft is one of several organizations participating in Project Glasswing, Anthropic’s initiative to give select software makers early access to Mythos so they can identify and fix vulnerabilities before adversaries develop equivalent AI tools. Anthropic made the project public in April.
During a mid-May meeting at Microsoft’s Redmond headquarters, engineering manager Hans Andersen urged colleagues to close out April bugs immediately. “Please, please, please if your org has any April bugs, drive those down,” Andersen said, according to ProPublica’s reporting.
The deadline was May 31, which Andersen described as “the day when the rest of the world will have caught up.” One engineer on the call translated the implication directly: “So basically you’re saying if it’s released on June 1, then on June 2 the adversaries will have our bugs?”
Multiple people on the call confirmed that assessment.
The Numbers
Since Microsoft began using Mythos earlier in 2026, the model has collectively identified hundreds of bugs classified as critical or important across Microsoft 365, Teams, Copilot, and SharePoint, according to internal documents reviewed by ProPublica. As of mid-May, most remained unpatched.
“They’re not profound and exotic, but they’re real,” Andersen said during the meeting. “And a lot of them are exploitable.”
The pressure has shown up in Microsoft’s public patch releases. June’s Patch Tuesday included fixes for over 200 bugs, which security researchers called an all-time high at the time. On July 14, Microsoft shattered that record with patches for more than 600 bugs. Only seven were categorized as low or moderate severity. One was already being actively exploited.
“Well folks. Here we are. The bug apocalypse has fully descended upon us,” wrote Dustin Childs, leader of the Zero Day Initiative bug bounty program.
The Chaining Problem
Microsoft’s current triage approach prioritizes critical and important bugs first, with plans to address roughly 300 “moderate” bugs afterward. Internal documents made no mention of “low” severity flaws. That approach mirrors standard industry practice.
But Vinh Nguyen, a senior technical adviser to Anthropic who formerly served as chief AI officer and chief data scientist at the National Security Agency, told ProPublica that Mythos can chain together multiple lower-severity bugs into high-severity attack paths. “The problem now is that you can chain four low-level flaws, and that can equal a high severity,” Nguyen said. “If you’re Microsoft, the current triage strategy may be underpricing risks.”
Microsoft told ProPublica that vulnerability chaining “has long been considered as part of vulnerability assessment and risk analysis,” and that the overall volume of bugs “will not be plateauing for a bit.”
The Window Is Closing
In late June, the Five Eyes intelligence alliance (the U.S., Australia, Canada, New Zealand, and the U.K.) issued an unusual joint statement warning that the window for defenders to fix AI-discovered flaws before adversaries develop equivalent tools was shrinking to months. ProPublica’s reporting suggests that window may already be closing.
J. Michael Daniel, a former cybersecurity adviser to President Obama and president of the Cyber Threat Alliance, told ProPublica that “nobody has really figured out how to deal with this, and everybody is casting around for what they need to do. Our tech debt is coming due.”
The Remediation Bottleneck
The structural challenge extends beyond any single company. Microsoft’s Security Response Center has been “perennially understaffed,” according to ProPublica, reflecting a corporate philosophy where security patching is treated as a cost center while product development drives profits. Ben Edwards, a data scientist specializing in vulnerability management, described the shift: “It was like drinking from a garden hose on the jet setting before, and now it’s like drinking from a fire hose.”
Nguyen argued that companies need to fundamentally rethink triage in the AI era, dedicating staff to develop and test patches across the entire severity spectrum. “There’s no alternative,” Nguyen said. “The patients are coming in fast and furious.”
Microsoft said it has “invested heavily in both people as well as AI-powered triage solutions” and is evaluating “whether things that were previously lows or moderates be upgraded or thought about differently.”