Wed 29 Jul 2026 / 17:33 ET
Kernel
Internet 3 min read

Anthropic Mythos Microsoft bugs pile up faster than patches

ProPublica reports Anthropic’s Mythos AI found hundreds of Microsoft flaws, forcing triage in SharePoint, 365, Teams and Copilot.

Dana Voss

By Dana Voss / Security Correspondent

Anthropic Mythos Microsoft bugs pile up faster than patches
img: Ars Technica

Anthropic Mythos Microsoft bugs have become a live stress test for one of software’s least glamorous jobs: fixing the holes before attackers turn them into working exploits. ProPublica reported that Microsoft engineers were told in May that Anthropic’s Claude Mythos Preview was finding vulnerabilities faster than Microsoft could repair them.

The reporting is based on a Microsoft meeting recording and internal documents reviewed by ProPublica. Anthropic had given selected organizations access to Mythos through Project Glasswing, an effort to expose software flaws before similar AI tools became widely available to hackers or foreign governments.

During a mid-May meeting at Microsoft, an engineering manager said the model had met Anthropic’s claims, according to ProPublica. A presentation showed that Mythos found 90 critical and 141 important bugs in SharePoint in April, with more found in the first half of May. Hans Andersen, a Microsoft engineering manager, urged teams to reduce the April backlog, saying they had about two weeks of access to find and fix as much as possible.

What is Anthropic Mythos finding at Microsoft?

Mythos is an AI model Anthropic made available to selected software makers to hunt for vulnerabilities. If you need the broader machinery behind systems like this, Kernel has a plain-language guide to how LLMs work.

At Microsoft, ProPublica reported, Mythos identified hundreds of critical or important flaws across major products, including SharePoint, Microsoft 365, Teams and Copilot. SharePoint is a particularly sensitive target because businesses and governments use it to store and manage documents and data.

Microsoft told ProPublica that it prioritizes bugs using factors such as exploitability and customer impact. That is standard vulnerability triage: fix the flaws most likely to cause the worst damage first, then work down the list. Microsoft said security is its top priority and that teams are using AI to find and remediate vulnerabilities as quickly as possible.

The problem is volume. Internal Microsoft materials reviewed by ProPublica said SharePoint staff would be busy for months, first with critical bugs, then important ones, then about 300 moderate flaws. Microsoft declined to say how many Mythos-discovered bugs had been patched since the May presentation.

Why low-severity bugs may no longer stay low

Vulnerability ratings can understate risk when several small flaws can be combined. Vinh Nguyen, a senior technical adviser to Anthropic and a former NSA chief AI officer, told ProPublica that four low-level flaws chained together can produce high-severity impact. He said Microsoft’s current triage may be undervaluing that risk.

Microsoft told ProPublica that chaining has long been part of its vulnerability assessment and risk analysis. The company also said it is reconsidering whether some issues formerly treated as low or moderate should be rated differently as AI systems change vulnerability discovery.

Public patch data shows the pressure. Microsoft’s June Patch Tuesday fixed more than 200 bugs, which the Zero Day Initiative described as a record at the time. On July 14, Microsoft released fixes for more than 600 bugs. Dustin Childs of the Zero Day Initiative said only seven were low or moderate severity, and one of those was already being exploited.

Microsoft told ProPublica that vulnerability volume would not level off for a while, but said it has invested in people and AI-powered triage tools. The company declined to discuss internal staffing decisions.

The risk is broader than Microsoft. J. Michael Daniel, a former cybersecurity adviser to President Barack Obama and now president of the Cyber Threat Alliance, told ProPublica that the software industry has not settled on how to cope with the new pace of AI-assisted bug discovery. Ben Edwards, a vulnerability management data scientist, said the industry already faced intense volume before AI made the stream worse.

Anthropic declined to comment to ProPublica. Microsoft said its security processes assume determined adversaries may gain access to code, after engineers in the May meeting noted that portions of Microsoft source code have leaked over the years.

This story draws on original reporting from Ars Technica.

More Internet/

view all ↗