
ai bug hunting Anthropic’s AI bug-hunting system is surfacing so many vulnerabilities in Microsoft software that the company’s security teams are racing to patch them before attackers can catch up. Internal documents and a recorded May meeting reviewed by ProPublica show Microsoft engineers describing a “mad dash” to close the gap as Anthropic’s Claude Mythos Preview uncovered critical and important flaws at a pace that outstripped remediation.
ai bug hunting
Project Glasswing and the scale of the problem
The effort was tied to Project Glasswing, Anthropic’s program to give select organizations access to Mythos, a model designed to find weaknesses in software used by consumers, businesses and governments. The purpose, according to the source material, was to identify bugs before hackers and hostile states, including China, could use similar AI systems for espionage or sabotage.
At Microsoft’s mid-May meeting in Redmond, Washington, an engineering manager told staff that Mythos was already doing more than the company could keep up with. In April alone, the model had found 90 “critical” bugs and 141 “important” bugs in SharePoint, Microsoft’s widely used collaboration platform. In the first half of May, it found even more.
Hans Andersen, the engineering manager, urged colleagues to drive down the backlog of April bugs and said the team had roughly two weeks “to find as many things and do as much good as we can with this access.” He said May 31 would be “the day when the rest of the world will have caught up.”
Why Microsoft is focused on triage
Microsoft’s internal strategy reflects standard industry practice: prioritize the most dangerous issues first, then move down the severity scale. The company said it is concentrating on flaws classified as critical or important, and later plans to address moderate-severity bugs uncovered by Mythos. The documents reviewed by ProPublica made no mention of low-severity issues.
That approach is common because resources are finite and the worst vulnerabilities can cause the most immediate harm. But several experts quoted in the material argued that AI changes the equation. Mythos can chain together multiple lower-severity flaws, meaning several “minor” bugs could combine into a serious attack path.
Why low-severity bugs may matter more now
- AI tools can discover large numbers of flaws quickly.
- Attackers may chain several low- or moderate-severity issues into a high-severity exploit.
- Unpatched lower-priority bugs can become part of larger compromise chains.
Vinh Nguyen, a senior technical adviser to Anthropic and a senior fellow for AI at the Council on Foreign Relations, said the current triage model may be “underpricing risks.” He noted that “you can chain four low-level flaws, and that can equal a high severity.” Nguyen formerly served as chief AI officer and chief data scientist at the National Security Agency.
Microsoft says urgency is rising, but the approach stands
In emailed responses, Microsoft defended its triage process and said decisions are based on factors such as exploitability and customer impact. A spokesperson said chaining “has long been considered as part of vulnerability assessment and risk analysis.” The company also said accelerated targeting of new vulnerabilities is “not a new phenomenon,” while acknowledging the sense of urgency around the issue.
Microsoft declined to say how many bugs had been patched since the presentation. Anthropic declined to comment.
Patch Tuesday numbers show the pressure
The internal documents suggest Microsoft’s workload is not confined to SharePoint. Since the company began using Mythos earlier this year, it has found hundreds of critical or important bugs across products including Microsoft 365, Teams and the Copilot AI tool. As of mid-May, most had not yet been patched.
The company’s public patch cadence has also shown unusual strain. In June, Microsoft disclosed fixes for more than 200 bugs, which industry experts said was a record at the time. On July 14, it released patches for more than 600 bugs, with only seven categorized as low- or moderate-severity. According to Dustin Childs, who leads the Zero Day Initiative bug bounty program at TrendAI, one of those lower-severity bugs was already being actively exploited. He described the moment in a July 14 blog post as the arrival of “the bug apocalypse.”
What the May presentation indicated
- SharePoint work would take months.
- Critical bugs would be addressed first.
- Important bugs were expected to follow in August.
- Roughly 300 moderate bugs remained after that.
Why Microsoft is especially exposed
Microsoft is a frequent target because its products are widely used around the world by governments, businesses and individuals. The company also relies on legacy code, some of it decades old, which adds technical debt and can leave long-standing flaws in place. The problem is broader than Microsoft, however. The source material notes that open-source software, which underpins much of the internet and is widely used in commercial products, faces the same growing vulnerability burden.
J. Michael Daniel, president of the Cyber Threat Alliance and a former cybersecurity adviser to President Barack Obama, said the industry is still searching for a workable response. “Our tech debt is coming due,” he said.
Ben Edwards, a data scientist who specializes in software vulnerability management, said the pre-AI workload already felt extreme. With AI now accelerating bug discovery, he compared the shift to moving from “drinking from a garden hose” to “drinking from a fire hose.”
A wider debate about security staffing and priorities
The Microsoft Security Response Center, which handles vulnerability reports, has long been described as understaffed, even before the surge in AI-generated findings. Previous ProPublica reporting has said the center often receives hundreds or thousands of reports each month. Former employees have also said Microsoft tends to treat security patching as a cost center rather than a profit driver.
Microsoft said it does not discuss internal staffing decisions, but said it has invested in people, processes and AI-powered triage tools to handle the growing volume. The company also said it continuously evaluates whether vulnerabilities previously considered low or moderate should be upgraded in light of AI capabilities.
What comes next
The central question raised by the Microsoft meeting is whether the industry’s current patching model is still viable when AI can uncover and chain weaknesses faster than teams can fix them. Nguyen argued that companies may need to stop treating the lowest-severity bugs as less urgent and instead devote staff to testing and patching the full spectrum of vulnerabilities.
“There’s no alternative,” he said. “The patients are coming in fast and furious.”
Microsoft, for its part, said it is prioritizing vulnerability discovery and remediation “as quickly as possible.” But the records reviewed by ProPublica suggest the company is already operating under a new reality: one in which the race between discovery and defense may be narrowing to a dangerous degree.
Explore more: Blog Our Services Contact Us
Source: Original report
Was this helpful?
Last Modified: July 30, 2026 at 6:37 pm
2 views

