Microsoft Racing to Patch Vulnerabilities Faster Than Anthropic's Mythos AI Can Discover Them
Key Takeaways
- ▸Anthropic's Mythos AI discovered 90 critical and 141 important vulnerabilities in Microsoft SharePoint in April alone, vastly exceeding human patching capacity
- ▸National security experts estimate only months remain before adversarial governments and hackers obtain similar AI vulnerability-discovery capabilities
- ▸Microsoft is pursuing aggressive triage, focusing resources on critical and important vulnerabilities while potentially leaving thousands of lower-severity bugs unpatched
Summary
Anthropic's Mythos AI model, deployed through Project Glasswing to select organizations, is discovering security vulnerabilities at an unprecedented rate—far faster than Microsoft can patch them. Internal Microsoft documents and recorded meetings reviewed by ProPublica reveal that in April alone, Mythos uncovered 90 critical bugs and 141 important vulnerabilities in SharePoint. Engineers described themselves as being in a "mad dash" to close the gap between discovery and patching.
The urgency reflects national security concerns: the U.S. and its Five Eyes allies warned in June that the window to fix these vulnerabilities before adversarial nations and hackers develop similar AI tools is rapidly closing. According to Microsoft's internal timeline, May 31 was identified as the deadline before "the rest of the world will have caught up"—meaning adversaries could deploy comparable models by June 1.
Microsoft's response reflects difficult triage decisions. The company is prioritizing only critical and important vulnerabilities for patching, with plans to eventually address moderate-severity flaws and no clear timeline for low-severity bugs. This approach reflects industry practice but raises questions about whether it remains adequate in an era of AI-accelerated vulnerability discovery.
- The incident reveals a new cybersecurity paradox: tools that enhance defense can also accelerate the timeline to compromise if adoption by adversaries outpaces patch deployment
Editorial Opinion
Anthropic's Mythos has exposed a critical vulnerability in our vulnerability-management processes—the sheer velocity of AI-powered discovery now outpaces human response systems. While the ability to find bugs at scale is a clear positive, this story underscores a systemic crisis emerging in cybersecurity: unless patch velocity matches discovery velocity, the tools meant to make us safer may actually accelerate the timeline to major breaches when adversaries gain access. The national security community faces a race it may already be losing.


