Anthropic is finding bugs faster than Microsoft can fix them

← Back to the feed

Anthropic is finding bugs faster than Microsoft can fix them

Ars Technica · 7 hours ago

Microsoft is struggling to patch security flaws in its software faster than Anthropic's new AI model, known as Mythos, can uncover them, according to a recording of an internal meeting and documents reviewed by ProPublica. The situation stems from Project Glasswing, an Anthropic initiative granting select software makers early access to Mythos so they could find and fix vulnerabilities before hackers or hostile states, such as China, could exploit similar AI tools themselves. The episode matters because it suggests the anticipated head start for defenders may already be running out, undermining assurances from national security officials that there would be a meaningful window to shore up systems first.

Internal figures showed Mythos uncovered 90 "critical" and 141 "important" bugs in Microsoft's SharePoint software in April alone, with even more found in early May, prompting engineers to describe a "mad dash" to fix them. Microsoft has prioritised patching only critical and important flaws, with plans to later address "moderate" ones, while lower-severity bugs are not yet being tackled — a standard triage approach that nonetheless carries risk, since Mythos can chain together multiple smaller flaws into more serious exploits. In late June, the Five Eyes intelligence alliance (US, UK, Australia, Canada and New Zealand) warned that this defensive window would close within months, but the Microsoft meeting suggests that point may have already arrived.

  • Anthropic's Mythos AI finds bugs faster than Microsoft can patch them
  • SharePoint alone had 90 critical, 141 important flaws in April
  • Five Eyes warned the defenders' head-start window is closing fast

AI Cybersecurity Technology

Read the full article at the source →