Anthropic's Mythos AI finds Microsoft bugs faster than they can patch
90 critical SharePoint bugs found in one month — and adversaries are closing in.
In mid-May 2025, a group of Microsoft engineers gathered to discuss Project Glasswing, a collaboration with Anthropic to deploy its Mythos AI (a variant of Claude) for bug hunting. Mythos Preview revealed an alarming volume of vulnerabilities: in April alone, it uncovered 90 critical bugs and 141 important ones in SharePoint, Microsoft's widely used collaboration software. The pace accelerated in early May, leaving Microsoft scrambling to patch before June 1, when similar tools would likely become available to adversaries like China. Engineering manager Hans Andersen told the team they had roughly two weeks, calling it 'a mad dash' to close the gap.
Microsoft's current triage strategy prioritizes critical and important vulnerabilities, planning to address moderate ones later and ignoring low-severity bugs entirely. However, experts like Vinh Nguyen (Anthropic senior technical adviser and former NSA chief AI officer) warn that Mythos can chain multiple low-level flaws into a high-severity exploit. This means unpatched moderate and low bugs could create dangerous attack vectors. The Five Eyes alliance issued an unusual joint statement in late June 2025, warning that the window of opportunity to fix these flaws is shrinking fast — and may already be closed. Internal Microsoft documents reviewed by ProPublica confirm the company has yet to publicly disclose the full scope of Mythos's findings or its long-term patch plan.
- Anthropic's Mythos AI uncovered 90 critical bugs and 141 important ones in Microsoft SharePoint in April 2025.
- Microsoft engineers had a two-week 'mad dash' to patch before adversaries could access similar AI tools by June 1.
- Experts warn that chaining moderate and low-severity bugs found by Mythos could enable high-severity attacks, challenging current triage strategies.
Why It Matters
AI-driven bug hunting is outpacing patch cycles, forcing a rethink of vulnerability management for all enterprise software.