Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

propublicathehackernews+1propublicaAnthropic's Claude Mythos AI model has been uncovering software vulnerabilities in Microsoft products at a pace that outstrips the company's ability to patch them, according to internal Microsoft recordings and documents obtained by ProPublica.propublica
In a mid-May meeting dubbed Project Glasswing, Microsoft engineers discussed how Mythos had surfaced 90 critical bugs and 141 important ones in SharePoint alone during April, with even more found in the first half of May. Engineering manager Hans Andersen urged colleagues to drive down the backlog before a May 31 deadline, after which Anthropic's model would become more widely available. "Please, please, please if your org has any April bugs, drive those down," Andersen told the group.propublica
The urgency was palpable. When one engineer asked whether adversaries would have access to their bugs by June 2, colleagues confirmed: "Yep."
The strain has become publicly visible. On July 14, Microsoft released patches for more than 600 vulnerabilities in its monthly Patch Tuesday update — an all-time record. Nearly all were rated important or critical, and at least two were already being exploited in the wild, including a SharePoint Server flaw.linkedin+2
"Well folks. Here we are. The bug apocalypse has fully descended upon us," wrote Dustin Childs of the Zero Day Initiative in a blog post that day.thezdi+1
Microsoft told ProPublica the overall volume "will not be plateauing for a bit" but said the company has "invested heavily in both people as well as AI-powered triage solutions."propublica
The challenge extends well beyond Microsoft. On July 28, Hitachi announced that its participation in Project Glasswing had reduced threat modeling for codebases running into millions of lines from weeks to hours, uncovering vulnerabilities in mission-critical proprietary software that existing tools had missed.ibtimes
In late June, the Five Eyes intelligence alliance issued an unusual joint warning that frontier AI models were "fundamentally transforming both offensive and defensive cyber capabilities" and that "the timeline is not years, it is months".euronews+1
Vinh Nguyen, a former chief AI officer at the National Security Agency and now a senior technical adviser to Anthropic, warned that Microsoft's standard triage approach — prioritizing the most severe bugs first — may be inadequate. Because Mythos can chain together low-severity flaws into devastating attack paths, he said, "the current triage strategy may be underpricing risks".propublica
"There's no alternative," Nguyen added. "The patients are coming in fast and furious."propublica