ProPublica, a nonprofit investigative journalism organization focused on scrutinizing power dynamics, offers an option to subscribe for updates on their key stories.
In mid-May, Microsoft engineers and their leadership convened both online and in person at the company’s Redmond, Washington, headquarters to address Project Glasswing.
The tech giant was under pressure to address vulnerabilities in its software exposed at an alarming rate by an innovative AI model called Mythos. Developed by Anthropic, this AI powerhouse granted select organizations access to its capabilities, aiming to identify and rectify flaws before malicious entities, including those from adversarial nations like China, could use similar technologies for harmful purposes.
As the session began, one engineer raised the pivotal question: Was Mythos living up to the expectations set by Anthropic?
“Yes,” a manager affirmed, based on audio from the meeting that ProPublica reviewed.
The Microsoft version, known as Claude Mythos Preview, revealed bugs faster than the company could address them, prompting engineers to engage in a “mad dash” to bridge the gap.
A slideshow presented during the meeting highlighted that in April alone, Mythos identified 90 “critical” and 141 “important” bugs within SharePoint, Microsoft’s popular collaboration tool. Its findings continued to grow in the first half of May.
“Please, please, please, if your organization has any bugs from April, handle those immediately,” urged engineering manager Hans Andersen. They had about two weeks left “to discover and remediate as much as possible.”
He added that May 31 marked a crucial deadline, signifying when adversaries would likely catch up to them.
The engineers scrutinized this assertion, with one summarizing the risk: “So, if it’s released on June 1, on June 2, adversaries will have our bugs?”
“Exactly,” came the response from the group.
The conversation surrounding AI's potential in bug detection escalated after Anthropic publicly initiated Project Glasswing in April, prompting national security experts to predict a narrow window for the U.S. to rectify its software weaknesses before adversaries could leverage similar models. In a rare joint statement, the intelligence alliance known as the Five Eyes—including the U.S., U.K., Canada, Australia, and New Zealand—cautioned that this window of opportunity would soon close. However, internal documents and the Microsoft meeting recording imply that this moment of reckoning may have already arrived.
With the overwhelming number of flaws identified by Mythos, Microsoft has primarily concentrated on addressing those categorized as the most dangerous—critical or important vulnerabilities, as outlined in both the presentation and public updates. Records indicate that Microsoft also intends to address “moderate” vulnerabilities flagged by Mythos eventually but made no mention of “low” severity bugs.
This prioritization reflects a common practice in the industry where vulnerabilities posing the highest risk are treated first, akin to how emergency rooms prioritize critically ill patients.
Nevertheless, this approach presents a significant risk in the current AI-enabled landscape, where new tools are revealing an unprecedented number of software weaknesses. Mythos has demonstrated an ability to connect several minor vulnerabilities, suggesting that unattended low and moderate flaws could be exploited together to launch serious attacks.
“The issue now is that you can link multiple low-level vulnerabilities to create a significant risk,” noted Vinh Nguyen, an expert from Anthropic and former AI chief for the NSA. “If you’re Microsoft, this skewed triage strategy could underestimate potential threats.”
In response to inquiries from ProPublica, Microsoft defended its methodology, stating that its decisions on vulnerability prioritization consider factors like the likelihood of exploitation and the potential impact on customers. Although the internal presentation didn’t reference the concept of chaining vulnerabilities, a spokesperson asserted that this has long been part of risk assessment in vulnerability management.
Regarding the significance of the internal meeting and the impending May 31 deadline, the spokesperson downplayed its urgency, noting that rapid exploitation of newly found vulnerabilities is not unprecedented. That said, they acknowledged the company's keen urgency to better protect its customers.
“What was evident on that call remains true: Security is Microsoft’s top priority, and teams across the company are focused on utilizing AI to discover and resolve vulnerabilities promptly.”
Microsoft did not disclose how many bugs had been patched following the presentation.
Anthropic refrained from commenting.
According to internal documents accessed by ProPublica, staff working on SharePoint—serving as a platform for data and document management for numerous businesses and governments—would be engaged for months addressing critical vulnerabilities first, then the important ones by August. Critical vulnerabilities are categorized as threats capable of launching worms that can disrupt systems or spread malware, while important issues could compromise user data integrity or system resources. Once these are addressed, the group would turn its attention to around 300 moderate vulnerabilities.
While ProPublica’s reviewed documents do not encapsulate the entirety of Microsoft’s software vulnerabilities, they shed light on the scale of the issue. One document revealed that since implementing Mythos, the tech giant has identified hundreds of critical and important vulnerabilities in popular products including Microsoft 365 and Teams, with many remaining unpatched as of mid-May.
“They’re not overly complex or unusual, but they are genuine vulnerabilities,” Andersen remarked during the meeting. “And many of them are ripe for exploitation.”
It remains uncertain whether any specific bugs identified by Mythos have been actively used by hackers, though reports suggest that some adversaries are employing AI to automate their attack strategies and appear to be utilizing similar tech to exploit weaknesses.
Microsoft’s evident struggle to tackle the escalating list of vulnerabilities is evident in its monthly release cycles aimed at addressing software flaws, known as “Patch Tuesday.” In June, the company filled gaps for over 200 bugs—an unprecedented number. However, on July 14, that record was shattered when Microsoft published fixes for more than 600 bugs, with only seven classified as low or moderate severity, one of which was supposedly under active exploitation, as noted by Dustin Childs of the Zero Day Initiative, a cybersecurity organization. The majority were deemed critical or important.
“Here we are. The bug apocalypse has hit us,” Childs expressed on his blog following the July release.
Microsoft confirmed to ProPublica that the overall number of identified vulnerabilities is unlikely to stabilize soon, while asserting that they have made significant investments in both personnel and AI-powered solutions for rapid triage to manage the growing influx of vulnerabilities.
In light of AI's evolving dynamics, including the chain vulnerability phenomenon, experts like Nguyen argue that companies like Microsoft may need to revise their entire approach. Rather than sidelining what are currently considered low-risk flaws, firms should focus on assembling teams dedicated to developing and testing patches across the complete range of vulnerabilities. Essentially, the cybersecurity landscape requires both comprehensive resources for critical threats and consistent care for lesser vulnerabilities that could later prove damaging.
“There’s no alternative,” Nguyen argued. “The influx of issues is relentless.”
In response to ProPublica’s inquiries, Microsoft indicated it continually reassesses its approach to vulnerability categorization, expressing an awareness of the need to adapt to new realities introduced by AI systems.
The sheer volume of Microsoft’s user base makes its software a significant target for cybercriminals, further complicated by the presence of outdated “legacy” code that harbors unaddressed vulnerabilities—what’s often termed as “technical debt.”
The burden of rectifying the surge in newly discovered bugs extends throughout the software industry, including the open-source ecosystem, which relies heavily on volunteers for maintenance and is integral to modern tech infrastructure, including products from major firms like Microsoft.
“There isn’t a clear solution in sight, and stakeholders are scrambling for strategies,” remarked J. Michael Daniel, a former cybersecurity advisor to President Obama. “Our technological shortcomings can no longer be ignored.”
Ben Edwards, a data scientist focused on software vulnerabilities, noted that even before the onset of AI, the industry was managing an impressive volume of bugs. “Handling bugs used to be like drinking from a garden hose; now it feels more like a fire hose. The existing teams might cope with the former, but it’s uncertain if they can manage the latter.”
Despite the growing influx of vulnerabilities, Microsoft’s Security Response Center typically finds itself understaffed. ProPublica has previously reported that this center generally faces hundreds, if not thousands, of monthly reports, often pushing its resources to the brink.
This staffing shortfall is indicative of Microsoft’s broader corporate approach: addressing security issues is seen as a cost center, whereas developing new products aligns with profit generation, as has been noted by former employees. The company is hesitant to deploy its top engineers on security patches, prioritizing new features that bolster its bottom line.
Responding to ProPublica, Microsoft stated it does not discuss internal staffing decisions; however, it has claimed to invest in ensuring that teams are adequately focused on customer security. The company continuously assesses its staffing and methodologies for security management.
Slides from the internal May presentation indicated that Anthropic had provided Mythos access to roughly 50 full-time Microsoft employees to enhance critical services before publicly available models could catch up. Another slide suggested a continued high volume of cases would persist as public tools advance alongside Mythos.
During the May discussion, one team member expressed some assurance, suggesting that adversaries lacked access to the source code necessary for AI scans. However, colleagues quickly pointed out that portions of Microsoft’s code have been compromised over time.
“It may not be the current source code,” one noted, “but they do have some code that’s out there.”
Microsoft responded by downplaying this sentiment, clarifying that their security protocols are designed on the premise that determined adversaries might gain access to code in various forms.


