AI finds so many Windows flaws, Microsoft can’t keep up. Should you worry? Anthropic's Mythos AI model has found thousands of high-severity vulnerabilities in major operating systems and web browsers, including Windows, faster than Microsoft can patch them, forcing Microsoft to prioritize only the most dangerous bugs. Microsoft is currently patching only the most severe flaws, with plans to address 'moderate'-severity issues later and no mention of 'low'-severity bugs, raising concerns among experts like Vinh Nguyen, former chief AI officer at the NSA, about the risks of this triage approach in the age of AI. Be careful what you wish for. That’s what Microsoft found out recently when it discovered that AI — rather than making Windows more secure by helping the company close security holes — could help hackers find flaws faster than Microsoft can fix them. It’s put Microsoft in a serious bind. Should the company devote a potentially massive amount of resources to fix every AI-unearthed security issue as fast as it can? Or should it rush to close the most important ones, and clean up the minor ones later at much less cost? What the company decides could have tremendous implications. For years, Microsoft has faced criticism from many in the US government because of how often its technologies have been hacked, potentially putting the nation’s security at risk. Some members of Congress have suggested the government curtail contracts with Microsoft until the company proves it can provide more safety. Billions of dollars in federal contracts could be pulled. To get a better insight into what could happen, let’s look at AI’s newfound prodigious ability to find security holes and bugs. Microsoft’s AI-related security problems are an outgrowth of the launch of Anthropic’s Mythos AI model https://www.anthropic.com/claude/mythos , designed to handle cybersecurity and biology research. One of its goals is to uncover security vulnerabilities as quickly as possible, so that software companies and cybersecurity companies can fix them before hackers find the holes. Anthropic’s early tests found that Mythos was spectacularly successful in finding Windows security flaws. “Within 31 minutes, Mythos generated its first proof-of-concept exploit for a Windows kernel vulnerability,” Axios reported in June https://www.axios.com/2026/06/08/exclusive-anthropics-mythos-can-exploit-new-flaws-in-hours . Anthropic noted that its testing of Mythos “reveals a stark fact: AI models have reached a level of coding capability where they can surpass all but the most skilled humans at finding and exploiting software vulnerabilities. “Mythos Preview has already found thousands of high-severity vulnerabilities, including some in every major operating system and web browser . Given the rate of AI progress, it will not be long before such capabilities proliferate, potentially beyond actors who are committed to deploying them safely. The fallout — for economies, public safety, and national security — could be severe.” As a result, Anthropic decided to launch a security project it calls Project Glasswing https://www.anthropic.com/glasswing , which it describes as “an urgent attempt to put these capabilities to work for defensive purposes.” Many companies beyond Anthropic are part of the effort, including Microsoft, Google, Amazon, Nvidia, Apple and others. In theory, it’s a great idea. Find and fix vulnerabilities before hackers can, and everyone is safer. What could go wrong? Plenty, as it turns out. Access to Mythos is available to anyone, and Mythos has been finding security holes and bugs far faster than companies — particularly Microsoft — can patch them. As Pro Publica https://www.propublica.org/article/anthropic-mythos-microsoft-software-vulnerabilities? reported in late July, ‘Microsoft is struggling to fix them fast enough.” For now, Microsoft is only patching the most dangerous bugs and holes. And, according to Pro Public, “internal records indicate that Microsoft plans to eventually address ‘moderate’-severity flaws uncovered by Mythos. The documents made no mention of ‘low’-severity bugs.” That’s fairly typical of the triage many companies use when deciding how much effort to put into plugging holes. But some experts believe that in the Age of AI, that’s a dangerous way to handle security. Vinh Nguyen, former chief AI officer and chief data scientist at the US National Security Agency and now a senior technical adviser to Anthropic and senior fellow for AI at the Council on Foreign Relations, is particularly concerned that the approach is outdated. He told Pro Publica: “The problem now is that you can chain four low-level flaws, and that can equal a high severity. If you’re Microsoft, the current triage strategy may be underpricing risks.” It’s already proving difficult for Microsoft to keep up with patching bugs and security holes since Mythos’ launch. July’s Patch Tuesday release fixed the most bugs in Microsoft’s history – 622 of them https://www.computerworld.com/article/4198400/julys-patch-tuesday-sees-an-end-of-support-collision-amidst-a-massive-record-setting-patch-wave.html . Things will only get harder from here. Microsoft is already in the doghouse for how it’s handled security. A year ago, in one of the worst attacks on Microsoft technologies, Sharepoint was hacked https://www.computerworld.com/article/4029811/again-microsoft-hit-for-poor-security-in-major-sharepoint-hack.html . Tens of thousands of servers were hit, including not just thousands of businesses, but many important government agencies as well. The National Institutes of Health NIH and the National Nuclear Security Administration NNSA , which is in charge of the nation’s nuclear security, were among the victims. So were the Department of Homeland Security DHS , the Cybersecurity and Infrastructure Security Agency, the Transportation Security Administration, Customs and Border Protection, and the Federal Emergency Management Agency, among many others. Even before then, some members in Congress were threatening to pull Microsoft contracts if it didn’t improve security. At one point Sens. Eric Schmitt R-MO and Ron Wyden D-OR sent a threatening letter to the Pentagon requesting it not increase its use of Microsoft products https://www.documentcloud.org/documents/24699162-schmitt-wyden-department-of-defense-cio-e5-52924 . “We write with serious concern that the Department of Defense DoD is doubling down on a failed strategy of increasing its dependence on Microsoft at a time when Congress and the administration are reviewing concerning cybersecurity lapses that led to a massive hack of senior US officials’ communications,” the letter said, in part. Nothing happened as a result of the hack or the letter. But that could change in a heartbeat if there’s another big attach. It seems inevitable that hackers will start taking advantage of how quickly Mythos discovers security holes and bugs, especially if Microsoft doesn’t fix them all. The next big hack, powered by AI, could prove very dangerous — not just for businesses and governments, but for Microsoft as well.