cd /news/artificial-intelligence/anthropics-mythos-finds-windows-bugs… · home topics artificial-intelligence article
[ARTICLE · art-92440] src=thecoinheadlines.com ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

Anthropic’s Mythos finds Windows bugs faster than Microsoft can patch them

Anthropic's Mythos AI model has identified software vulnerabilities in Microsoft's SharePoint faster than Microsoft can patch them, uncovering 90 critical and 141 important bugs in April alone, according to a ProPublica report. Microsoft's July Patch Tuesday fixed a record 622 bugs, and the company's engineering manager Hans Andersen described a 'mad dash' to close the gap before May 31, when adversaries were expected to catch up. The model has also found over 10,000 high- and critical-severity vulnerabilities across 50 organizations in Project Glasswing, including 2,000 bugs at Cloudflare, and broke into classified U.S. government systems in hours during a red-team exercise.

read3 min views1 publishedAug 11, 2026
Anthropic’s Mythos finds Windows bugs faster than Microsoft can patch them
Image: Thecoinheadlines (auto-discovered)

ProPublica revealed that Anthropic’s Mythos AI model has been identifying software vulnerabilities faster than Microsoft can patch them. In a mid-May meeting, engineering manager Hans Andersen told staff they were in “a mad dash” to close the gap, with roughly two weeks “to find as many things and do as much good as we can with this access.” May 31, he explained, “is considered the day when the rest of the world will have caught up.”

The scale of the problem

The numbers are staggering. In April alone, Mythos uncovered 90 “critical” bugs and 141 “important” ones in SharePoint, Microsoft’s widely used collaboration software. In the first half of May, it found even more.

Microsoft’s July Patch Tuesday release fixed 622 bugs, an all-time high, blowing past the previous record of over 200 set just in June. Only seven were categorized as low- or moderate-severity, according to Dustin Childs of the Zero Day Initiative.

“The bug apocalypse has fully descended upon us,” Childs wrote. One internal presentation predicted that the group working on SharePoint “will be busy for months,” first working through critical bugs, then tackling important ones in August, before beginning work on roughly 300 “moderate” bugs.

Chaining flaws and the AI arms race

To this point, the most concerning development is that Mythos can chain together multiple low-severity bugs to create a devastating attack. Vinh Nguyen, former chief AI officer at the National Security Agency (NSA) and now a senior technical adviser to Anthropic, warned:

“The problem now is that you can chain four low-level flaws, and that can equal a high severity. If you’re Microsoft, the current triage strategy may be underpricing risks.”

The May 31 deadline was significant because the Five Eyes intelligence alliance had warned that the window of opportunity to fix flaws before adversaries gain similar capabilities was closing. Microsoft tried to act like it wasn’t a big deal (downplaying the date’s significance), but the engineers knew better: “If it’s released on June 1, then on June 2 the adversaries will have our bugs.”

Beyond Microsoft: Mythos’s relentless bug hunt

Microsoft is not alone in facing Mythos’s bug-hunting capabilities. In less than two months, Anthropic reported that Mythos Preview uncovered over 10,000 high- and critical-severity vulnerabilities across roughly 50 organizations participating in Project Glasswing. Cloudflare alone found 2,000 bugs, with 400 classified as high- or critical-severity, a false positive rate better than human testers.

The model’s reach has extended into classified government systems as well. When U.S. intelligence agencies put it through its paces during a testing exercise back in June 2026, Mythos managed to spot security vulnerabilities in these highly sensitive government computer networks in just a matter of hours.

Senator Mark Warner disclosed that the tool “broke into almost all of our classified systems, not in weeks but in hours.” The NSA and Cyber Command confirmed the testing, though it was a controlled red-team exercise rather than an outside breach.

Nevertheless, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) is reportedly using Anthropic’s AI model Mythos to audit government software code, too.

What’s clear is that the bottleneck is no longer discovery. As Anthropic itself noted, progress on software vulnerability is now limited by the speed of verification, disclosure, and patching, not the ability to find bugs. The era of finding more vulnerabilities than can be fixed has arrived.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @anthropic 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/anthropics-mythos-fi…] indexed:0 read:3min 2026-08-11 ·