ProPublica revealed that Anthropic’s Mythos AI model has been identifying software vulnerabilities faster than Microsoft can patch them. In a mid-May meeting, engineering manager Hans Andersen told staff they were in “a mad dash” to close the gap, with roughly two weeks “to find as many things and do as much good as we can with this access.” May 31, he explained, “is considered the day when the rest of the world will have caught up.”
The scale of the problem
The numbers are staggering. In April alone, Mythos uncovered 90 “critical” bugs and 141 “important” ones in SharePoint, Microsoft’s widely used collaboration software. In the first half of May, it found even more.
Microsoft’s July Patch Tuesday release fixed 622 bugs, an all-time high, blowing past the previous record of over 200 set just in June. Only seven were categorized as low- or moderate-severity, according to Dustin Childs of the Zero Day Initiative.
“The bug apocalypse has fully descended upon us,” Childs wrote. One internal presentation predicted that the group working on SharePoint “will be busy for months,” first working through critical bugs, then tackling important ones in August, before beginning work on roughly 300 “moderate” bugs.
Chaining flaws and the AI arms race
To this point, the most concerning development is that Mythos can chain together multiple low-severity bugs to create a devastating attack. Vinh Nguyen, former chief AI officer at the National Security Agency (NSA) and now a senior technical adviser to Anthropic, warned:
“The problem now is that you can chain four low-level flaws, and that can equal a high severity. If you’re Microsoft, the current triage strategy may be underpricing risks.”
The May 31 deadline was significant because the Five Eyes intelligence alliance had warned that the window of opportunity to fix flaws before adversaries gain similar capabilities was closing. Microsoft tried to act like it wasn’t a big deal (downplaying the date’s significance), but the engineers knew better: “If it’s released on June 1, then on June 2 the adversaries will have our bugs.”
Beyond Microsoft: Mythos’s relentless bug hunt
Microsoft is not alone in facing Mythos’s bug-hunting capabilities. In less than two months, Anthropic reported that Mythos Preview uncovered over 10,000 high- and critical-severity vulnerabilities across roughly 50 organizations participating in Project Glasswing. Cloudflare alone found 2,000 bugs, with 400 classified as high- or critical-severity, a false positive rate better than human testers.
The model’s reach has extended into classified government systems as well. When U.S. intelligence agencies put it through its paces during a testing exercise back in June 2026, Mythos managed to spot security vulnerabilities in these highly sensitive government computer networks in just a matter of hours.
Senator Mark Warner disclosed that the tool “broke into almost all of our classified systems, not in weeks but in hours.” The NSA and Cyber Command confirmed the testing, though it was a controlled red-team exercise rather than an outside breach.
Nevertheless, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) is reportedly using Anthropic’s AI model Mythos to audit government software code, too.
What’s clear is that the bottleneck is no longer discovery. As Anthropic itself noted, progress on software vulnerability is now limited by the speed of verification, disclosure, and patching, not the ability to find bugs. The era of finding more vulnerabilities than can be fixed has arrived.