Skip to content

Anthropic’s Mythos finds Windows bugs faster than Microsoft can patch them

AI finds so many Windows bugs, Microsoft is struggling to fix them all
Share this article

ProPublica revealed that Anthropic’s Mythos AI model has been identifying software vulnerabilities faster than Microsoft can patch them. In a mid-May meeting, engineering manager Hans Andersen told staff they were in “a mad dash” to close the gap, with roughly two weeks “to find as many things and do as much good as we can with this access.” May 31, he explained, “is considered the day when the rest of the world will have caught up.”

The scale of the problem

The numbers are staggering. In April alone, Mythos uncovered 90 critical bugs and 141 important ones in SharePoint, Microsoft’s widely used collaboration software. In the first half of May, it found even more. 

Microsoft’s July Patch Tuesday release fixed 622 bugs, an all-time high, blowing past the previous record of over 200 set just in June. Only seven were categorized as low- or moderate-severity, according to Dustin Childs of the Zero Day Initiative. 

“The bug apocalypse has fully descended upon us,” Childs wrote. One internal presentation predicted that the group working on SharePoint “will be busy for months,” first working through critical bugs, then tackling important ones in August, before beginning work on roughly 300 moderate bugs.

Anthropic's Mythos AI model has been uncovering software vulnerabilities at an unprecedented rate, leaving Microsoft in a "mad dash" to patch holes before hackers can exploit them. Documents reviewed by ProPublica reveal that in April alone, Mythos identified 90 "critical" and 141 "important" bugs in SharePoint alone, with the pace accelerating in May.
Security Update Severity Rating System. (Source: Microsoft)

Chaining flaws and the AI arms race

To this point, the most concerning development is that Mythos can chain together multiple low-severity bugs to create a devastating attack. Vinh Nguyen, former chief AI officer at the National Security Agency (NSA) and now a senior technical adviser to Anthropic, warned: 

“The problem now is that you can chain four low-level flaws, and that can equal a high severity. If you’re Microsoft, the current triage strategy may be underpricing risks.” 

The May 31 deadline was significant because the Five Eyes intelligence alliance had warned that the window of opportunity to fix flaws before adversaries gain similar capabilities was closing. Microsoft tried to act like it wasn’t a big deal (downplaying the date’s significance), but the engineers knew better: “If it’s released on June 1, then on June 2 the adversaries will have our bugs.”

Beyond Microsoft: Mythos’s relentless bug hunt

Microsoft is not alone in facing Mythos’s bug-hunting capabilities. In less than two months, Anthropic reported that Mythos Preview uncovered over 10,000 high- and critical-severity vulnerabilities across roughly 50 organizations participating in Project Glasswing. Cloudflare alone found 2,000 bugs, with 400 classified as high- or critical-severity, a false positive rate better than human testers.

The model’s reach has extended into classified government systems as well. When U.S. intelligence agencies put it through its paces during a testing exercise back in June 2026, Mythos managed to spot security vulnerabilities in these highly sensitive government computer networks in just a matter of hours. 

Senator Mark Warner disclosed that the tool “broke into almost all of our classified systems, not in weeks but in hours.” The NSA and Cyber Command confirmed the testing, though it was a controlled red-team exercise rather than an outside breach.

Nevertheless, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) is reportedly using Anthropic’s AI model Mythos to audit government software code, too.

What’s clear is that the bottleneck is no longer discovery. As Anthropic itself noted, progress on software vulnerability is now limited by the speed of verification, disclosure, and patching, not the ability to find bugs. The era of finding more vulnerabilities than can be fixed has arrived.

About The Coin Headlines

The Coin Headlines strives to bring trust into crypto media. At a time when every soundbite and headline can move the markets from red to green and vice-versa, The Coin Headlines promises to bring verified, credible and timely news and analysis from the world of crypto, blockchain, Web3, tech and markets. Founded in 2026, The Coin Headlines is based in the UAE with a team of experienced journalists and editors covering breaking news and updates from around the world.

From covering the biggest events to interviewing some of the most popular KOLs in the industry, The Coin Headlines keeps you informed of the latest trends and insights.

At The Coin Headlines our focus is clear: Real-time news updates, market movements, whale transfers, macroeconomic trends, tech and AI and geopolitical breaking news. The news we report goes through a strict editorial audit before its published to ensure the readers only get verified and credible information. We realize the world of crypto is dynamic, volatile, and many times, confusing. At The Coin Headlines we break down these complex issues into simple articles which cater to not just the experienced trader but also the student and first-time investor who wants to understand the space before committing to it.