
Anthropic's AI Model Can Find Software Bugs Faster Than Microsoft Can Fix Them, ProPublica Investigation Finds
An AI model built to make software safer just exposed an uncomfortable truth about how prepared even the world's largest software companies actually are. Anthropic's Mythos model has been identifying security vulnerabilities in Microsoft's software faster than Microsoft's own teams can patch them, according to internal documents reviewed by ProPublica, prompting what the outlet described as a "mad dash" behind the scenes to close holes before hackers find and exploit them first.
Mythos is part of Anthropic's Project Glasswing initiative, which gave roughly 50 full-time Microsoft employees access to the model with a specific goal, according to slides from a May internal presentation cited by ProPublica's reporting: to "harden critical services before publicly available models catch up." A slide titled "What's Next" predicted the Microsoft Security Response Center would keep seeing rising case volume specifically as public AI tools eventually match Mythos's current capability.
Why Chained Low-Severity Bugs Are the Real Danger
The most technically important detail in this investigation isn't the raw number of bugs found, it's how Mythos finds them. Vinh Nguyen, a senior technical adviser to Anthropic and a senior fellow for AI at the Council on Foreign Relations who formerly served as chief AI officer and chief data scientist at the National Security Agency, explained the core risk directly to ProPublica: "The problem now is that you can chain four low-level flaws, and that can equal a high severity. If you're Microsoft, the current triage strategy may be underpricing risks." That's a meaningful warning, since traditional vulnerability triage typically ranks and prioritizes bugs individually rather than accounting for how multiple minor flaws can be combined into a single severe exploit.
This capability isn't new information in isolation. Anthropic previously disclosed that Mythos identified more than 2,000 unknown software vulnerabilities in just seven weeks of testing, and that scanning more than 1,000 open-source projects turned up 23,019 issues, including 6,202 rated high or critical severity, according to Help Net Security's earlier reporting on the program. What's new in the ProPublica investigation is direct evidence that Microsoft's actual patching capacity is struggling to keep pace with what Mythos is finding in real time.
Microsoft's Response, and What It Reveals
Microsoft told ProPublica it does not discuss internal staffing decisions but has made investments in recent years to "focus our teams on keeping our customers secure," and that the company "continuously evaluates the staffing, processes, and technologies required to support security response and vulnerability management." That's a carefully worded response that notably doesn't directly dispute the core finding: that bug discovery is currently outpacing bug fixing at one of the world's largest software vendors, a tension worth understanding alongside our earlier coverage of OpenAI's own AI agent breaching Hugging Face's infrastructure during what was meant to be a controlled security test.
Why This Matters for Business
In my four years in sales at a research and advisory firm, I heard directly from CMOs and CEOs about what they wanted from AI, and cybersecurity consistently ranked as one of their top-line concerns, well before AI-powered vulnerability discovery tools like Mythos existed. This investigation is a genuinely important signal for any business running Microsoft software, which is to say nearly every business. The gap between AI-accelerated vulnerability discovery and traditional human-paced patching capacity is a structural security risk that's only going to widen as more labs deploy similar bug-finding capabilities.
For IT and security leaders, this is worth treating as a prompt to review your organization's own patch management cadence and prioritization framework now, rather than waiting for a chained-exploit incident to force the issue.
The Fast Version
Internal documents reviewed by ProPublica show Anthropic's Mythos AI model is finding software vulnerabilities in Microsoft products faster than Microsoft's own security teams can patch them. Experts warn the model's ability to chain together multiple low-severity flaws into high-severity exploits means current triage strategies may be underpricing actual risk. Microsoft did not directly dispute the finding, saying only that it continuously evaluates its security staffing and processes.




