SharePoint alone accounted for 90 “critical” bugs and 141 “important” ones surfaced by a single AI model during the month of April. One product. One month.
The figure appeared on a slide presented to dozens of Microsoft engineers and managers who assembled online and in a Redmond conference room one afternoon in mid-May to discuss an effort known as Project Glasswing. ProPublica reviewed a recording of the session along with internal documents. Together they depict a company that received precisely what it had asked for and now cannot keep pace with it.
The model in question is Mythos, developed by Anthropic. Microsoft was operating a version called Claude Mythos Preview, and it was turning up flaws faster than the company’s teams could ship fixes.

The question everyone in the room wanted answered
One engineer put it bluntly at the top of the meeting. Had Mythos “live up to the hype that Anthropic claimed it would have had?”
“Yes,” a manager answered.
Engineers were now in “a mad dash” to close the gap, the manager said. Over the first half of May, Mythos turned up an even larger haul of SharePoint bugs than it had in April.
Anthropic had granted access to a hand-picked set of organizations whose software is relied on by ordinary people, businesses and governments around the world. The idea was to buy a head start: locate and seal the holes before hackers and adversarial governments such as China obtain tools capable of finding the very same ones.
The deadline was May 31 and nobody argued with it
“Please, please, please if your org has any April bugs, drive those down,” engineering manager Hans Andersen urged the group. About two weeks remained “to find as many things and do as much good as we can with this access.”
May 31, he told them, “is considered the day when the rest of the world will have caught up.”
The engineers probed that claim. One of them spelled out the implication without dressing it up: “So basically you’re saying if it’s released on June 1, then on June 2 the adversaries will have our bugs?”
Yep, came one reply. Yep, came another.
Five Eyes said months. The meeting suggests otherwise
After Project Glasswing was disclosed publicly in April, national security specialists assumed the US still had time to patch flaws before adversaries obtained equivalent models. In late June the Five Eyes intelligence alliance — the US, Australia, Canada, New Zealand and the UK — took the unusual step of issuing a joint statement cautioning that the window would shut within months.
The Microsoft recording and the internal documents suggest something less reassuring. The day of cyber reckoning may already have arrived.
Triage works fine until bugs start stacking
Confronted with the deluge, Microsoft has concentrated on the tiers it considers most dangerous — critical and important — according to the presentation and the company’s public patch updates. Internal records indicate Microsoft intends to get to the “moderate” flaws Mythos identified eventually. “Low” ones go unmentioned entirely in the documents.
That is ordinary industry practice: treat the sickest patient first. It is also the piece that unsettles those who grasp what Mythos is capable of, since the model links bugs together, stacking one atop another until a heap of overlooked minor issues turns into a genuine attack.
“The problem now is that you can chain four low-level flaws, and that can equal a high severity,” said Vinh Nguyen, a senior technical adviser to Anthropic and a senior fellow for AI at the Council on Foreign Relations, who previously served as chief AI officer and chief data scientist at the National Security Agency. “If you’re Microsoft, the current triage strategy may be underpricing risks.”
In emailed replies to ProPublica, Microsoft defended its method, saying triage calls take multiple factors into account, among them exploitability and customer impact. Chaining went unmentioned in the presentation, but a spokesperson said the technique “has long been considered as part of vulnerability assessment and risk analysis.”
On the May 31 deadline, the spokesperson played it down, noting that “accelerated targeting and exploitation of new vulnerabilities is not a new phenomenon.” The remarks made on the call, he added, reflect how the company “feels a sense of urgency to help our customers at this time.”
“What was heard on that call and is true today is that security is Microsoft’s most important priority and teams across the company are prioritizing using AI to discover and remediate vulnerabilities as quickly as possible.”
Microsoft would not say how many bugs its engineers have patched in the time since the presentation.
Months of work, and that’s one product team
The SharePoint group “will be busy for months,” the presentation and slides forecast. Critical bugs come first, important ones in August, and after that roughly 300 “moderate” bugs. SharePoint is the product governments and businesses lean on to handle data and documents.
By Microsoft’s definition, critical takes in things such as worms that crash systems and spread malware across networks. Important can refer to “compromise of the confidentiality, integrity, or availability of user data” as well as the “availability of processing resources.”
Microsoft’s entire product line isn’t covered in the documents, though one noted that since the company began using Mythos earlier this year, hundreds of critical or important bugs have surfaced across Microsoft 365, Teams and the Copilot AI tool. Most remained unpatched as of mid-May.
“They’re not profound and exotic, but they’re real,” Andersen said during the meeting. “And a lot of them are exploitable.”
It remains unclear whether hackers have exploited any particular bug Mythos uncovered. Some have turned to AI to automate attacks and appear to be running Mythos-like technology to hunt for and exploit weaknesses.
Patch Tuesday broke its own record by 400
The pressure is visible in public. Microsoft’s monthly patch release in June addressed more than 200 bugs, a figure industry experts called an all-time high at the time. Then on July 14 the company shipped fixes for more than 600.
Just seven of those fell into the low or moderate severity bands, and hackers were actively exploiting one of them, according to Dustin Childs, who leads the Zero Day Initiative bug bounty program at cybersecurity company TrendAI. The remainder were rated important or critical.
“Well folks. Here we are. The bug apocalypse has fully descended upon us,” Childs wrote in a July 14 blog post.
Microsoft told ProPublica the volume “will not be plateauing for a bit,” adding that it has “invested heavily in both people as well as AI-powered triage solutions that scale quickly to handle the growing number of vulnerabilities.”
The fix is more people, which is the part nobody wants to hear
Nguyen’s case is that chaining upends the old arithmetic. Rather than shunting low-risk flaws to the side, companies ought to add staff to build and test patches across the full severity spectrum. What the cyber ER needs is more doctors and nurses attending to the minor wounds that later turn fatal, not solely the life-threatening ones.
“There’s no alternative,” Nguyen said. “The patients are coming in fast and furious.”
Microsoft said it is “always going to be reevaluating and considering whether things that were previously lows or moderates be upgraded or thought about differently. With these AI systems, it makes us rethink some of these things. Across the industry, we’re all looking to see how drastic of a change it will be.”
Decades-old code, global install base
Users of Microsoft software occupy an uncomfortable position. The company’s sheer ubiquity makes it a frequent and profitable target, and many of its products still run “legacy” code authored decades ago on outdated technology, carrying unresolved flaws that accumulate into what the industry terms “technical debt.”
The same affliction runs through the rest of the software industry, and through open-source code as well, which is generally free to use and maintained largely by volunteers. That code props up Internet infrastructure and is embedded in much of modern technology, Microsoft’s own products included.
“Nobody has really figured out how to deal with this, and everybody is casting around for what they need to do,” said J. Michael Daniel, a former cybersecurity adviser to President Barack Obama and president of the Cyber Threat Alliance, a cybersecurity nonprofit. “Our tech debt is coming due.”
Ben Edwards, a data scientist whose specialty is managing software vulnerabilities, said the industry was already coping with an “intense volume even before AI.”
“It was like drinking from a garden hose on the jet setting before, and now it’s like drinking from a fire hose,” Edwards said. “They might have had the teams that could handle that garden hose. Whether they can handle the fire hose is something else.”
The team catching all of this was understaffed before Mythos
As ProPublica has previously reported, the Microsoft Security Response Center has been chronically undermanned. Even before AI-identified bugs began pouring in, the center was handling hundreds or thousands of reports a month, stretching it to its limits.
Former employees traced the cause to corporate arithmetic: sealing security holes is a cost center, while building new products is a profit center. The company would rather not have its strongest engineers occupied writing patches instead of shipping revenue-generating features.
Microsoft said it does not comment on internal staffing but has invested in recent years to “focus our teams on keeping our customers secure.” The company “continuously evaluates the staffing, processes, and technologies required to support security response and vulnerability management,” a spokesperson said.
The May slides attached a number to the effort: Anthropic extended Mythos access to roughly 50 full-time Microsoft employees, with the aim of “harden critical services before publicly available models catch up.” A slide headed “What’s Next” projected that the Security Response Center would continue to see case volume “as public tools catch up” to Mythos.
One staffer’s reassurance lasted about five seconds
At the May meeting, one attendee floated a consoling idea: adversaries “don’t have the source code” that an AI tool of this kind would scan. Colleagues shot it down on the spot. Chunks of Microsoft’s code have leaked to hackers over the years.
“It might not be this week’s source code,” one person said. “But they’ve got source code. It’s out there.”
Microsoft’s answer to that exchange was that its engineers “design our security processes on the expectation that determined adversaries may gain access to code.”
Which amounts to conceding that the head start was never really the point. For anyone running SharePoint, Microsoft 365 or Teams, the practical lesson is to quit treating the moderate and low end of your patch backlog as optional, because the tools doing the finding aren’t sorting by severity. They’re sorting by what connects to what.

















STAY ALWAYS UP TO DATE