Mid‑May saw dozens of Microsoft engineers and their managers huddle in Redmond’s headquarters and online to address a growing security threat. The meeting, part of an internal effort dubbed Project Glasswing, focused on vulnerabilities that Anthropic’s new AI model, Mythos, was surfacing at an unprecedented rate.
Anthropic, the creator of Mythos, has granted limited access to the model for select partners, including Microsoft. The intent: let the AI comb through widely used software, flagging weaknesses before hostile actors can weaponize them. In practice, the model’s speed has outstripped the company’s capacity to respond.
“The version we’re using—Claude Mythos Preview— is surfacing bugs faster than we can patch them,” an engineering manager told colleagues, according to a recording obtained by ProPublica. The sentiment in the room was urgent, bordering on frantic. Engineers described their work as a “mad dash” to close the gap between discovery and remediation.
April’s results alone were striking: Mythos identified 90 bugs classified as critical and 141 as important within SharePoint, Microsoft’s flagship collaboration platform. The first half of May produced even more findings, though exact numbers were not disclosed. Hans Andersen, another manager on the call, urged teams to “drive those down” and emphasized a two‑week horizon to address as many issues as possible.
May 31 was marked as the deadline after which “the rest of the world will have caught up.” The implication was clear—once Microsoft releases updates on June 1, adversaries could reverse‑engineer the same vulnerabilities the day after. One engineer summed up the risk: “So basically you’re saying if it’s released on June 1, then on June 2 the adversaries will have our bugs?”
The stakes are high. SharePoint underpins communication for countless businesses, governments, and individuals. A breach could expose sensitive data or enable sabotage on a massive scale. Anthropic’s Mythos, while designed to improve security, inadvertently accelerates the timeline for both defenders and attackers.
Microsoft’s response includes allocating additional resources to the Glasswing effort and tightening internal processes for rapid patch deployment. The company has not disclosed whether it plans to delay the broader rollout of the affected SharePoint components.
Industry observers note that the episode underscores a paradox of AI‑driven security: powerful tools can both fortify defenses and amplify the speed at which threats emerge. As AI models become more capable of dissecting complex codebases, organizations may need to rethink how they balance discovery with remediation.
For now, Microsoft races against the clock, hoping to stay ahead of the very technology meant to protect it.
This article was written with the assistance of AI.
News Factory APP - agentic news to boost your SEO & AEO.