Thursday, July 30, 2026

News

ProPublica Investigation: Microsoft Can't Keep Up With Bugs Found by Anthropic's AI

PolicyPatryk Raba
ProPublica Investigation: Microsoft Can't Keep Up With Bugs Found by Anthropic's AI
Fot. Jiaqian AirplaneFan, Wikimedia Commons (CC BY 3.0)

Anthropic's Claude Mythos model is finding thousands of serious security vulnerabilities in Microsoft's code faster than the company can patch them, according to a ProPublica investigation based on internal recordings. In July, Microsoft shipped over 600 patches in a single month, what engineers are calling a "bug apocalypse."

Contents
  1. The Redmond Recording
  2. Record Patching Pace
  3. The Risk of Triage
  4. Microsoft's Response

The Claude Mythos artificial intelligence model, built by Anthropic to hunt for security vulnerabilities in software, is finding bugs in Microsoft's products faster than the company's engineers can fix them. A ProPublica investigation, based on a recording from an internal meeting at Microsoft's Redmond headquarters, reveals the scale of the problem and the mounting time pressure facing one of the world's largest software makers.

Anthropic made Claude Mythos public in April 2026 and gave access to select companies and institutions building software used by billions of people, businesses, and governments. The stated goal was defensive: find and patch vulnerabilities before hackers or hostile governments do. Among the first partners was Microsoft, which received access to a preview build of the model, Claude Mythos Preview.

The Redmond Recording

ProPublica obtained a recording from mid-May 2026, taped during an internal meeting of Microsoft's security team focused on Project Glasswing. On it, a manager confirms that Mythos "live[s] up to the hype," and that the team found itself in what he called "a mad dash" to close the gap between finding a bug and patching it.

Hans Andersen, the engineer managing the project, told the team they had "roughly two weeks to find as much good stuff as possible," because May 31 was expected to be the day "the rest of the world" would catch up to the capabilities of Anthropic's tool. The implication was clear to the engineers: once similar tools reach wider use, the same vulnerabilities become available to criminals and hostile intelligence services.

It was like drinking from a garden hose on the jet setting before, and now it's like drinking from a fire hose - Ben Edwards, cybersecurity expert

Record Patching Pace

The pressure translated into an unprecedented pace of patch releases. In June 2026, Microsoft shipped more than 200 security patches, a company record at the time. That record fell just a month later: on July 14, Microsoft released more than 600 patches at once, only seven of which were classified as low or moderate risk. The rest addressed critical or important vulnerabilities.

Here we are. The bug apocalypse has fully descended upon us - Dustin Childs, cybersecurity expert

The Risk of Triage

Microsoft has adopted a triage strategy, prioritizing critical and important bugs while setting aside low and moderate priority ones. Experts warn that in the AI era this approach can be dangerous, since models like Mythos are capable of chaining several seemingly minor flaws into one serious attack path. Vinh Nguyen, former head of AI at the US National Security Agency (NSA), warned that four low severity bugs combined can add up to the equivalent of one high risk vulnerability, meaning Microsoft's current strategy may be understating the real risk.

According to ProPublica's findings, a further problem is years of underfunding at the Microsoft Security Response Center, the team responsible for handling vulnerability reports. The company reportedly treated security patching as a cost center rather than a revenue driver, steering its best engineers toward revenue generating product work rather than security.

Microsoft's Response

Microsoft responded that security remains its "top priority," and that its teams are "prioritizing the use of AI to find and remediate vulnerabilities as quickly as possible." The company said patching order takes into account whether a given vulnerability could realistically be exploited and its impact on customers, not just its formal severity classification.

The story matters beyond a single vendor. Similar tools from Anthropic have also reached other organizations working on digital infrastructure security, including the US NSA, which tested Mythos for finding weaknesses in widely used software. If the pace at which AI uncovers vulnerabilities genuinely outstrips humans' ability to patch them, the entire industry faces the question of how to reorganize its threat response process before these same tools fall into the wrong hands.

For Polish companies and institutions that rely on Microsoft products, the vast majority of the country's public and private sector, this means an even greater need to roll out security updates quickly and to monitor Microsoft Security Response Center advisories, as the scale and pace of released patches keeps growing month over month.

Share: