Anthropic's Mythos found 90 critical Microsoft bugs in a month, triggering a 'mad dash' fix
Curated by the Inblix editorial team
The internal panic was palpable. Microsoft engineers huddled in mid-May, confronting a stark new reality: Anthropic’s Claude Mythos Preview was unearthing security flaws in their code faster than they could possibly fix them. A recording of the meeting, obtained by ProPublica, reveals the tension. One engineer asked point-blank if the model lived up to the hype. “Yes,” a manager replied flatly.
The numbers were unsettling. In April alone, Mythos surfaced 90 “critical” bugs and 141 “important” ones in SharePoint, Microsoft’s ubiquitous collaboration platform. The pace only accelerated in the first half of May. Engineering manager Hans Andersen didn’t sugarcoat the urgency, pleading with teams to “drive those down” before a hard deadline.
That deadline was May 31. Andersen framed it as the moment the advantage evaporated. The engineers weren’t just racing against their own patch schedule—they were racing against every hacker and adversarial government that would soon get their hands on similar capabilities. One engineer cut to the chase, distilling the predicament into a chilling hypothetical: if the tool goes public June 1, do the adversaries have their bugs on June 2?
The exchange exposes a brutal asymmetry in AI-powered security. Defenders get a brief head start. Attackers get everything else. The meeting wasn’t about whether Mythos was impressive—it was about whether Microsoft could shrink its own attack surface before the window slammed shut. The tension in that room is a preview of what every major software vendor will soon face: a fixed period of grace, followed by a free-for-all.
💡 Key Takeaways
- Anthropic's Mythos model forced Microsoft into a frantic race to patch 90 critical SharePoint bugs before adversaries could exploit them.
- Microsoft engineers were explicitly told May 31 was the cutoff—after that, they assumed hostile actors would have equivalent tools.
- The meeting recording reveals a fundamental shift in cybersecurity timelines, where defenders get only weeks of advantage from an AI model preview.
- A Microsoft engineer directly questioned whether bugs found by Mythos would be in adversarial hands within a day of its wider release.
Keep reading: See related articles below for more coverage on this topic.
Get smarter about AI
The sharpest AI news, curated daily. Delivered free to your inbox.