In a critical mid-May afternoon, dozens of Microsoft engineers and their managers convened virtually and in person at the tech giant’s Redmond, Washington, headquarters, the urgent agenda: Project Glasswing. The company found itself in a frenetic race against time, grappling with an unprecedented onslaught of software weaknesses unearthed by Mythos, an advanced artificial intelligence model developed by AI behemoth Anthropic. This exclusive access, granted to select software providers serving individuals, corporations, and governments globally, aimed to fortify digital defenses. The overarching goal was stark: identify and remediate vulnerabilities before sophisticated adversaries, particularly state-sponsored actors like China, could leverage similar AI tools for espionage and sabotage.
The gravity of the situation was palpable as the team settled into their discussion. An engineer voiced the central question that loomed over the gathering: "Did Mythos live up to the hype that Anthropic claimed it would have had?" The response from a manager, captured in a recording of the meeting reviewed by ProPublica, was unequivocal: "Yes." The specific iteration in use, "Claude Mythos Preview," was exposing bugs at a rate far exceeding Microsoft’s patching capabilities, pushing engineers into what the manager described as "a mad dash" to close the ever-widening security gap.
The Unprecedented Scale of AI-Discovered Flaws
The internal presentation slides from that day painted a stark picture of the challenge. In April alone, Mythos had identified 90 "critical" bugs and 141 "important" ones within SharePoint, Microsoft’s ubiquitous collaboration software used by millions worldwide for document management and team communication. The first half of May saw an even greater discovery rate, further intensifying the pressure on the engineering teams. Hans Andersen, an engineering manager, implored the group, "Please, please, please if your org has any April bugs, drive those down." The deadline was tight: approximately two weeks remained "to find as many things and do as much good as we can with this access."
The looming date was May 31, explained Andersen, considered "the day when the rest of the world will have caught up." This assertion provoked a pointed question from an engineer on the call, encapsulating the predicament: "So basically you’re saying if it’s released on June 1, then on June 2 the adversaries will have our bugs?" The grim reality was confirmed by multiple respondents: "Yep," echoed across the virtual conference. This exchange underscored a fundamental shift in the cybersecurity landscape – the perceived window of opportunity for defenders to patch flaws before adversaries acquired similar AI capabilities was rapidly, perhaps already, closing.
The Narrowing Window and the Five Eyes Warning
Anthropic had publicly announced Project Glasswing in April, initiating a national conversation about the transformative power of AI in bug hunting. National security experts had initially posited a crucial, albeit brief, window for the U.S. and its allies to address newly discovered flaws before hostile nations could replicate the AI’s capabilities. This sentiment was echoed in late June when the Five Eyes intelligence alliance – comprising the United States, Australia, Canada, New Zealand, and the United Kingdom – issued an unusual joint statement. Their warning was stark: this critical window would likely close within months. However, the Microsoft meeting recording and internal documents reviewed by ProPublica suggest that this "day of cyber reckoning" may have arrived sooner than anticipated, marking a new, accelerated era of digital vulnerability.
The deluge of flaws unearthed by Mythos forced Microsoft into a triage system, prioritizing the most dangerous vulnerabilities. Their immediate focus, as indicated by internal presentations and public patch updates, was on "critical" and "important" bugs. "Moderate"-severity flaws were slated for eventual attention, but "low"-severity bugs received no mention in the immediate plans. This approach, standard practice in the cybersecurity industry, mirrors emergency room protocols: the most life-threatening issues are addressed first to prevent immediate catastrophic damage.
The Peril of Unpatched "Low-Severity" Flaws in the AI Era
However, this traditional triage strategy carries significant, evolving risks in the age of AI-powered bug discovery. Mythos, and similar future AI tools, possess the capability to "chain together" multiple seemingly innocuous bugs. This means that a series of low- and moderate-severity vulnerabilities, left unpatched, could be combined to create complex attack vectors capable of devastating consequences.
Vinh Nguyen, a senior technical adviser to Anthropic, senior fellow for AI at the Council on Foreign Relations, and former chief AI officer and chief data scientist at the National Security Agency, articulated this paradigm shift. "The problem now is that you can chain four low-level flaws, and that can equal a high severity," Nguyen stated. He cautioned, "If you’re Microsoft, the current triage strategy may be underpricing risks." The traditional model, designed for a slower, human-driven discovery process, struggles to adapt to AI’s ability to rapidly identify and synthesize vulnerabilities.
Microsoft’s Stance and the Evolving Threat Landscape
In response to ProPublica’s inquiries, Microsoft defended its triage approach, asserting that decisions are based on a multifaceted analysis, including exploitability and potential customer impact. While the internal presentation did not explicitly detail "chaining," a company spokesperson confirmed that the technique "has long been considered as part of vulnerability assessment and risk analysis." Regarding the May 31 deadline and the internal presentation, Microsoft downplayed its singular significance, stating that "accelerated targeting and exploitation of new vulnerabilities is not a new phenomenon." Nonetheless, the spokesperson acknowledged that the internal discussions reflected the company’s "sense of urgency to help our customers at this time." They reiterated, "What was heard on that call and is true today is that security is Microsoft’s most important priority and teams across the company are prioritizing using AI to discover and remediate vulnerabilities as quickly as possible." Microsoft declined to provide specific figures on the number of bugs patched since the May presentation, and Anthropic similarly declined to comment.
A Torrent of Bugs: SharePoint, Microsoft 365, Teams, and Copilot Under Siege
The internal Microsoft presentation and accompanying slides offered a glimpse into the immense workload facing specific product teams. The SharePoint team, whose software is foundational for countless governments and businesses globally, was projected to be "busy for months." Their initial focus would be on addressing critical bugs, followed by important ones in August, and finally, an estimated 300 "moderate" bugs. Microsoft’s categorization defines "critical" vulnerabilities as those that could lead to system crashes, the spread of malware (worms), or remote code execution, while "important" bugs risk "compromise of the confidentiality, integrity, or availability of user data" and "availability of processing resources."
While the reviewed internal documents did not encompass the entire breadth of Microsoft’s vast product portfolio, they clearly indicated the sheer scale of the problem. Since the company began leveraging Mythos earlier this year, the AI had collectively identified hundreds of critical and important bugs across popular offerings such as Microsoft 365, the Teams conferencing platform, and the Copilot AI tool. As of mid-May, the vast majority of these remained unpatched. Engineering manager Hans Andersen summarized the nature of these discoveries: "They’re not profound and exotic, but they’re real. And a lot of them are exploitable."
The "Bug Apocalypse" and Record-Breaking Patch Tuesdays
While definitive proof of hackers exploiting specific Mythos-identified bugs remains elusive, there is growing evidence of adversaries increasingly incorporating AI into their attack methodologies. Reports indicate hackers are already using AI to automate attacks and employ Mythos-like technologies to identify and exploit weaknesses, blurring the lines between defensive and offensive AI capabilities.
Outwardly, Microsoft’s struggle to manage the expanding list of vulnerabilities has become visible. The company’s monthly "Patch Tuesday" releases, where fixes for software vulnerabilities are publicly distributed, have swelled dramatically. In June, Microsoft released patches for over 200 bugs, a figure industry experts noted as an "all-time high" at the time. However, this record was shattered on July 14, when the company released fixes for more than 600 bugs. Notably, only seven of these were categorized as low- or moderate-severity, with one low-severity flaw already being actively exploited by hackers, according to Dustin Childs, leader of the Zero Day Initiative bug bounty program at cybersecurity company TrendAI. The overwhelming majority were important or critical. Childs starkly declared in a July 14 blog post: "Well folks. Here we are. The bug apocalypse has fully descended upon us."
Microsoft acknowledged to ProPublica that the overall volume of bugs "will not be plateauing for a bit." However, a spokesperson emphasized the company’s "invested heavily in both people as well as AI-powered triage solutions that scale quickly to handle the growing number of vulnerabilities."
Rethinking Triage: A New Paradigm for Cybersecurity
Nguyen, the former NSA AI chief, argues that the new realities of the AI age, particularly the chaining capabilities, necessitate a fundamental re-evaluation of current triage strategies. Instead of sidelining what were previously considered low-risk flaws, companies must dedicate resources to developing and testing patches for the entire spectrum of vulnerabilities. He likened the situation to an emergency room needing more doctors and nurses to treat not just life-threatening illnesses but also minor wounds that could quickly escalate. "There’s no alternative," Nguyen asserted. "The patients are coming in fast and furious."
Microsoft indicated an openness to this evolving perspective, telling ProPublica that it is "always going to be reevaluating and considering whether things that were previously lows or moderates be upgraded or thought about differently. With these AI systems, it makes us rethink some of these things. Across the industry, we’re all looking to see how drastic of a change it will be."
Microsoft’s Technical Debt and the Industry-Wide Challenge
Microsoft’s users are particularly exposed due to the widespread adoption of its products, making them a lucrative target for cybercriminals and nation-state actors. Furthermore, many of its foundational products contain "legacy code," developed decades ago with now-outdated technologies. This legacy code often harbors unaddressed flaws and contributes significantly to what the industry terms "technical debt" – the implied cost of additional rework caused by choosing an easier, limited solution now instead of using a better approach that would take longer. This technical debt, accumulated over decades, is now coming due with the advent of AI-driven vulnerability discovery.
The challenge, however, extends far beyond Microsoft to the entire software industry, including the vast ecosystem of open-source software. Open-source code forms the backbone of much of the internet’s infrastructure and is integrated into nearly all modern technology, including offerings from major tech companies. J. Michael Daniel, former cybersecurity adviser to President Barack Obama and president of the Cyber Threat Alliance, a cybersecurity nonprofit, summarized the widespread dilemma: "Nobody has really figured out how to deal with this, and everybody is casting around for what they need to do. Our tech debt is coming due."
Ben Edwards, a data scientist specializing in software vulnerability management, vividly described the situation: "It was like drinking from a garden hose on the jet setting before, and now it’s like drinking from a fire hose." He questioned whether existing teams, accustomed to managing a "garden hose" volume, could withstand the "fire hose" of AI-discovered bugs.
Understaffing and Corporate Philosophy
Even before the current flood of AI-identified bugs, Microsoft’s internal group responsible for fielding vulnerabilities, the Microsoft Security Response Center (MSRC), has been perennially understaffed. ProPublica has previously reported that the MSRC handled hundreds, sometimes thousands, of reports monthly, consistently pushing its resources to the limit. This understaffing, according to former employees, reflects a corporate philosophy where plugging security holes is viewed as a "cost center," while developing new products and features is a "profit center." The company has historically been reluctant to reallocate its top engineering talent to security patching when they could be generating new revenue streams.
Microsoft declined to discuss internal staffing specifics but stated it has made significant investments in recent years to "focus our teams on keeping our customers secure." A spokesperson added that the company "continuously evaluates the staffing, processes, and technologies required to support security response and vulnerability management."
According to the slides accompanying the May internal presentation, Anthropic provided Mythos access to approximately 50 full-time Microsoft employees, with the explicit objective to "harden critical services before publicly available models catch up." A slide titled "What’s Next" ominously predicted that the MSRC would experience "continued case volume as public tools catch up" to Mythos’s capabilities.
During the May meeting, a staffer initially found comfort in the belief that adversaries "don’t have the source code" that such an AI tool would scan for weaknesses. This notion was quickly corrected by colleagues. Portions of Microsoft’s source code have, in fact, been compromised and fallen into hackers’ hands over the years. "It might not be this week’s source code," one person noted, "But they’ve got source code. It’s out there." In a statement to ProPublica, Microsoft downplayed the specific comment, emphasizing that engineers "design our security processes on the expectation that determined adversaries may gain access to code." This underscores a grim reality: in the AI-accelerated cyber arms race, even proprietary code offers no absolute sanctuary. The digital frontier is rapidly shifting, demanding an urgent, holistic re-evaluation of security strategies across the entire global software ecosystem.







