In April alone, one AI model found 90 “critical” bugs and 141 “important” ones in SharePoint. Just SharePoint. One product, one month.
That number comes from a slide shown to dozens of Microsoft engineers and managers who gathered online and in a Redmond conference room on an afternoon in mid-May to talk about something called Project Glasswing. A recording of that meeting was viewed by ProPublica, along with internal documents. What they show is a company that got exactly what it asked for and can’t keep up with it.
The model is Mythos, built by Anthropic. Microsoft was running a version called Claude Mythos Preview, and it was surfacing bugs faster than the company could patch them.

The question everyone in the room wanted answered
An engineer asked it directly as the meeting started. Did Mythos “live up to the hype that Anthropic claimed it would have had?”
“Yes,” a manager responded.
Engineers, the manager said, were now in “a mad dash” to close the gap. In the first half of May, Mythos found even more SharePoint bugs than it had in April.
Anthropic had handed access to a select group of organizations that make software used by regular people, companies and governments worldwide. The premise was a head start: find and fix the holes before hackers and adversarial governments like China get tools that can find the same ones.
The deadline was May 31 and nobody argued with it
“Please, please, please if your org has any April bugs, drive those down,” engineering manager Hans Andersen told the group. They had roughly two weeks “to find as many things and do as much good as we can with this access.”
May 31, he explained, “is considered the day when the rest of the world will have caught up.”
The engineers pushed on that. One of them laid out what it meant in plain terms: “So basically you’re saying if it’s released on June 1, then on June 2 the adversaries will have our bugs?”
Yep, one person responded. Yep, another echoed.
Five Eyes said months. The meeting suggests otherwise
When Project Glasswing was made public in April, national security experts figured the US had a window to patch flaws before adversaries got comparable models. In late June the Five Eyes intelligence alliance, made up of the US, Australia, Canada, New Zealand and the UK, issued an unusual joint statement warning that the window would close in a matter of months.
The Microsoft recording and the internal documents point somewhere less comfortable. The day of cyber reckoning may already be here.
Triage works fine until bugs start stacking
Faced with the flood, Microsoft has focused on what it deems most dangerous, the critical and important tiers, according to the presentation and the company’s public patch updates. Internal records say Microsoft plans to eventually address “moderate” flaws Mythos found. The documents don’t mention “low” ones at all.
That’s standard industry practice. Sickest patient first. It’s also the part that worries people who understand what Mythos can do, because the model chains bugs together, building one on top of another until a pile of ignored small problems becomes a real attack.
“The problem now is that you can chain four low-level flaws, and that can equal a high severity,” said Vinh Nguyen, a senior technical adviser to Anthropic and a senior fellow for AI at the Council on Foreign Relations who formerly served as chief AI officer and chief data scientist at the National Security Agency. “If you’re Microsoft, the current triage strategy may be underpricing risks.”
Microsoft stood by its approach in emailed responses to ProPublica, saying triage decisions weigh several factors including exploitability and customer impact. The presentation didn’t mention chaining, but a spokesperson said the technique “has long been considered as part of vulnerability assessment and risk analysis.”
Asked about the May 31 deadline, the spokesperson downplayed it, saying “accelerated targeting and exploitation of new vulnerabilities is not a new phenomenon.” The comments on the call, he added, reflect how the company “feels a sense of urgency to help our customers at this time.”
“What was heard on that call and is true today is that security is Microsoft’s most important priority and teams across the company are prioritizing using AI to discover and remediate vulnerabilities as quickly as possible.”
Microsoft declined to say how many bugs engineers have patched since the presentation.
Months of work, and that’s one product team
The SharePoint group “will be busy for months,” the presentation and slides predicted. Critical bugs first, important ones in August, then roughly 300 “moderate” bugs after that. SharePoint is what governments and businesses use to manage data and documents.
Microsoft says critical covers things like worms that crash systems and spread malware across networks. Important can mean “compromise of the confidentiality, integrity, or availability of user data” plus the “availability of processing resources.”
The documents don’t cover Microsoft’s full product line, but one noted that since the company started using Mythos earlier this year, it has found hundreds of critical or important bugs across Microsoft 365, Teams and the Copilot AI tool. As of mid-May, most were still unpatched.
“They’re not profound and exotic, but they’re real,” Andersen said during the meeting. “And a lot of them are exploitable.”
Whether hackers have exploited any specific Mythos-found bug isn’t clear. Some have used AI to automate attacks and appear to be running Mythos-like tech to find and exploit weaknesses.
Patch Tuesday broke its own record by 400
The strain shows up in public. In June, Microsoft’s monthly patch release covered more than 200 bugs, which industry experts called an all-time high at the time. On July 14, it shipped fixes for more than 600.
Only seven of those were low or moderate severity, and hackers were actively exploiting one of them, according to Dustin Childs, leader of the Zero Day Initiative bug bounty program at cybersecurity company TrendAI. Everything else was important or critical.
“Well folks. Here we are. The bug apocalypse has fully descended upon us,” Childs wrote in a July 14 blog post.
Microsoft told ProPublica the volume “will not be plateauing for a bit,” and said it has “invested heavily in both people as well as AI-powered triage solutions that scale quickly to handle the growing number of vulnerabilities.”
The fix is more people, which is the part nobody wants to hear
Nguyen’s argument is that chaining breaks the old math. Instead of pushing low-risk flaws aside, companies should staff up to develop and test patches across the whole severity range. The cyber ER needs more doctors and nurses working the minor wounds that turn deadly later, not just the life-threatening cases.
“There’s no alternative,” Nguyen said. “The patients are coming in fast and furious.”
Microsoft said it’s “always going to be reevaluating and considering whether things that were previously lows or moderates be upgraded or thought about differently. With these AI systems, it makes us rethink some of these things. Across the industry, we’re all looking to see how drastic of a change it will be.”
Decades-old code, global install base
Microsoft’s users sit in an awkward spot. Ubiquity makes the company a frequent and lucrative target, and plenty of its products still run “legacy” code written decades ago on outdated technology, carrying unaddressed flaws that pile into what the industry calls “technical debt.”
The rest of the software industry has the same problem, and so does open-source code, which is typically free to use and largely maintained by volunteers. That code holds up Internet infrastructure and gets baked into much of modern technology, including Microsoft’s own products.
“Nobody has really figured out how to deal with this, and everybody is casting around for what they need to do,” said J. Michael Daniel, a former cybersecurity adviser to President Barack Obama and president of the Cyber Threat Alliance, a cybersecurity nonprofit. “Our tech debt is coming due.”
Ben Edwards, a data scientist who specializes in managing software vulnerabilities, said the industry was already handling an “intense volume even before AI.”
“It was like drinking from a garden hose on the jet setting before, and now it’s like drinking from a fire hose,” Edwards said. “They might have had the teams that could handle that garden hose. Whether they can handle the fire hose is something else.”
The team catching all of this was understaffed before Mythos
The Microsoft Security Response Center has been perennially short-handed, ProPublica has reported. Even before AI-identified bugs started arriving, the center fielded hundreds or thousands of reports a month, pushing it to its limits.
Former employees described the reason as a matter of corporate math: plugging security holes is a cost center, building new products is a profit center. The company doesn’t want its best engineers tied up writing patches instead of shipping features that make money.
Microsoft said it doesn’t discuss internal staffing but has invested in recent years to “focus our teams on keeping our customers secure.” It “continuously evaluates the staffing, processes, and technologies required to support security response and vulnerability management,” a spokesperson said.
The May slides put a number on the effort: Anthropic gave Mythos access to roughly 50 full-time Microsoft employees, with a goal to “harden critical services before publicly available models catch up.” A slide titled “What’s Next” predicted the Security Response Center would keep seeing case volume “as public tools catch up” to Mythos.
One staffer’s reassurance lasted about five seconds
During the May meeting, someone offered a comforting thought. Adversaries “don’t have the source code” that an AI tool like this would scan. Colleagues corrected him immediately. Portions of Microsoft’s code have leaked to hackers over the years.
“It might not be this week’s source code,” one person said. “But they’ve got source code. It’s out there.”
Microsoft’s response to that exchange was that engineers “design our security processes on the expectation that determined adversaries may gain access to code.”
Which is another way of saying the head start was never really the point. If you run SharePoint, Microsoft 365 or Teams, the practical takeaway is to stop treating the moderate and low tier of your own patch backlog as optional, because the tools doing the finding don’t sort by severity. They sort by what connects to what.