Logic of Logic
thursday, august 6, 2026 · the day's ai, attributed published by trilot llc · wyoming
brief securitysafetyproducts

Mythos outpaces Microsoft's own patches

ProPublica found Claude Mythos surfaced 90 critical and 141 important SharePoint bugs in April alone, faster than Microsoft's teams could patch them.

A ProPublica investigation published July 29, based on a recording of an internal Microsoft meeting and internal documents, describes engineers racing to patch vulnerabilities that Anthropic’s Claude Mythos Preview keeps finding faster than they can fix them. Under a program called Project Glasswing, Anthropic gave Microsoft and other major software makers early access to Mythos to find and fix flaws before attackers could. In April alone, Mythos surfaced 90 “critical” and 141 “important” bugs in SharePoint, Microsoft’s widely used collaboration software, according to a slide shown at the meeting; more turned up in the first half of May. Engineering manager Hans Andersen told the group they had roughly two weeks before “the rest of the world will have caught up” to the same class of tooling.

The scale shows up in Microsoft’s own public numbers. The company’s June “Patch Tuesday” release, at over 200 fixed bugs, was already an industry-reported all-time high; July 14’s release blew past that with patches for more than 600 bugs, nearly all rated important or critical. Dustin Childs, who leads the Zero Day Initiative bug bounty program, called it “the bug apocalypse” in a public post the same day. Internal documents reviewed by ProPublica show roughly 300 additional “moderate”-severity bugs still queued behind the critical and important ones, with no clear plan yet for the “low”-severity tier. Microsoft told ProPublica its triage priorities are based on exploitability and customer impact, and that bug volume “will not be plateauing for a bit.”

What it means for operators

The uncomfortable detail here isn’t the raw bug count, it’s the chaining risk. Vinh Nguyen, a senior technical adviser to Anthropic and former NSA chief AI officer, put it directly:

You can chain four low-level flaws, and that can equal a high severity.

— Vinh Nguyen, senior technical adviser to Anthropic

That means the unpatched moderate-and-below backlog isn’t necessarily low-risk just because Microsoft’s triage system labels it that way. If your organization runs SharePoint, Teams, Microsoft 365, or Copilot, and you don’t already track Microsoft’s Patch Tuesday cadence as a signal of exposure, this is the moment to start, since the volume Anthropic’s tooling is surfacing suggests the backlog is growing faster than any single vendor’s patch pipeline. It’s also a preview of what every major software vendor is about to face: AI-assisted bug discovery isn’t slowing down, and neither adversaries nor competitors are waiting for anyone’s patch calendar. The same underlying tooling has already turned up real weaknesses in cryptographic algorithms like HAWK and reduced-round AES, which should tell you this isn’t a one-vendor story; if you’re weighing your own agent-security spending, the Microsoft numbers here are the clearest public evidence yet of the scale that spending needs to match.

sources 2 cited
1 propublica.org Anthropic is finding bugs faster than Microsoft can fix them 2 arstechnica.com Anthropic is finding bugs faster than Microsoft can fix them (syndicated)
next