Anthropic's AI is finding Microsoft bugs faster than engineers can fix them

A new Anthropic model called Mythos is uncovering security flaws in Microsoft software at a rate that has the company scrambling. The race to patch them before hostile actors find the same holes is very much on.

AI2Day NewsdeskUpdated Editor: Lee Brown4 min read
An advanced computer screen displaying a complex AI algorithm in a darkened cybersecurity operations center
Share

Key points

  • Anthropic gave select software companies access to a new AI model called Mythos in mid-May 2025 to find security flaws before hackers could.
  • Microsoft launched an internal effort, codenamed Project Glasswing, specifically to fix the vulnerabilities Mythos uncovered.
  • The effort is framed as a defensive race: patch the holes before China or other adversarial actors use similar AI tools to exploit them.
  • Engineers at Microsoft's Redmond headquarters openly questioned whether Mythos performed as well as Anthropic claimed.

Dozens of Microsoft engineers crowded into a conference room in Redmond or joined by video one afternoon in mid-May. The agenda was blunt: an AI had been breaking their software, and they needed to reckon with how badly.

That AI is Mythos, a model built by Anthropic, the San Francisco safety-focused company behind the Claude chatbot family. Anthropic gave Mythos access to a small group of organisations that build software used by ordinary people and governments. The goal was straightforward: let an advanced AI hunt for security vulnerabilities, the weak spots in code that attackers can slip through, before real-world hackers find them first.

Microsoft's internal response got a name: Project Glasswing. We first covered it on 21 July 2026.

Why does this matter to ordinary people?

Microsoft software sits on hundreds of millions of computers worldwide. A vulnerability left unpatched is an open door. If a government-backed hacking group or a criminal gang finds the same flaws first, the consequences range from stolen data to disrupted infrastructure.

That's exactly the threat Anthropic and Microsoft are trying to get ahead of. As reported by Ars Technica, the concern inside the Glasswing meetings was explicit: adversarial governments, China named among them, could soon deploy their own AI tools to scan for the same weaknesses at scale.

AI models have long helped write code. What's newer is the speed at which Mythos apparently identifies flaws in existing code. Fixing vulnerabilities has always been a race against discovery. Mythos seems to be shortening the clock on both sides.

Were the engineers convinced?

Not entirely, at first. As the Glasswing meeting got underway, one engineer asked the question that hung over the room: did Mythos actually "live up to the hype that Anthropic claimed it would have had?"

Healthy scepticism. AI systems get oversold regularly. A model that surfaces ten minor, already-known issues looks very different from one that finds genuinely dangerous, previously unknown flaws. What Mythos's findings actually consist of, and how many were patched, hasn't been reported yet. That's the number worth watching.

What happens next?

The specific flaws Mythos found remain unpublished, which is standard: you don't announce where the holes were until the patches are live. Our earlier story "Anthropic's Mythos AI Finds New Bugs Fast" made the case that most real-world breaches still exploit flaws that should have been patched months earlier, a reminder that speed of discovery is only half the equation.

What this story signals is a shift in how security works. Companies are pointing AI at their own products to beat attackers to the punch. That approach will spread. Whether defenders can keep pace with adversaries who have the same tools is the question nobody can answer yet.

For everyday users, the practical advice hasn't changed: keep your software updated. The patch that arrives on your machine may now owe its existence to an AI that found the problem first.

Common questions

What is a software vulnerability, exactly?

A vulnerability is a mistake or weak spot in a program's code that an attacker can use to get in where they shouldn't. Think of it as an unlocked window in an otherwise locked building.

Should you worry that AI can now find these flaws so quickly?

The same speed that worries defenders could protect you. If companies use AI to find and fix flaws before attackers do, your software gets more secure. The risk is that hostile actors get the same tools first.

© 2026 AI2Day