Anthropic finds security bugs faster than Microsoft

▼ Summary
– Microsoft engineers met in May to discuss Project Glasswing, a race to fix code vulnerabilities uncovered by Anthropic’s AI model, Mythos.
– Mythos was given to select organizations to find and fix bugs before adversaries like China could exploit them for espionage or sabotage.
– The AI model found bugs faster than Microsoft could patch them, with 90 critical and 141 important bugs in SharePoint in April alone.
– Engineering manager Hans Andersen urged teams to clear April bugs quickly, as access to Mythos was set to expire on May 31.
– Engineers expressed concern that adversaries would gain access to the same bugs once Mythos was released to the wider world on June 1.
In mid-May, dozens of Microsoft engineers and their managers gathered both online and inside a conference room at the company’s Redmond, Washington headquarters. The topic of discussion was Project Glasswing, a race to patch security flaws in the company’s code that a new artificial intelligence model, Mythos, was uncovering at a blistering pace.
The AI behind Mythos was developed by Anthropic, a major player in the AI space. The company had granted access to select organizations that build software used by millions , individuals, companies, and governments alike. The mission was clear: find and fix vulnerabilities before hackers and adversarial nations, such as China, could weaponize similar tools for espionage and sabotage.
As the meeting got underway, one engineer posed the question everyone was thinking: Did Mythos “live up to the hype that Anthropic claimed it would have had?”
“Yes,” a manager replied, according to a recording of the meeting reviewed by ProPublica.
The version Microsoft was using, Claude Mythos Preview, was surfacing bugs faster than the tech giant could patch them. Engineers, the manager explained, were now in “a mad dash” to close the gap.
A slide shown that day revealed that in April alone, Mythos had flagged 90 “critical” bugs and 141 “important” ones in SharePoint, Microsoft’s widely used collaboration platform. The pace only accelerated in the first half of May.
“Please, please, please if your org has any April bugs, drive those down,” urged engineering manager Hans Andersen. The team had roughly two weeks “to find as many things and do as much good as we can with this access.”
May 31, he noted, “is considered the day when the rest of the world will have caught up.”
The engineers on the call pushed back on that timeline. One summed up the dilemma bluntly: “So basically you’re saying if it’s released on June 1, then on June 2 the adversaries will have our bugs?”
(Source: Ars Technica)




