In mid-May 2026, Microsoft engineers and managers convened at the company’s Redmond, Washington headquarters to discuss Project Glasswing, an initiative focused on addressing software vulnerabilities rapidly uncovered by a new AI model called Mythos.
Developed by AI company Anthropic, Mythos was granted access to select organizations, including Microsoft, to identify security weaknesses in widely used software before malicious actors, including adversarial governments like China, could exploit them.
According to a recording of the meeting reviewed by ProPublica, Microsoft was using the Claude Mythos Preview version of the AI, which surfaced bugs at a pace faster than the company could patch. A manager described the situation as a “mad dash” to close the gap between discovery and remediation.
Microsoft releases monthly software fixes through its “Patch Tuesday” program. In June 2026, the company issued patches for over 200 bugs, marking an all-time high according to industry experts. Despite this, the volume of vulnerabilities identified by Mythos has strained Microsoft’s capacity to respond swiftly.
Internal presentation slides from May revealed that Anthropic provided Mythos access to approximately 50 full-time Microsoft employees. The goal was to “harden critical services before publicly available models catch up.” The presentation also forecasted that the Microsoft Security Response Center would continue to see increased case volume as public AI tools advance.
Microsoft spokespersons downplayed the urgency of the situation, stating that “accelerated targeting and exploitation of new vulnerabilities is not a new phenomenon,” but acknowledged the company’s “sense of urgency to help our customers at this time.”
Some vulnerabilities identified could compromise the confidentiality, integrity, or availability of user data and processing resources. After addressing the most critical issues, Microsoft planned to tackle roughly 300 moderate-severity bugs.
This development highlights the growing impact of AI in cybersecurity, both as a tool for defense and a potential vector for exploitation.
Sources
- ProPublica, "Anthropic’s New AI Model Can Identify More Software Bugs Than Ever. Microsoft Is Struggling to Fix Them Fast Enough.", July 29, 2026, link
Loading comments.