Microsoft is contending with a sharp rise in software vulnerabilities uncovered by Anthropic’s AI model Mythos under Project Glasswing, according to internal materials reviewed by ProPublica. The report says the model was identifying flaws faster than Microsoft could remediate them, including 90 critical and 141 important SharePoint bugs found in April alone, with additional issues discovered in early May. Microsoft reportedly prioritized critical and important findings, while security experts warned that lower-severity flaws can still be chained into serious attack paths, reducing the usefulness of traditional severity-based triage.
The pressure from AI-assisted bug discovery is reflected in Microsoft’s unusually heavy June security updates, which included dozens of fixes across Windows, Microsoft 365, Azure, Office, Exchange, SharePoint, and developer tools. Among the most urgent issues was CVE-2026-41091, a Microsoft Defender elevation-of-privilege flaw that was publicly disclosed and exploited in the wild, alongside multiple critical remote-code-execution vulnerabilities such as CVE-2026-48567 in Azure HorizonDB and CVE-2026-47291 in HTTP.sys. The disclosures highlight growing concern that defenders may have only a limited lead before attackers gain comparable AI-driven vulnerability discovery capabilities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
On July 29, 2026, ProPublica reported that Microsoft's internal response to vulnerabilities found by Anthropic's Mythos was being strained by the pace of discovery. The article framed the issue as a broader warning that defenders may have only a limited window before attackers gain similar AI-assisted vulnerability discovery capabilities.
On June 9, 2026, ZDI reviewed Microsoft's June 2026 security updates, highlighting CVE-2026-41091 in Microsoft Defender as publicly disclosed and exploited in the wild. The patch cycle also included numerous critical flaws across Azure, Windows, Office, Exchange, SharePoint, and other components.
In mid-May 2026, Microsoft held an internal meeting on Project Glasswing where managers said Anthropic's Mythos was finding vulnerabilities faster than Microsoft could patch them. Engineers were told they had roughly two weeks to reduce April bug counts before May 31 amid concern that public or adversary capabilities could catch up after June 1.
ProPublica reports that internal Microsoft materials showed more vulnerabilities were discovered in early May after the large April SharePoint haul. This indicated the AI-assisted discovery surge was continuing rather than tapering off.
According to internal Microsoft materials cited by ProPublica, Anthropic's Mythos model identified 90 critical and 141 important SharePoint vulnerabilities in April alone. The volume of findings reportedly outpaced Microsoft's ability to patch them.
As the volume of AI-discovered vulnerabilities grew, Microsoft reportedly prioritized remediation of critical and important bugs first. Experts cited by ProPublica warned that this severity-based triage could miss dangerous exploit chains built from lower-severity issues.
Anthropic says it launched Project Glasswing with Microsoft to use AI systems to help identify and secure critical software vulnerabilities. The reference does not provide a specific event date for the launch beyond the existence of the project.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
techdirt.com
Open sourcepropublica.org
Open sourcezerodayinitiative.com
Open sourcemicrosoft.com
Open sourceanthropic.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.