One afternoon in mid-May, dozens of Microsoft engineers and their managers gathered online and in a conference room at the company’s headquarters in Redmond, Washington, to discuss the Glasswing project.
The tech giant was racing to fix weaknesses in its code that a new AI model known as Mythos was discovering at an unprecedented rate. AI giant Anthropic, which developed Mythos, had provided access to selected organizations that create software used by individuals, businesses and governments around the world. The goal was to find and fix vulnerabilities before hackers and opposing governments like China began using similar tools to find and exploit them for espionage and sabotage.
As the group was setting up, an engineer asked the question that dominated the meeting: Did Mythos “live up to the hype that Anthropic claimed it had?”
“Yes,” one official responded, according to a recording of the meeting viewed by ProPublica.
The version Microsoft was using, Claude Mythos Preview, was showing up bugs faster than the tech giant could fix them, and engineers, the official said, were now in “a mad race” to close the gap.
A slide from today’s presentation showed that in the month of April alone, Mythos discovered 90 “critical” and 141 “important” bugs in SharePoint, Microsoft’s widely used collaboration software. In the first half of May, even more were found.
“Please, please, please, if your organization has April bugs, remove them,” engineering manager Hans Andersen implored the group. They had about two weeks “to find as many things and do as much good as possible with this access.”
May 31, he explained, “is considered the day when the rest of the world will have caught up.”
The engineers on the call emphasized this assertion, with one summarizing the situation: “So basically you’re saying if it comes out on June 1st, then on June 2nd the adversaries will have our bugs? »
Yes, one person responded. Yes, another one echoed.
Since Anthropic launched a national conversation about the bug-hunting power of AI in April, when the Glasswing project was made publicnational security experts predicted that the United States would have a window of opportunity to fix the flaws before its adversaries have similar models capable of discovering the same weaknesses. In late June, the international alliance of intelligence agencies known as Five Eyes – whose members include the United States, Australia, Canada, New Zealand and the United Kingdom – warned in a statement unusual joint statement that in a few months, this window would close. But the recording of Microsoft’s meeting, as well as internal documents reviewed by ProPublica, suggest that the day of cyber may already be here.
Given the deluge of flaws identified by Mythos, Microsoft has so far focused on patching those it considers the most dangerous, which are rated critical or important, according to the presentation as well as the company’s own public patch updates. Internal records indicate that Microsoft plans to eventually patch the “moderate” severity flaws discovered by Mythos. The documents made no mention of “low” severity bugs.
The company’s approach reflects the industry’s typical triage system. Just as the sickest patients are the first to be treated in the emergency room, vulnerability triage prioritizes issues that could cause the most damage if exploited by hackers.
But this strategy carries its own risk in the age of AI-driven bug hunting, in which new tools are revealing a record volume of weaknesses in the products we use every day. Mythos, for example, is able to chain together a series of bugs that build on each other, meaning that low or moderate severity vulnerabilities that remain unpatched could create an opening to carry out devastating attacks.
“The problem now is that you can chain four low-level breaches together, which can equate to high severity,” said Vinh Nguyen, senior technical advisor at Anthropic and senior AI fellow at the Council on Foreign Relations, who previously served as director of AI and chief data scientist at the National Security Agency. “If you’re Microsoft, the current triage strategy may understate the risks.”
In its email responses to ProPublica’s questions, Microsoft stood by its approach, saying its sorting decisions were based on a number of factors, including usability and customer impact. The company’s presentation did not mention chaining, but a spokesperson told ProPublica that the technique “has long been considered part of vulnerability assessment and risk analysis.”
Asked about the internal presentation and the then-looming May 31 deadline, the spokesperson downplayed its significance, saying that “the accelerated targeting and exploitation of new vulnerabilities is not a new phenomenon.” That said, he added, comments made during the meeting reflect how the company “feels a sense of urgency to help our customers at this time.”
“What was heard on that call and is true today is that security is Microsoft’s most important priority and that teams across the company are prioritizing the use of AI to discover and remediate vulnerabilities as quickly as possible. »
Microsoft declined to answer questions about how many bugs engineers have fixed since the presentation.
Anthropic declined to comment.
Microsoft’s internal presentation and accompanying slides predict that the group of employees working on SharePoint, used by governments and businesses around the world to manage data and documents, “will be busy for months,” working first on the highest priority critical bugs and then tackling the biggest ones in August. Microsoft claims to categorize vulnerabilities Critical items include so-called worms that can crash systems and spread malware as they race across computer networks. The most significant ones could result in a “compromise of the confidentiality, integrity or availability of user data” as well as the “availability of processing resources”. Once those categories are cleared, the group would begin working on about 300 “moderate” bugs, according to the presentation.
Although internal documents reviewed by ProPublica don’t include updates on all of Microsoft’s offerings, they give an idea of the scope of the problem. A document states that since the company started using Mythos earlier this year, it has collectively found hundreds of bugs that Microsoft has classified as critical or important in popular products such as Microsoft 365, the Teams conferencing platform and the Copilot AI tool. As of mid-May, most of them had not yet been fixed.
“They’re not deep or exotic, but they’re real,” Andersen, the engineering manager, said at the meeting. “And a lot of them are actionable.”
It’s unclear whether the hackers exploited a specific bug identified by Mythos, but some did. leveraged AI to automate attacks And seems to use A myth-like technology for finding and exploiting weaknesses.
There have been outward signs of Microsoft’s internal struggle to deal with the growing list of bugs to fix. Each month, the company publicly releases patches for its software vulnerabilities in what is known as “Patch Tuesday.” In June, it released fixes for more than 200 bugs, which industry experts then called record level. But on July 14, the company broke that record and released fixes for more than 600 bugs. Only seven were classified as low or moderate severity, including one that hackers were actively exploiting, according to Dustin Childs, manager of the Zero Day Initiative bug bounty program, part of cybersecurity firm TrendAI. The rest was important or critical.
“Well folks. Here we are. The insect apocalypse has descended upon us”, Childs wrote in a blog post July 14.
Microsoft told ProPublica that overall bug volume “won’t stagnate for a while,” but a spokesperson said the company has “invested heavily in people- and AI-based triage solutions that are rapidly evolving to handle the growing number of vulnerabilities.”
Given the new realities of the AI era, including chaining capabilities, companies like Microsoft may need to rethink their entire approach to triage, said Nguyen, former head of AI at the NSA. Rather than leaving aside what are now considered low-risk vulnerabilities, companies should dedicate staff to developing and testing patches across the entire spectrum of vulnerabilities, he said. In other words, cyber emergencies need more doctors and nurses to treat life-threatening illnesses as well as minor injuries that could later become life-threatening.
“There is no alternative,” Nguyen said. “Patients are coming fast and furious. »
Microsoft told ProPublica that it is “always going to reevaluate and determine whether things that were previously low or moderate will be upgraded or thought of differently. With these AI systems, it’s making us rethink some of these things. Across the industry, we’re all looking to see how radical this change will be.”
“The bug apocalypse has completely descended upon us.”
Dustin Childs, manager of the Zero Day Initiative bug bounty program
Microsoft users may be particularly vulnerable. The popularity of its offerings, used worldwide, makes it a frequent and lucrative target for hackers. Additionally, many of its products contain “legacy” code. Developed decades ago using now obsolete technology, this code contains unresolved defects and contributes to what is known in the industry as “technical debt.”
But the challenge of fixing the flood of newly discovered bugs also extends to the rest of the software industry, as well as to the code of open source software that is generally free to use and largely run by volunteers. Open source software underpins the infrastructure of the Internet and is integrated into much of the world’s modern technology, including products offered by major technology companies such as Microsoft.
“Nobody has really figured out how to deal with this, and everyone is figuring out what to do,” said J. Michael Daniel, a former cybersecurity adviser to the president Barack Obama and president of the Cyber Threat Alliance, a nonprofit organization focused on cybersecurity. “Our technology debt is coming due. »
Ben Edwards, a data scientist specializing in software vulnerability management, said the software industry was dealing with “intense volume even before AI.”
“It used to be like drinking from a garden hose on a jet, and now it’s like drinking from a fire hose,” Edwards said. “They may have had the crews that could handle that garden hose. Whether they could handle the fire hose is another thing.”
Although the volume of vulnerabilities has increased over the years, Microsoft’s internal group responsible for dealing with them, the Microsoft Security Response Center, is consistently understaffed. Even before AI-identified bugs were squashed, the center was logging hundreds, if not thousands, of reports per month, pushing the group to its limits, ProPublica reported.
The size of the center reflects Microsoft’s business philosophy: Closing security holes is a cost center, while creating new products is a profit center. former employees said. The company is reluctant to commit its top engineers to creating security patches — a cost center — instead of developing new products and features that will generate profits, ProPublica reported.
Microsoft told ProPublica that it does not discuss internal personnel decisions, but has made investments in recent years to “focus our teams on keeping our customers safe.” The company “continually evaluates the personnel, processes and technologies needed to support security response and vulnerability management,” a spokesperson said.
According to slides that accompanied the May internal presentation, Anthropic provided Mythos with access to approximately 50 full-time Microsoft employees, with the goal of “strengthening critical services before publicly available models are adopted.” at top.” A slide titled “What’s Next” predicted that the Microsoft Security Response Center would experience continued case volume “as public tools catch up with Mythos.
At the May meeting, one staffer seemed to console himself with the thought that adversaries “don’t have the source code” that would allow such an AI tool to analyze weaknesses. His colleagues, however, quickly corrected him. Parts of Microsoft’s code have actually fallen into the hands of hackers over the years.
“This may not be the source code for this week,” one person said. “But they have the source code. It’s available.”
In a statement to ProPublica, Microsoft downplayed the comment, saying engineers “design our security processes with the expectation that determined adversaries can access the code.”






























