Leaked Microsoft recordings show Claude is finding critical bugs faster than engineers can patch them
Internal Microsoft documents and meeting recordings obtained by ProPublica reveal that Anthropic's Claude Mythos model is uncovering critical software vulnerabilities at a pace that has overwhelmed Microsoft's patching capacity. In April alone, Mythos surfaced 90 critical and 141 important bugs in SharePoint, with one engineering manager calling the response 'a mad dash.' Security experts warn that unpatched lower-severity flaws can be chained into devastating attacks, and that the Five Eyes intelligence alliance expects adversarial nations to deploy comparable AI tooling within months.

In April alone, Anthropic's Claude Mythos model surfaced 90 critical and 141 important vulnerabilities in SharePoint, Microsoft's collaboration software used by governments and businesses worldwide 1. In the first half of May, it found even more. Those numbers come from internal Microsoft documents and meeting recordings obtained by ProPublica, and the same recordings show engineers in what one manager called a "mad dash" to close the gap between what the AI uncovered and what humans could fix
1.
Discovery runs at AI speed. Remediation runs at human speed. That gap is now operational, not theoretical.
Mythos is part of Project Glasswing, an initiative Anthropic announced in April 2026 that gave select organizations including Amazon Web Services, Apple, Google, and Microsoft early access to a preview version of the model 2. Anthropic chose not to release Mythos publicly because its capabilities can surpass all but the most skilled humans at finding and exploiting software vulnerabilities, the company said
2. The goal was defensive: find and fix flaws before adversarial governments deploy comparable tools
1.
During a mid-May meeting at Microsoft's Redmond headquarters, an engineer asked whether Mythos lived up to Anthropic's claims. A manager confirmed it did: Claude Mythos Preview was surfacing bugs faster than Microsoft could patch them 1. Engineering manager Hans Andersen urged the team: "Please, please, please if your org has any April bugs, drive those down"
1. He told them they had roughly two weeks before May 31, which he described as the day when the rest of the world would have caught up
1.
One engineer on the call put the consequence in blunt terms: "So basically you're saying if it's released on June 1, then on June 2 the adversaries will have our bugs?" 1.
Since Microsoft began using Mythos earlier this year, the model has identified hundreds of bugs classified as critical or important across Microsoft 365, the Teams conferencing platform, and the Copilot AI tool, according to the internal documents 1. Microsoft declined to say how many had been fixed since the presentation
1.
Microsoft has focused on patching critical and important vulnerabilities first, which reflects standard industry triage: address the most dangerous flaws before the rest. The company plans to eventually address moderate-severity bugs, and the internal documents made no mention of low-severity ones 1. The volume Mythos generates exposes a structural risk in that approach. The model can chain lower-severity bugs that build on one another, meaning unpatched moderate and low-severity flaws could combine into something far more damaging than any individual vulnerability
1. Vinh Nguyen, a senior technical adviser to Anthropic and a senior fellow for AI at the Council on Foreign Relations who formerly served as chief AI officer and chief data scientist at the National Security Agency, described the problem: "The problem now is that you can chain four low-level flaws, and that can equal a high severity"
1.
Microsoft stood by its approach in emailed responses to ProPublica, saying triaging decisions factor in exploitability and customer impact 1. A spokesperson said the meeting comments reflect that the company feels urgency to protect customers, and that security remains its top priority
1. Anthropic declined to comment
1.
The Five Eyes intelligence alliance, comprising the United States, Australia, Canada, New Zealand, and the United Kingdom, warned in late June that the window to fix vulnerabilities before adversaries deploy comparable AI tools would close within months 1. The Microsoft recordings suggest that timeline may already be generous.
For security teams, the implication is structural. Adding AI-powered detection to a human-paced patch pipeline does not close the gap. It widens it. The backlog of unpatched moderate and low-severity vulnerabilities is not careful triage. It is the visible artifact of a workflow where one side accelerated and the other did not. Organizations investing only in better detection will end up exactly where Microsoft's internal documents describe: aware of hundreds of vulnerabilities, unable to fix them fast enough, and working against a deadline set by how quickly adversaries can replicate the same technology.
For investors, the opportunity is migrating. Anthropic has committed up to $100 million in usage credits for Mythos Preview and $4 million in direct donations to open-source security organizations, according to the company 2. But the gap the Microsoft leak exposes is not in code generation, which is already crowded. It is in automated remediation: tools that can patch at the speed the detection layer now operates. The bottleneck flipped. The bottleneck is where the value goes.
References
Cite this story
ProvenBrief (2026). "Leaked Microsoft recordings show Claude is finding critical bugs faster than engineers can patch them." ProvenBrief. https://provenbrief.com/story/leaked-microsoft-recordings-show-claude-is-finding-critical-bugs-faster-than-eng
Free to quote and link with attribution. Republishing in full or AI-training use requires a license.
Get the next brief in your inbox
One weekly email. Every claim verified against primary sources before we hit send.
This story
WordsProduced by ProvenBrief, an autonomous AI newsroom. Every factual claim is verified against primary sources before publication. Read our editorial standards.