Microsoft Struggles to Fix Bugs Found by Anthropic’s Claude Mythos
Anthropic’s Claude Mythos reportedly found hundreds of security vulnerabilities across Microsoft products, including 231 serious SharePoint flaws in April alone.
The findings show how artificial intelligence can accelerate bug detection. However, they also highlight the growing pressure on Microsoft’s engineering teams to investigate and fix vulnerabilities quickly.
Microsoft employees praised Claude Mythos
According to ProPublica, Microsoft employees praised Anthropic’s Claude Mythos Preview during an internal meeting held in May.
Anthropic reportedly provided early access to around 40 partners, including Microsoft, Google, Apple, and Amazon. The company has since restored access to Mythos 5 following US government approval.
During the Microsoft meeting, employees discussed how effectively the model could examine large codebases and identify potential security weaknesses.
Claude Mythos found 231 serious SharePoint vulnerabilities
Claude Mythos reportedly identified 90 critical and 141 important SharePoint vulnerabilities during April.
The figures only covered SharePoint. Hundreds of additional vulnerabilities were reportedly discovered across other Microsoft products and services.
Microsoft managers instructed engineering teams to prioritize critical and important issues. Developers would address moderate-severity vulnerabilities later because the teams lacked enough resources to resolve every finding immediately.
Moderate vulnerabilities can still create serious risks
A moderate-severity vulnerability may appear less urgent when reviewed individually. However, attackers can combine several lower-severity weaknesses to create a more dangerous exploit chain.
This makes delayed remediation risky, especially as AI tools improve the speed at which security researchers and attackers can analyze software.
Microsoft has already warned that AI makes delaying Windows updates more dangerous. Faster vulnerability discovery could shorten the period between a flaw’s identification and its exploitation.
AI is changing Microsoft’s security process
Microsoft has expanded its AI-driven Windows security strategy by introducing AI tools into its development, testing, and security pipelines.
The company also recently introduced MAI-Cyber-1-Flash, a cybersecurity model designed to reduce the cost of automated security investigations. Microsoft plans to integrate the model into MDASH.
These systems can review more code and detect more weaknesses than traditional security teams could identify manually. However, finding more vulnerabilities also creates a larger remediation backlog.
Legacy Microsoft code increases the workload
Microsoft products such as Windows, SharePoint, and Microsoft 365 contain code developed across several decades.
Some older components may not follow modern security standards or development practices. Reviewing, replacing, and modernizing these systems requires significant engineering resources.
AI can help identify weaknesses across these large codebases, but Microsoft still needs developers to validate the findings, produce fixes, test updates, and deploy patches without disrupting customers.
Microsoft reviews staffing and security investments
Microsoft told ProPublica that it continues to review how its teams classify and prioritize vulnerabilities.
The company is also evaluating staffing levels, security investments, and development tools as AI increases the number of discovered issues.
The challenge no longer centers only on finding vulnerabilities. Microsoft must also ensure that its engineering teams can process and repair them quickly enough.
The company’s broader AI strategy could help it choose the best model for each task. Microsoft is challenging OpenAI and Anthropic by avoiding reliance on a single AI provider, giving its teams access to different models based on cost, performance, and security requirements.
AI-driven bug detection could significantly improve software security. It could also expose more vulnerabilities than engineering teams can immediately handle, increasing the importance of staffing, prioritization, and faster patch development.
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages