Anthropic's Mythos Finds 90 Critical SharePoint Bugs as Microsoft Races to Patch Them
Updated
Updated · Ars Technica · Jul 29
Anthropic's Mythos Finds 90 Critical SharePoint Bugs as Microsoft Races to Patch Them
3 articles · Updated · Ars Technica · Jul 29
Summary
Microsoft engineers told a mid-May meeting that Anthropic's Claude Mythos Preview was surfacing vulnerabilities faster than the company could fix them, triggering what one manager called a "mad dash."
April data from an internal presentation showed 90 critical bugs and 141 important ones in SharePoint alone, with even more found in the first half of May.
Hans Andersen urged teams to clear April bugs within roughly two weeks, saying May 31 was the point when "the rest of the world will have caught up" to Microsoft's early access.
The urgency reflects fears that hackers or governments such as China could soon use similar AI tools to uncover and exploit the same flaws for espionage or sabotage.
If AI uncovers critical software flaws faster than humans can patch them, are we unintentionally making our systems more vulnerable?
Can automated remediation systems evolve fast enough to save critical infrastructure from the very AI designed to protect it?
The 622-CVE Patch Crisis: How AI Unleashed a Vulnerability Deluge and Redefined Software Security in 2026
Overview
In July 2026, Microsoft’s integration of Anthropic’s Mythos AI into its security workflows led to a record-breaking Patch Tuesday, with 622 vulnerabilities disclosed—triple the previous high. This surge was driven by AI models that can find software flaws in minutes, while human teams still need days or weeks to verify and patch them. As soon as patches are released, attackers quickly analyze the changes to develop exploits, shrinking defenders’ response time. The result is a dangerous imbalance: AI accelerates vulnerability discovery, but human remediation can’t keep up, leaving organizations exposed to rapid, automated attacks and forcing a shift toward resilience and real-time defense.