Anthropic’s new AI model, Mythos, is uncovering software vulnerabilities in Microsoft’s code faster than the tech giant’s engineers can patch them. This has forced Microsoft to hold urgent meetings to address the growing security gap.
In mid-May, dozens of Microsoft engineers and their managers gathered online and in a conference room at the company’s Redmond, Washington, headquarters to discuss Project Glasswing. The project was a race to fix weaknesses in Microsoft’s code that Mythos was finding at an unprecedented speed.
How Mythos Finds Bugs Faster Than Humans
Anthropic gave access to Mythos to select organizations that make software used by regular people, companies, and governments worldwide. The AI model can scan large amounts of code and identify vulnerabilities much quicker than human security teams.
According to the original story, the goal was to find and fix these vulnerabilities before hackers and adversarial governments — like China — begin using similar AI tools to find and exploit them for espionage and sabotage.
Why This Matters for Cybersecurity
The speed at which Mythos finds bugs creates a serious problem: even if AI finds a vulnerability, fixing it still takes time. Microsoft engineers are struggling to keep up with the pace of detection.
During the meeting, one engineer asked whether Mythos “lived up” to its reputation, highlighting the tension between the AI’s capabilities and the human team’s ability to respond.
This situation shows a growing challenge in cybersecurity: AI tools can now find threats faster than organizations can patch them, leaving a window of opportunity for attackers.
Our Take: A New Race Between AI and Security Teams
This story is a wake-up call for the entire tech industry. AI is no longer just a tool for finding bugs — it is now outpacing the people who are supposed to fix them. In our view, this creates a dangerous gap. If AI can find vulnerabilities faster than humans can patch them, then the same AI could be used by bad actors to exploit those weaknesses before they are fixed.
Microsoft and other tech companies need to rethink their security processes. They cannot rely on human teams alone anymore. Automated patching systems and faster response protocols will be essential. Otherwise, the very tool meant to protect us could become a weapon in the hands of adversaries.
The question is no longer whether AI can find bugs — it is whether we can fix them fast enough.