Anthropic's AI finds Microsoft bugs faster than they can be patched
In mid-May, Microsoft engineers gathered in Redmond, Washington, to address vulnerabilities uncovered by Anthropic's AI model, Mythos. The AI, developed by Anthropic, was shared with select organizations to identify security flaws before malicious actors could exploit them. During a meeting, a manager confirmed that Mythos lived up to its hype, surfacing bugs faster than Microsoft could patch them. In April alone, Mythos found 90 critical and 141 important bugs in SharePoint. Engineering manager Hans Andersen urged teams to address April bugs, noting that by May 31, adversaries would likely have similar capabilities. Engineers expressed concern that releasing the tool on June 1 would give adversaries access to their bugs the next day.
Key facts
- Microsoft engineers met in mid-May at Redmond headquarters to discuss Project Glasswing.
- Anthropic's AI model Mythos uncovered vulnerabilities at an unprecedented rate.
- Mythos was given to select organizations to find and fix bugs before hackers exploited them.
- A manager confirmed Mythos lived up to Anthropic's claims.
- In April, Mythos found 90 critical and 141 important bugs in SharePoint.
- Engineering manager Hans Andersen urged teams to reduce April bugs.
- May 31 was considered the day when adversaries would have similar tools.
- Engineers worried that releasing Mythos on June 1 would give adversaries immediate access to bugs.
Entities
Institutions
- Microsoft
- Anthropic
- ProPublica
Locations
- Redmond
- Washington
- United States
- China