Microsoft grapples with backlog fixing AI‑found SharePoint vulnerabilities
Internal Microsoft documents show that Anthropic’s Claude Mythos Preview AI model uncovered 90 critical and 141 important security flaws in SharePoint during April, with additional findings reported in the first half of May. The model also identified hundreds of serious bugs across Microsoft 365, Teams and Copilot. Microsoft’s triage process prioritises critical and important findings, leaving roughly 300 medium‑severity SharePoint issues for later and offering little attention to low‑severity bugs. An internal meeting in mid‑May described a “mad‑dash” to close the gap before a May 31 deadline, after which the broader security community—or adversaries such as state‑linked actors—could exploit the remaining flaws. Engineers warned that low‑severity weaknesses can be chained together, turning several minor bugs into a high‑severity attack. Project Glasswing, the partnership that gave Anthropic’s model early access to Microsoft code, is intended to help protect critical systems before AI‑driven tools become widely available.
Entities: Anthropic PBC · Claude Mythos · Claude Mythos Preview · Microsoft Corp. · Microsoft Corporation · Project Glasswing · SharePoint
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [○ 1 SOURCE] Engineers warned that if the AI model were released publicly on June 1, attackers could exploit the unpatched bugs the next day. (Internal meeting recording)
- [● 4 SOURCES] Claude Mythos Preview identified 141 important vulnerabilities in SharePoint in April. (ProPublica, internal Microsoft materials)
- [● 2 SOURCES] Microsoft engineers held an internal meeting in mid‑May to accelerate patching, setting May 31 as a deadline before the wider security community could catch up. (Recorded meeting, ProPublica)
- [● 2 SOURCES] Project Glasswing provides early AI model access to selected partners, including Microsoft, to help protect critical systems. (Company announcements, internal documents)
- [● 3 SOURCES] Four low‑severity flaws can be chained together to create a high‑severity vulnerability. (Expert commentary, internal Microsoft analysis)
- [● 4 SOURCES] Around 300 medium‑severity SharePoint findings were deprioritized for later remediation. (Internal Microsoft documents)
- [● 4 SOURCES] Anthropic's Claude Mythos Preview identified 90 critical vulnerabilities in Microsoft SharePoint in April. (ProPublica, internal Microsoft materials)
- [● 3 SOURCES] Hundreds of serious vulnerabilities were also discovered in Microsoft 365, Teams and Copilot by May. (ProPublica, internal Microsoft materials)