< Back to all clusters
[TECHNOLOGY] · United States · 8 sources

started · updated

Microsoft grapples with backlog fixing AI‑found SharePoint vulnerabilities

Internal Microsoft documents show that Anthropic’s Claude Mythos Preview AI model uncovered 90 critical and 141 important security flaws in SharePoint during April, with additional findings reported in the first half of May. The model also identified hundreds of serious bugs across Microsoft 365, Teams and Copilot. Microsoft’s triage process prioritises critical and important findings, leaving roughly 300 medium‑severity SharePoint issues for later and offering little attention to low‑severity bugs. An internal meeting in mid‑May described a “mad‑dash” to close the gap before a May 31 deadline, after which the broader security community—or adversaries such as state‑linked actors—could exploit the remaining flaws. Engineers warned that low‑severity weaknesses can be chained together, turning several minor bugs into a high‑severity attack. Project Glasswing, the partnership that gave Anthropic’s model early access to Microsoft code, is intended to help protect critical systems before AI‑driven tools become widely available.

Entities

Anthropic PBC · Claude Mythos · Claude Mythos Preview · Microsoft Corp. · Microsoft Corporation · Project Glasswing · SharePoint

Claims

What the coverage asserts, and how many sources carry each claim.