Anthropic’s Bug Hunters Are Outrunning Microsoft’s Fixers, and the Backlog Is Growing

Under Project Glasswing, Anthropic’s Claude Mythos model has been discovering security flaws in Microsoft software at a pace that exceeds the company’s ability to fix them, leaving a growing backlog of unpatched vulnerabilities in disclosure limbo.

Project Glasswing, announced in April 2026, brought together Amazon, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, Nvidia, Palo Alto Networks, and others on the premise that frontier AI models could fundamentally change how critical software is secured. Anthropic provided access to a preview of Claude Mythos, a model trained with enhanced capabilities for code analysis and vulnerability discovery.

The results have been dramatic and destabilizing. According to reporting from ProPublica, Microsoft engineers have been racing to patch exploits before the next batch of discoveries arrives. In one session in mid-May, dozens of Microsoft engineers and managers gathered at the company’s Redmond headquarters to discuss the findings from a single round of Glasswing analysis. The volume of critical vulnerabilities identified by Anthropic’s model has repeatedly outstripped the available engineering hours to fix them.

The dynamic creates an unusual pressure: the same AI tools that make software safer by finding bugs also reveal just how fragile the human-driven remediation pipeline is. Microsoft is not ignoring the findings; the company is working through them. But the throughput of human security engineers, constrained by code review cycles, regression testing, and deployment schedules, cannot match the output of a model that analyzes codebases at machine speed.

Instead of chasing clicks, we focus on delivering reliable information. Your support helps us stay on that path.

Help keep us independent

National security experts have been watching closely since Glasswing went public, anticipating exactly this scenario: AI discovery outpaces human patching, creating a window where known vulnerabilities exist without fixes. The traditional responsible disclosure model, built around a human researcher finding one bug at a time, was not designed for a world where AI finds hundreds.

The situation underscores a broader shift in cybersecurity. The bottleneck is no longer detection; it is remediation. And that is a problem that no model, however capable, has yet solved.

Sources: Ars Technica (Jul 29, 2026); ProPublica (Jul 29, 2026); Anthropic (Apr 7, 2026)

Scroll to Top