Anthropic’s Mythos Finds SharePoint Bugs Faster Than Microsoft Can Fix Them: The Five Eyes Alert
Anthropic's Mythos AI finds SharePoint vulnerabilities faster than Microsoft can patch them, prompting a Five Eyes intelligence alert.
Illustrative image generated with AI
Introduction
On July 29, 2026, details emerged of unprecedented activity in the cybersecurity world: the artificial intelligence model Mythos (Claude Mythos Preview), developed by Anthropic and distributed to a restricted number of organizations under Project Glasswing, is finding vulnerabilities in Microsoft products – particularly SharePoint – at a pace that outstrips the remediation capacity of the Redmond giant. In April alone Mythos uncovered 90 critical and 141 important bugs; the first half of May saw even higher numbers. The situation pushed Microsoft to set a May 31 deadline to close the gap before similar technologies became globally available. The alert was then amplified by the Five Eyes intelligence coalition (US, Australia, Canada, New Zealand, UK) at the end of June, which warned that the window for patching is closing and the risk of immediate exploitation is real.
Technical Analysis
Mythos is an artificial intelligence capable of performing static analysis, dynamic analysis and large-scale fuzzing, identifying vulnerability patterns at speeds unattainable by human teams. The most critical element is its ability to chain medium- and low-severity bugs to create high-impact exploit chains – combinations that, individually considered minor, can lead to full compromise, data exfiltration or sabotage.
Microsoft classifies flaws as critical (worm, automatic propagation, system crash) and important (compromise of confidentiality, integrity or availability). The company’s triage strategy prioritises these two categories, deferring moderate ones and not even mentioning low-severity issues in urgent plans. But Mythos’ chaining capability calls this approach into question: apparently innocuous weaknesses become levers for devastating attacks.
The Project Glasswing revelations indicate that Anthropic granted early access to trusted partners precisely to test the technology in real-world settings; this means similar capabilities could already be in the arsenal of hostile actors, as highlighted by the Five Eyes advisory.
Impact
SharePoint is adopted by governments, banks and large enterprises for collaboration and document management. Mass exploitation could translate into espionage, sabotage and disruption of essential services. The speed of Mythos’ discovery reduces the window for patching: while Microsoft races to release fixes, attackers may already have similar automated tools at their disposal.
The mid-May internal meeting, where engineers described a “mad dash” to respond, and the May 31 deadline, show how critical the time gap is perceived to be. If adversarial nations possess analogous AIs, the current defense model, based on severity triage, may no longer hold.
Mitigation
Organizations using SharePoint and other Microsoft products must act immediately:
- Apply all security patches as soon as they are released, prioritising critical and important ones, but not neglecting moderate ones if they can be exploited in a chain.
- Monitor official channels for out-of-band updates, which may arrive in response to the emergency.
- Adopt layered defenses:
- Network segmentation to isolate SharePoint servers and limit lateral movement.
- Behavioral monitoring and IDS/IPS systems to detect anomalous exploits.
- System hardening (disabling unnecessary services, strict access control, updating components).
- Review patch management processes by integrating risk assessments that consider bug chaining.
- Include adversarial AI scenarios in corporate threat modelling, preparing incident responses where the attacker leverages Mythos-like capabilities.
The situation demands a paradigm shift: AI-driven automation is redesigning the timelines and methods of cybersecurity, and standing still is tantamount to exposure.
FAQ
1. What is Mythos and how does it manage to find so many vulnerabilities?
Mythos is an advanced artificial intelligence model from Anthropic, part of the Claude family, provided in preview to selected partners through Project Glasswing. It works by analyzing code and binaries with machine learning, reverse engineering and automated fuzzing, scanning software around the clock at a speed and depth unattainable manually. Its distinctive strength is the ability to link apparently minor weaknesses to build complex attacks.
2. Why can’t Microsoft keep pace with fixes?
Developing a patch requires analysis, design, testing and distribution: a process that cannot be compressed beyond certain limits. Faced with hundreds of bugs found in a few weeks, the team is under extreme pressure. Moreover, the automatic discovery of moderate vulnerabilities changes traditional priorities, forcing a rethink of which bugs to fix first.
3. My company uses SharePoint only internally: what precautions should I take?
Even on an apparently isolated intranet, an attacker who penetrates the network (e.g., via phishing or compromised VPN) could exploit exploit chains to reach SharePoint servers and cause data theft, sabotage or ransomware. It is essential to segment the network, activate behavioral monitoring and apply all patches with maximum urgency – because physical isolation is no longer enough.
Sources
This article is an original reworking based on the sources below.




