Microsoft Struggling With Hundreds of AI-Discovered Security Bugs — ProPublica
Arrow Right
Caret
Close
Search ProPublica Search Close<br>ProPublica is a nonprofit, investigative newsroom that exposes<br>corruption. We report in all 50 states and partner with local newsrooms. Our work spurs real-world impact and has received numerous awards, including nine Pulitzer Prizes.
Topics We Cover<br>See All<br>Abortion<br>Civil Rights<br>Courts<br>Criminal Justice<br>Debt<br>Democracy<br>Education<br>Environment<br>Health Care<br>Health Insurance<br>Immigration<br>Labor<br>Mental Health<br>Military<br>Police<br>Politics<br>Pregnancy<br>Prison<br>Racial Justice<br>Regulation<br>Sex and Gender<br>Technology
Our Biggest Series<br>See All<br>Life of the Mother<br>How Abortion Bans Lead to Preventable Deaths
The New Immigration<br>How Recent Arrivals at the Border Have Changed the Country and Its Attitudes
Friends of the Court<br>SCOTUS Justices’ Beneficial Relationships With Billionaire Donors
ProPublica is a nonprofit newsroom that investigates abuses of power. Sign up to receive our biggest stories as soon as they’re published.
On an afternoon in mid-May, dozens of Microsoft engineers and their managers gathered online and in a conference room at the company’s Redmond, Washington, headquarters to discuss Project Glasswing.
The tech giant was racing to fix weaknesses in its code that a new AI model known as Mythos was uncovering at an unprecedented clip. The AI behemoth Anthropic, which developed Mythos, had given access to select organizations that make software used by regular people, companies and governments across the world. The goal was to find and fix the vulnerabilities before hackers and adversarial governments like China began using similar tools to find and exploit them for espionage and sabotage.
As the group settled in, one engineer asked the question that loomed over the meeting: Did Mythos “live up to the hype that Anthropic claimed it would have had?”
“Yes,” a manager responded, according to a recording of the meeting viewed by ProPublica.
The version being used by Microsoft, Claude Mythos Preview, was surfacing bugs faster than the tech giant could patch them, and engineers, the manager said, were now in "a mad dash" to close the gap.
One slide in that day’s presentation showed that in April alone, Mythos had uncovered 90 “critical” bugs and 141 “important” ones in SharePoint, Microsoft’s widely used collaboration software. In the first half of May it found even more.
“Please, please, please if your org has any April bugs, drive those down,” engineering manager Hans Andersen implored the group. They had roughly two weeks “to find as many things and do as much good as we can with this access.”
May 31, he explained, “is considered the day when the rest of the world will have caught up.”
The engineers on the call poked at that assertion, with one of them summing up the predicament: “So basically you’re saying if it’s released on June 1, then on June 2 the adversaries will have our bugs?”
Yep, one person responded. Yep, another echoed.
Do You Know More About the AI Arms Race?
We’re still reporting. If you know more about AI and the tech industry, please contact our reporting team.
Renee Dudley
I’m interested in the intersection of Big Tech and national security. If you’ve worked in tech or government, or otherwise have tips about this area, please get in touch.
Contact Me
Ever since Anthropic kick-started a national conversation about the bug-hunting power of AI in April, when Project Glasswing was made public, national security experts predicted that the U.S. would have a window of opportunity to fix flaws before adversaries would have similar models capable of discovering the same weaknesses. In late June, the international alliance of intelligence agencies known as the Five Eyes — whose members are the U.S., Australia, Canada, New Zealand and the U.K. — warned in an unusual joint statement that in a matter of months, that window would be closing. But the recording of the Microsoft meeting, along with internal documents reviewed by ProPublica, suggest the day of cyber reckoning may already be here.
Given the deluge of flaws Mythos has identified, Microsoft so far has focused on patching those it considers most dangerous, which are classified critical or important, according to the presentation as well as the company’s own public patch updates. The internal records indicate that Microsoft plans to eventually address “moderate”-severity flaws uncovered by Mythos. The documents made no mention of “low”-severity bugs.
The company’s approach reflects the triage system that is typical in the industry. Just as the sickest patients are the first to be treated in the emergency room, vulnerability triage prioritizes issues that are likely to cause the most damage if exploited by hackers.
But that strategy carries its own risk in this AI-powered bug-finding era, in which new tools are unearthing a record-breaking volume of weaknesses in the products we use every day....