ProPublica obtained a recording of Microsoft engineers describing a 'mad dash' to patch AI discovered SharePoint vulnerabilities before a May 31 cutoff Microsoft internally tied to the expected arrival of the AI's capabilities in adversarial hands.
In April, an Anthropic-built AI model the company calls Mythos surfaced 90 "critical" and 141 "important" vulnerabilities inside Microsoft SharePoint in a single month, according to a ProPublica investigation. By mid-May the count had climbed higher. Microsoft engineering manager Hans Andersen told colleagues the next two months would be a "mad dash" to triage and patch them. The deadline, May 31, was not Microsoft's to set. It was the day the company internally assumed Mythos-class capability would be in adversarial hands.
A recording of an internal Microsoft meeting, obtained by ProPublica, captures the scale of the race. SharePoint, the file-sharing and collaboration backbone of Microsoft 365 used across most Fortune 500 IT departments, became the proving ground for what Anthropic calls Project Glasswing: a pre-release arrangement under which frontier AI models are handed to software vendors to find vulnerabilities before those same models, or ones like them, reach the open internet. One engineer, in the recording reviewed by ProPublica, put the strategic predicament in plain terms: "So basically you're saying if it's released on June 1, then on June 2 the adversaries will have our bugs?"
That is the new clock defenders are racing against. Anthropic's Project Glasswing program page frames the arrangement as responsible pre-release access for defenders. The company's initial research update describes the work as a way to find and disclose vulnerabilities to vendors ahead of broader model availability. For Microsoft, the model is now a fixture of its security calendar. For the rest of the software industry, the question is whether the May 31 dynamic, with its fixed handover date and patch treadmill measured in days rather than weeks, has become the new normal.
Microsoft's public posture arrived in May in the form of a note on Patch Tuesday from the Microsoft Security Response Center. The post acknowledged the situation without naming Anthropic or the model. The implicit message: a single vendor's patching cadence is now a function of an external laboratory's discovery rate, and the math has changed. The MSRC note states the terms. It does not resolve them.
Outside Microsoft, the cadence is being watched at the level of national cyber agencies. In the same period, the Five Eyes cyber security agencies, the United States, the United Kingdom, Canada, Australia, and New Zealand, issued a joint statement flagging AI-enabled vulnerability discovery as a shared security concern. The statement is not a direct response to Project Glasswing. It is contemporaneous framing for a category of risk that Glasswing, in one corner of one vendor's product line, has now made visible.
The arithmetic in the recording is the part that travels. Ninety critical and 141 important bugs in one product, in one month, from a single model: these are not figures a human red team would generate. They are figures a frontier model produces when it is pointed at a large surface and given time, according to the ProPublica investigation. The defenders in the meeting are not falling behind because they are slow. They are falling behind because the rate at which findings arrive now exceeds the rate at which any single software vendor can triage, fix, test, and ship patches through its existing release engineering.
The "mad dash" was the workaround. The longer question is what replaces it. Microsoft's MSRC note suggests the company is reorganizing around AI-driven discovery, but does not commit to a specific throughput. Anthropic's Glasswing page describes responsible pre-release access, but does not specify how many vendors are in the program, what the model finds that human review would have missed, or how the cutoff date is chosen. The Five Eyes statement names the concern but does not set a disclosure-window norm.
The next test is dated, not hypothetical. If a Mythos-class model is generally available in June, whether the SharePoint-class bugs already disclosed to Microsoft represent the difference between an espionage race defenders can run and one they cannot is the question the recording poses. The 231 April findings are the floor of what is coming. The May 31 cutoff was the day Microsoft's internal clock stopped. The external one has just started.