- Microsoft's Project Glasswing used Anthropic's AI model Mythos to uncover a record number of vulnerabilities in its software, including 90 critical and 141 important bugs in SharePoint in April 2024 alone.
- Engineers were in a 'mad dash' to patch flaws before adversaries could exploit them, with a May 31 deadline marking when the rest of the world would have similar AI capabilities.
- The Five Eyes intelligence alliance warned in June 2024 that the window to fix vulnerabilities before adversaries use similar AI tools is closing within months.
- Microsoft prioritizes patching critical and important bugs first, but AI can chain low-severity flaws into high-severity attacks, raising concerns about the triage strategy.
- Internal records show Microsoft planned months of work on SharePoint bugs, starting with critical ones in mid-May and moving to moderate ones later, with most critical and important bugs unpatched as of mid-May.
- Microsoft's Patch Tuesday record was broken in July 2024 with over 600 patches, signaling a 'bug apocalypse' driven by AI.
- Former NSA AI chief Vinh Nguyen advised companies to rethink triage, dedicating staff to patch all vulnerabilities due to AI chaining capabilities.
- The software industry faces challenges from 'technical debt' in legacy code and understaffed security teams, with open-source software also at risk.
- Microsoft's internal security response center is understaffed, reflecting a corporate philosophy prioritizing profit-making products over cost-center security patches.