Microsoft said Wednesday it will incorporate advanced artificial intelligence models, including Anthropic’s Claude Mythos Preview, into its secure coding framework as part of an effort to bolster its cybersecurity posture.
According to a Microsoft blog post, the company will embed these models within its Security Development Lifecycle (SDL). Microsoft said the move is intended to help find security flaws earlier during software development and to speed the creation of fixes once issues are identified.
Anthropic’s Claude Mythos Preview, which the company announced on April 7, has reportedly uncovered thousands of major vulnerabilities across operating systems, web browsers and other types of software. Experts cited in the original account note that Mythos’s capability to produce high-level code gives it a potentially unprecedented capacity to analyze systems and to identify ways security weaknesses might be exploited.
Anthropic has stated that the current Claude Mythos Preview will be rolled out first to a select group of companies under Project Glasswing. That initiative is described as a controlled program in which a handful of major technology firms, including Microsoft, Amazon.com (NASDAQ:AMZN) and Apple (NASDAQ:AAPL), will be able to use the model to search for cybersecurity vulnerabilities.
Microsoft reported that it tested Mythos using its own open-source benchmark focused on real-world detection engineering tasks. The company said the model produced substantial improvements when compared with earlier models on that benchmark.
At the same time, the arrival of Mythos has prompted attention from public- and private-sector actors. The article referenced that the Trump administration, central bankers worldwide and various industries are engaged in efforts to understand Mythos and its potential to make complex cyberattacks easier and quicker to carry out.
Context and implications
Microsoft frames the integration as a way to accelerate detection and remediation within its SDL, while Anthropic’s controlled deployment under Project Glasswing limits initial access to a small group of large technology companies. The model’s reported ability to find substantial numbers of vulnerabilities and to code at a high level has generated scrutiny from governments and industry stakeholders.