Histoire
juillet 30, 2026
Anthropic’s AI is finding security holes faster than defenders can close them
Anthropic's AI security model, Mythos, has discovered significant weaknesses in cryptographic systems, including the HAWK digital signature scheme, which was subsequently withdrawn from consideration as a US standard. The model is reportedly finding bugs in Microsoft's software faster than the company can patch them, raising concerns about the speed of AI-driven vulnerability discovery.
Anthropic’s latest security AI is forcing an ugly question into the open: what happens when machines can discover critical flaws faster than the people responsible for fixing them? The early answer, judging by fresh reporting on cryptography and Microsoft’s internal scramble, is that defenders may be entering a race they can’t comfortably win.
The clearest warning sign came from cryptography. Anthropic’s Mythos helped uncover a fatal weakness in HAWK, a post-quantum digital signature candidate that had already survived multiple rounds of NIST scrutiny before being pulled from consideration.1 That does not mean today’s core encryption has suddenly collapsed. Ars Technica notes the results are incremental, tested on weakened challenge instances, and do not break production cryptosystems currently in use.1 Still, the symbolism is hard to ignore: a scheme designed for the quantum era was knocked out after years of human review missed what an AI-assisted approach surfaced.1
Then there is the software side, where the pace looks even more alarming. According to Ars Technica’s reporting on Microsoft’s internal response, engineers were dealing with a model that was “surfacing bugs faster than the tech giant could patch them,” turning remediation into “a mad dash.”2 One internal presentation reportedly showed Mythos finding 90 critical and 141 important SharePoint bugs in a single month.2 The fear inside the room was blunt: once comparable tools spread, adversaries could quickly inherit the same map of weaknesses.2
Put together, the two episodes point to the same tension. Optimists will say this is exactly what defensive AI is for: find the cracks first, patch them, and harden systems before attackers catch up.2 Skeptics will counter that the bottleneck is no longer discovery but human capacity — triage, repair, validation, rollout.2 If Mythos is a preview of that future, the uncomfortable truth is not that AI can break everything today. It’s that it may already be accelerating vulnerability discovery faster than institutions can respond.12