Where was Mythos when WordPress fell?

AI was hyped as the internet’s bodyguard, and commenters are now asking where it was when the big blog engine needed help most

TLDR: Anthropic hyped Mythos as a tool to help protect important open-source software, but critics noticed it seemingly missed a major WordPress flaw and questioned the flashy numbers. In the comments, people split between mocking the hype, defending the testing context, and jokingly asking what disaster they’d missed.

The real spectacle here isn’t just Anthropic’s giant claims about Mythos, the ultra-hyped AI bug hunter. It’s the community side-eye after those promises collided with a very awkward question: if this thing scanned 1,000 major open-source projects that “underpin much of the internet,” then why wasn’t it there for WordPress, the website builder powering a huge chunk of the web? One confused commenter basically walked in like a sitcom character asking, “Wait, WordPress fell?” and honestly, that set the mood perfectly: panic, confusion, and a lot of people trying to figure out whether the emperor has any clothes.

Then the debate got spicy. The article points out that Anthropic’s huge numbers were partly the model rating its own work, and commenters seized on that like sharks smelling blood. But not everyone joined the dunking. One reply pushed back hard, arguing people keep using curl as an anti-Mythos talking point without context, because curl had already been pounded by every scanner and test under the sun. Another commenter bristled at the idea that browsers somehow don’t count as “the real web,” basically saying, excuse me, browsers are the web. So now the drama isn’t just “Did Mythos overpromise?” It’s also “Are critics cherry-picking?”

The darkest punchline: even when AI does find problems, they still land on unpaid humans already drowning in work. So the comments read like a mix of meme energy, nitpicking, and a very modern suspicion that the loudest miracle in tech might have been mostly marketing with a cape on.

Key Points

  • The article says Anthropic claimed on 22 May that Mythos Preview had scanned more than 1,000 open-source projects and aimed to secure critical software.
  • It contrasts those claims with a pre-authentication remote code execution vulnerability in WordPress Core that was credited to Adam Kues of Searchlight Cyber, not Anthropic.
  • According to the article, Mythos Preview reported 23,019 total vulnerabilities, including 6,202 self-rated as high or critical, while 1,752 had been independently assessed and a little over 60% of that assessed subset held up as high or critical.
  • The article says the public disclosure record tied to Mythos amounted to roughly 40 CVEs, mostly in Firefox and wolfSSL, with no public examples involving PHP or CMS software.
  • It reports that Anthropic had sent around 530 high- or critical-severity bug reports to open-source maintainers, with 75 patched by the time of the cited update, and that some maintainers asked for slower disclosure because of overload.

Hottest takes

"What do you mean by WordPress fell? What did I miss?" — Brajeshwar
"How does one arrive at the idea that 'browsers' is a category less representative" — aleksejs
"People always cite CURL incorrectly in thier anti Mythos rants." — bluGill
Made with <3 by @siedrix and @shesho from CDMX. Powered by Forge&Hive.