Anthropic announced on 7 April 2026 that its latest AI model, Claude Mythos Preview, had identified thousands of previously unknown vulnerabilities across every major operating system and every major web browser. Some of these flaws had been sitting undetected for decades. Anthropic isn't releasing Mythos to the public. Instead, it launched Project Glasswing, a consortium of 12 companies, including Apple, Microsoft, Google, and CrowdStrike, who get advance access to the findings. Everyone else, including the millions of businesses whose websites run on that software, will have to wait for patches to trickle down.
If your WordPress site sits on a Linux server and your customers browse with Chrome, Safari, or Firefox, those systems now have known vulnerabilities that a sufficiently capable AI model can find and exploit. The companies who build that software got advance warning. You didn't.
What Mythos Actually Found
The numbers are striking. In a matter of weeks, Mythos identified thousands of zero-day vulnerabilities, flaws that had been invisible to both human researchers and automated scanning tools. TechCrunch reported that the model found a 27-year-old remote crash vulnerability in OpenBSD, one of the most security-hardened systems in existence. It found a 16-year-old flaw in FFmpeg, the video library used by virtually every media application on the planet. Automated testing tools had hit that same code path five million times without catching it.
On the CyberGym benchmark for vulnerability reproduction, Mythos scored 83.1%, compared to 66.6% for Claude Opus 4.6. What sets it apart from previous AI security tools is its ability to chain individually minor flaws into exploitable attack sequences. In one test, it linked multiple Linux kernel vulnerabilities to escalate privileges from an ordinary user to full system control.
"AI capabilities have crossed a threshold that fundamentally changes the urgency required to protect critical infrastructure from cyber threats, and there is no going back."
Anthony Grieco, SVP & Chief Security Officer, Cisco (via Project Glasswing announcement)
Anthropic's own team is candid about why Mythos isn't going public. Logan Graham, speaking about the decision to restrict access, put it simply: "We are not confident that everybody should have access right now." That's not marketing caution. That's an AI lab telling you their model is too dangerous to hand out.
We run security scans on every client site we manage. The same classes of vulnerability Mythos is finding in operating systems and browsers exist in WordPress plugins, in PHP extensions, in the server configurations that underpin every hosted site. When Google's threat intelligence team reported that AI-powered malware was making live API calls during attacks back in February, that was a warning shot. Mythos is the confirmation: AI has permanently changed the speed of both offence and defence in cybersecurity.
The Two-Tier Security Gap
Glasswing's launch partners read like a who's who of big tech: Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks. Over 40 additional organisations that maintain critical software infrastructure also get access. Anthropic is committing $100 million in model usage credits and $4 million to open-source security foundations.
"The opportunity to use AI responsibly to improve security and reduce risk at scale is unprecedented."
Igor Tsyganskiy, EVP Cybersecurity, Microsoft (via Project Glasswing announcement)
That's a reasonable approach for securing the software that runs the internet. But it creates an information gap. When Apple gets advance notice of a Safari zero-day, it can prepare a patch before attackers know the flaw exists. When a UK plumber running WordPress on shared hosting learns about it, the patch has already shipped and they're just hoping their server applied it. If they're on managed WordPress hosting, it probably did. If they're self-managing on budget hosting, it probably didn't.
This gap is going to widen. 365i covered the political backdrop to Anthropic's AI capabilities back in February. What's different now is that we have concrete evidence of what these models can do. Thousands of zero-days. Decades-old flaws. Found in weeks. The speed at which vulnerabilities can be discovered, and by extension exploited, has changed permanently.
What This Means for Your WordPress Site
The same week Anthropic announced Mythos, attackers compromised the update infrastructure for Smart Slider 3 Pro, a WordPress plugin with 800,000 active installations. They pushed a backdoored update through the official channel. It was live for six hours before detection. Sites that auto-updated received a multi-layered persistence toolkit that created rogue admin accounts, exfiltrated credentials, and installed redundant backdoors that survived plugin deletion.
These two events aren't directly connected, but they point to the same problem. The software stack your website depends on contains vulnerabilities. The people finding them, whether they're working for a safety-focused AI lab or a criminal operation, are getting faster. The window between a vulnerability being discovered and being exploited is compressing. And for small businesses without dedicated security teams, the margin for error is shrinking.
If you run a WordPress site, the practical response hasn't changed, but the urgency has:
- Update everything now. WordPress core, every plugin, every theme. Don't wait for the weekend. The WordPress security checklist we published in March covers the full process.
- Check your hosting. Is your server running a supported PHP version? Does your host apply OS-level patches automatically? Test your site's security posture in 30 seconds with the free 365i scanner.
- Audit your plugins. Every active plugin is an attack surface. If you installed something two years ago and haven't thought about it since, scan your site and review what's running.
- Consider a maintenance plan. A managed WordPress support plan means someone is watching your site's security posture, vetting updates before they're applied, and responding to incidents before you know they've happened.
The AI security arms race is here. For the companies in the Glasswing consortium, it's a controlled advantage. For the rest of us, it's a reminder that the basics, keeping your software up to date, choosing a host that patches its servers, and having someone who knows what they're looking at on the other end, have never mattered more.
Frequently Asked Questions
What is Claude Mythos and what did it find?
Claude Mythos Preview is Anthropic's most capable AI model to date. In security testing over several weeks, it identified thousands of previously unknown (zero-day) vulnerabilities across every major operating system and web browser, including flaws that had gone undetected for up to 27 years. It can also chain individually minor flaws into full exploit sequences.
What is Project Glasswing?
Project Glasswing is a cybersecurity consortium launched by Anthropic alongside the Mythos announcement. It gives 12 major technology companies (including Apple, Microsoft, Google, and CrowdStrike) early access to the model to find and fix vulnerabilities in critical software. Over 40 additional organisations maintaining critical infrastructure also receive access.
Does this affect my WordPress website?
Yes. Your WordPress site runs on a server operating system (typically Linux) and your visitors use the browsers where these zero-days were found. Any unpatched vulnerability in your server stack, PHP version, or the browsers accessing your site is a potential attack vector. The WordPress plugin ecosystem adds its own layer of supply chain risk, as the Smart Slider 3 Pro incident from the same week demonstrated.
Will small businesses get access to Claude Mythos?
Not directly. Anthropic has stated that Mythos Preview will not become generally available because its exploit capabilities are too powerful to release broadly. The findings flow downstream as patches from affected software vendors, but small businesses won't get the same advance warning that consortium members receive.
How quickly will patches reach my website?
That depends on the software vendor and your hosting provider. Consortium partners get advance notice to prepare patches. Those patches then flow through normal vendor update channels. Managed WordPress hosts apply server-level patches promptly. Self-managed servers rely on the site owner to update manually, which creates a lag that attackers can exploit.
What should I do right now to protect my WordPress site?
Update WordPress core, all plugins, and all themes immediately. Confirm your hosting provider runs a supported PHP version (8.2 or later). Review your active plugins and remove anything you don't use. Run a security scan. If you aren't confident managing this yourself, a managed WordPress maintenance plan handles the ongoing security for you.
How does managed WordPress hosting help with this?
Managed WordPress hosts maintain the full server stack (OS, PHP, web server, database) and apply security patches as they ship. They monitor for suspicious activity, can isolate compromised sites quickly, and respond to incidents before most site owners know there's a problem. As AI accelerates vulnerability discovery on both sides, having a professional team managing your infrastructure becomes less of a luxury and more of a necessity.
Concerned About Your WordPress Site's Security?
From plugin audits to server hardening, we help UK businesses lock down their WordPress sites against the threats that matter. Talk to us before you find out the hard way.
WordPress Security ServicesPublished: 13 April 2026 · Last reviewed: 14 April 2026 · Written by: Mark McNeece, Founder & Lead Developer, Press Forge
Editorially reviewed by: Mark McNeece on 14 April 2026 · Our editorial standards
Sources
- Project Glasswing: Securing critical software for the AI era - Anthropic (7 April 2026)
- Anthropic debuts preview of powerful new AI model Mythos in new cybersecurity initiative - TechCrunch (7 April 2026)
- Fail Safe: Why Anthropic won't release its new AI model - RTE (12 April 2026)
- Critical Supply Chain Compromise in Smart Slider 3 Pro: Full Malware Analysis - Patchstack (April 2026)
- Anthropic is giving some firms early access to Claude Mythos to bolster cybersecurity defenses - Fortune (7 April 2026)