The World Changed, Whether You Like It or Not: The Cybersecurity Revolution

The World Changed, Whether You Like It or Not: The Cybersecurity Revolution

From speculation to hard data: what Project Glasswing revealed in just two months about the future of cybersecurity.

It was in April of this year when the cybersecurity world started talking about Claude Mythos, an LLM capable of identifying zero-day vulnerabilities at a speed never seen before. At first, many of us saw it as pure marketing: another "revolutionary product," another campaign designed to sell hype.

But in that same announcement, Anthropic made a decision few companies would dare make: not releasing Mythos to the public, precisely because of the risk it would pose in the wrong hands. Marketing dressed up as responsibility, or a real warning about what was coming? Many dismissed it as overblown. The following months proved the skeptics wrong.

When theory became a number

By May, Project Glasswing — the coalition bringing together nearly 50 organizations, including AWS, Apple, Microsoft, Google, Cisco, CrowdStrike, and Palo Alto Networks, using Mythos to harden the world's most critical software — published its first progress report. The numbers spoke for themselves:

Note: Glasswing partners found more than 10,000 critical or high-severity vulnerabilities in software of global systemic importance. Separately, by scanning over 1,000 open-source projects, Mythos identified 23,019 flaws — many of them decades-old bugs no human had ever detected.

Anthropic didn't stop at just "finding" the problem. It also launched Claude Security in public beta to tackle the other half of the challenge: patching everything being discovered. In just three weeks, this tool helped fix more than 2,100 vulnerabilities. The bottleneck in cybersecurity stopped being "how do we find the bugs?" and became "how fast can we verify and patch them before someone else finds them first?"

By June, the coalition had already expanded to 150 organizations across more than 15 countries, covering critical infrastructure sectors — energy, water, healthcare, communications — where a single flaw can affect hundreds of millions of people. And as you'd expect in any tech race, the competition didn't sit still either: OpenAI responded with its own cybersecurity-focused model.

The board changed — and this part is my own take

With all this, in my opinion, there's nothing left to do but accept it: in a matter of months, the world changed, and resistance is no longer an option. I believe traditional cybersecurity tools are becoming obsolete at a speed we hadn't seen before, and that threats are scaling far beyond any calculation we would have made a year ago.

Careful, though — this doesn't mean Claude Mythos is in just anyone's hands. Quite the opposite: it remains restricted to a controlled group of partners, precisely to keep it from falling into the wrong hands. But it is true that general-access AI models (not Mythos) are already lowering the barrier to finding simpler vulnerabilities, and that democratizes both defense and offense. That combination — cutting-edge tools restricted at the top, accessible tools at the bottom — is, to me, the real turning point.

My personal takeaway: an annual risk assessment is no longer enough — I believe that model has stopped being effective. Today, in my view, risk should be measured almost daily. The world changed, and our protection strategies have to change with it, whether we like it or not.

Fear of change is no longer an option. The world changed, whether you accept it or not.

So was all that preparation wasted?

No. Quite the opposite.

Cybersecurity as a discipline is now more relevant than ever, and the experience of those who've been in this field for years is worth more than ever. For the first time, we have something we used to lack: genuinely powerful tools to minimize risk at a scale that, a year ago, was science fiction. Anthropic even created a Cyber Verification Program so certified security professionals can use these models with fewer restrictions for legitimate work — the door for experts is opening, not closing.

We have a future ahead full of more threats and more zero-day attacks than in all of prior history combined. But, in my opinion, that same future also gives us the chance to adapt, evolve, and defend cyberspace with tools humanity had never had before.

The revolution has already begun. The question is no longer whether you're going to change — it's whether you're going to fall behind while everyone else moves forward.


Sources: Project Glasswing — Initial Update (Anthropic)

Autor: Edu Quijano

The World Changed, Whether You Like It or Not: The Cybersecurity Revolution · Café Hacking