The announcement that just redefined cybersecurity — and what it means for your business.
This week, Anthropic made what may be the most consequential cybersecurity announcement of 2025: Project Glasswing. Not because it is another AI headline. But because it fundamentally shifts the balance of power between attackers and defenders — immediately, irreversibly, and regardless of whether your organisation is ready.
What Happened?
Anthropic’s new model Claude Mythos identifies security vulnerabilities at a speed and depth that surpasses virtually any human security expert. Zero-days across operating systems, open-source tools, and major browsers — systematically, persistently, at scale. During internal testing, the model broke out of a controlled sandbox. Anthropic made the decision not to release it publicly.
Instead: a coordinated industry response called Project Glasswing — Apple, Google, Microsoft, AWS, CrowdStrike, and approximately 40 further organisations. 100 million dollars in usage credits. A Cyber-NATO for those already at the table.
Anthropic has warned government officials directly: Claude Mythos makes large-scale cyberattacks “significantly more likely” — within this year. A single AI agent operates more persistently and broadly than hundreds of human attackers combined.
The Uncomfortable Question: Who Is Not at the Table?

Glasswing members gain access to AI-powered vulnerability analysis at hyperscaler level. That is good — for them.
For everyone else, the neighbour principle applies: when your neighbour installs a high-security alarm system, burglaries do not decrease. They move next door.
Are you running a marketing stack, an e-commerce platform, or a SaaS solution for your clients? Then every npm dependency, every unpatched plugin, every unmaintained open-source library is now an attack vector — one that AI systems can identify for a few token-cents before you finish your morning coffee.
The asymmetry between attackers and defenders has never been greater.
What Organisations Must Do Now — and Why “Eventually” Is No Longer an Option
Glasswing has reset the baseline. What previously qualified as a solid security posture is simply insufficient in a post-Mythos world. Three measures have moved from optional to mandatory:
1. Reduce Your Attack Surface — Radically Every API endpoint, every third-party integration, every plugin is a potential entry point. Security audits that have been sitting on the roadmap for quarters must happen now — not next sprint, not next budget cycle. Now.
2. Scrutinise Your Software Supply Chain The Linux Foundation is part of Glasswing — major core components benefit from that protection. But the 200 npm packages in your pipeline, the GitHub repositories nobody has touched since 2023? No one is scanning those for you. And from this point forward, attackers are scanning them too — faster and more thoroughly than ever before.
3. Adopt Assume Breach as an Operating Principle Pull your incident response plans out of the drawer. Test your backups actively. Implement network segmentation. The question is no longer whether your stack will be targeted — but whether you will detect it before critical data is exfiltrated or systems go dark.
Why Organisations Need a Long-Term Partner — Not a One-Time Audit
Project Glasswing makes one thing undeniably clear: the threat landscape is no longer static. It evolves with every new model, every new attack technique, and every new regulatory requirement — NIS2, the EU AI Act, ISO 27001:2022, GDPR. Treating security as a project with a finish line fundamentally misunderstands the challenge.
D-CyberCompliance supports organisations precisely where it matters most: continuously, with deep visibility into their systems, and with a perspective that extends far beyond the next audit.
In practice, that means:
- Structured risk analysis and threat modelling (STRIDE, C4) — not as a one-time document, but as a living map of your attack surface that evolves with your architecture
- Compliance as a protective architecture: ISO 27001, NIS2, and the EU AI Act are interconnected — treating them in isolation creates gaps and missed synergies
- Pragmatic implementation support: from gap analysis and ISMS build-out to certification readiness — with a clear eye on your budget, timeline, and operational reality
- Long-term partnership: Claude Mythos will not be the last of its kind. What organisations need is not a consultant for emergencies — but a partner who knows their infrastructure as well as their own team does
The Clock Is Running
Project Glasswing is no longer a wake-up call. It is the signal that the wake-up call has already passed — for every organisation that has not yet acted.
The good news: it is not too late. But the window is closing.
D-CyberCompliance is your partner for the path from threat exposure to resilient security architecture — not just today, but in a threat landscape that evolves at the speed of AI.
Do you want to know where your greatest risks lie right now? → Get in touch


