Claude Mythos Preview won’t break cybersecurity, but two new analyses shed light on how it is compressing exploit windows and exposing gaps in vulnerability management. CISOs should prepare for what’s ahead. Credit: Pixabay Over the past week, reaction to Anthropic’s Glasswing disclosure has split along familiar lines. At one end: alarm over an AI system capable of autonomously identifying and exploiting vulnerabilities. At the other: dismissive hot takes, arguing there is nothing new here. A more grounded view comes from a new briefing by the Cloud Security Alliance (CSA), led by Gadi Evron, CEO of Knostic and CISO-in-Residence for AI at the alliance; Rob T. Lee, chief AI officer and chief of research at SANS Institute; and Rich Mogull, chief analyst at CSA. The paper draws on a deep bench of contributors, including former CISA Director Jen Easterly, Bruce Schneier, former National Cyber Director Chris Inglis, and former Google CISO Phil Venables, along with dozens of CISOs and CEOs. Evron told CSO that assembling that level of input among so many leaders so quickly reflects the nature of cybersecurity itself: “The cybersecurity industry is also a community, and knowing each other, all folks need to have is a good cause, and dispelling noise and spreading good information matters to us.” The group’s conclusion is direct: Glasswing is not an outlier. It is an early example of a capability that will scale, and CISOs should start getting ready for this era. “In the near term, security organizations will likely be overwhelmed by the need to apply patches and respond to AI-discovered vulnerabilities, exploits, and autonomous attacks,” the paper states. “The storm of vulnerability disclosures from Project Glasswing is the first of many large waves.” The shift is speed AI-driven vulnerability discovery is not new. What has changed is speed. Tasks that