What Anthropic’s Project Glasswing and the discovery of 10,000 critical vulnerabilities means for entrepreneurs who thought cybersecurity was someone else’s problem
I have to confess something.
For most of my entrepreneurial life, I treated cybersecurity the way I suspect most of you do: as an IT problem. Something you hand to the person who knows about computers. Something you satisfy by having a password manager and hoping you are not interesting enough to be a target.
I was wrong. And the events of this week made that clearer to me than anything has before.
On June 2-3, 2026, Anthropic — the company that makes Claude — announced the expansion of Project Glasswing, a controlled program deploying an unreleased AI frontier model called Claude Mythos Preview to 150 organizations across 15 countries. The model has demonstrated the ability to identify and exploit software vulnerabilities at a level that surpasses all but the most skilled human hackers. Since the program’s launch, Glasswing partners have surfaced more than 10,000 high or critical-level security flaws.
Partners include NATO, the EU’s cybersecurity agency ENISA, Apple, Nvidia, Samsung, and Microsoft.
These are not organizations that lack resources for security. They are the most security-conscious organizations on the planet. And they still had 10,000 critical vulnerabilities.
Let that settle before you read any further.
Key Takeaways
- Anthropic’s Claude Mythos Preview has demonstrated the ability to find and exploit software vulnerabilities beyond the skill of elite human hackers — and it is real, deployed, and operational.
- Project Glasswing partners surfaced more than 10,000 high or critical security flaws since launch, including within organizations like NATO, Apple, and Nvidia.
- The program is now expanding to power, water, healthcare, communications, and hardware sectors — industries previously underrepresented in the first phase.
- Small businesses face a 49% annual cyberattack rate, with a 340% surge in AI-powered attacks and average losses of $254,000 per breach.
- AI-generated phishing achieves open rates 5-6x higher than traditional attacks at 95% lower production cost — meaning the economics of attacking your business just dramatically improved for attackers.
The Shift I Did Not Want to See
Here is what changed for me when I read the Glasswing announcement.
For years, the mental model of “cybersecurity for small business” has been human attackers acting with limited speed and scale. Phishing emails that contain typos. Social engineering attempts that are slightly off. Password guessing that takes time. Ransom demands with obvious grammar errors.
That model produced a playbook that most small business owners recognize: use strong unique passwords, enable two-factor authentication, keep your software updated, train your team to spot obvious phishing. That playbook is not wrong. It is just no longer sufficient.
When AI can generate phishing content that is indistinguishable from legitimate communication at 95% lower cost and achieves open rates five to six times higher than traditional attacks — the detection skills your team has been building are no longer adequate on their own.
When AI can autonomously identify zero-day vulnerabilities — flaws in software that have never been publicly disclosed and for which no patch exists — in your tools and integrations — the “keep software updated” advice, while still correct, no longer protects against the unknown attack surface.
The 340% surge in AI-powered attacks against small businesses is not a prediction. It is 2025-2026 data from organizations that monitor these things. 62% of small businesses faced AI-driven attacks in 2025. The number for 2026 is expected to be higher.
What Project Glasswing Actually Tells Us
I want to be precise about what Anthropic built and what they chose not to do with it.
Claude Mythos Preview is not a product you can subscribe to. It is a frontier AI model that Anthropic determined was too powerful to release publicly without safeguards — because a model capable of finding and exploiting zero-day vulnerabilities at this level could be catastrophically dangerous in the wrong hands.
So they built a controlled program. They partnered with the US government, NATO, open-source software maintainers, and vetted private sector organizations. They deployed the model only where its output — vulnerability discovery — would be used defensively. And they documented the results.
The results were unambiguous: thousands of critical flaws across organizations with dedicated security teams, significant budgets, and rigorous processes.
The implication for the rest of us is direct. If organizations with all of those resources had 10,000 critical vulnerabilities, what does the vulnerability profile of a small business with no dedicated security staff actually look like?
I do not ask that to create panic. I ask it to create honesty.
The Asymmetry That Makes This Hard
Cybersecurity has always had a fundamental asymmetry: defenders have to find every vulnerability. Attackers only have to find one.
AI makes this asymmetry worse before it makes it better.
The defenders who have early access to AI-powered vulnerability detection — the organizations in Glasswing’s program — are getting significantly safer. The defenders who do not have access yet remain exposed to attackers who are already using AI offensively.
Anthropic chose to expand Glasswing’s second phase specifically to critical infrastructure — power, water, healthcare, communications, and hardware — because those sectors were underrepresented in the first phase. The implication: the sectors with the highest potential societal impact had not yet been audited. That work is starting now.
Small business is not critical infrastructure in the national security sense. But it is critical to the people who own it, employ people through it, and serve customers with it. And the resources available to defend it are a fraction of what NATO and Apple can deploy.
What This Means Practically
I want to give you a few specific things to think about, not a generic checklist.
Your most vulnerable surface is your inbox. AI-generated phishing is now functionally indistinguishable from legitimate communication. The detection skills your team has — watching for urgency, odd formatting, suspicious links — are not enough when the attack is well-crafted. You need technical defenses — email filtering, link inspection, attachment scanning — not just human vigilance.
Your second most vulnerable surface is your integrations. Every third-party tool that has access to your data is a potential attack vector. The point is not to stop using integrations. The point is to know which ones have access to what, so you can monitor them and reduce unnecessary access.
Your most likely incident is ransomware. 88% of small business breaches include ransomware, compared to 39% for large organizations. The cost is not just the ransom. It is downtime, data recovery, and reputational damage — adding up to an average of $254,000 per incident. 60% of companies attacked close within six months.
The response plan matters as much as the prevention. Most small businesses do not have a documented incident response plan. When an attack happens — and statistically, the probability is significant — the first 24 hours determine most of the outcome. What do you shut down first? Who do you call? How do you communicate with customers? Those decisions should be made before the incident, not during it.
Practical Steps
Step 1: Know what you have. Spend one hour listing every system that touches your most sensitive data — customer records, payment information, intellectual property. Trace every integration. This audit costs nothing and is the foundation of everything else.
Step 2: Enable multi-factor authentication everywhere. If you have not done this on every account that touches your business — email, banking, CRM, cloud storage — stop reading and do it now. This is the single highest-ROI security action available to you.
Step 3: Run a phishing simulation with your team. Several free and low-cost tools allow you to send simulated phishing emails to your team and measure how many people click. The results are always humbling and always instructive.
Step 4: Write a one-page incident response plan. Five questions to answer before an attack: (1) Who is my first call? (2) What systems do I shut down first? (3) How do I communicate with customers? (4) Where are my backups and how fast can I restore them? (5) Do I have cyber insurance? One page. Keep it somewhere you can find it in a crisis.
Step 5: Consider a security assessment. Several organizations offer small business cybersecurity assessments at accessible price points. Given that the average breach costs $254,000 and a basic assessment costs a fraction of that, the math is clear.
Frequently Asked Questions
What is Project Glasswing and who can participate?
Project Glasswing is Anthropic’s joint industry initiative to find and fix critical software vulnerabilities using Claude Mythos Preview. It is not publicly available. Organizations must apply and be vetted. The program expanded on June 2-3, 2026 to include 150 new organizations in critical infrastructure sectors across 15+ countries.
What is Claude Mythos Preview?
It is an unreleased frontier AI model from Anthropic that has demonstrated the ability to identify and exploit zero-day software vulnerabilities at a level exceeding all but the most skilled human security researchers. Anthropic chose controlled deployment specifically because of the model’s capabilities.
How do AI-powered cyberattacks differ from traditional ones?
The primary differences are speed, scale, and quality. AI-generated phishing achieves 5-6x higher open rates than traditional attacks and costs 95% less to produce. AI can identify vulnerabilities in software automatically at a scale and speed that human attackers cannot match. The attack surface has not changed — the attacker’s capability to exploit it has.
What is the most important thing a small business can do right now?
Enable multi-factor authentication on every account, then document your most sensitive data and the systems that touch it. These two actions address the two most common entry points for attacks on small businesses.
Is cyber insurance worth it for small businesses?
Only 17% of US small businesses carry cyber insurance, compared to 62% in the UK. Given that average breach costs exceed $250,000 and 60% of attacked businesses close within six months, cyber insurance deserves serious consideration — especially as AI-powered attacks make incidents more likely, not less.
The Close
I want to be honest with you about where I am with this.
I am not a cybersecurity expert. I am an entrepreneur who takes AI seriously and who reads carefully when something shifts.
This week shifted something.
The existence of an AI model powerful enough to surpass elite human hackers — and the fact that Anthropic chose not to release it publicly for that exact reason — tells me that the threat environment has escalated beyond what most small business owners are currently prepared for.
I am not telling you this to make you afraid. I am telling you this because I think you deserve to know what is actually happening, not a softened version of it.
The entrepreneurs who take this seriously now — who spend a few hours getting their security fundamentals right, who write the incident response plan, who run the phishing simulation — will not be immune to attacks. But they will be in a dramatically better position than the ones who treat this as tomorrow’s problem.
Tomorrow’s problem has a way of arriving today.
Jonathan Mast is an entrepreneur and AI educator who helps business owners navigate the rapidly changing AI landscape. He is the founder of White Beard Strategies and the AI Prompts for Entrepreneurs community, where he works daily with business owners who are building AI fluency and resilience into their operations.





















