Anthropic folds Project Glasswing into a three-tier Cyber Verification Program; reports 129K+ vulnerabilities found by partners
On Oct 6, 2026 Anthropic merged Project Glasswing and its Cyber Verification Program (CVP) into one program with three tiers (Defense, Red Team, Specialized Access), each giving vetted security users Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1 with fewer cyber safeguards. It said Glasswing partners found 129,000 verified vulnerabilities in April–July 2026 and its own open-source scanning another 5,500 through October, more than 33,000 of them critical or high severity.
Key facts
- Defense Access: security teams at companies, nonprofits, universities and governments, critical-infrastructure operators, smaller security firms, open-source maintainers and individual researchers with a disclosure record; reduced safeguards for SOC work, incident response, malware reverse-engineering and vulnerability analysis; applications reviewed 'within days'
- Red Team Access: in-house and government red teams and pentest firms only (no individuals); authorized penetration testing; real-time blocks stay for ransomware deployment and safety-critical systems; review takes weeks (applicants get Defense Access meanwhile)
- Specialized Access: a few verified organizations testing safety-critical systems (flight systems, power grids, telecom, interbank infrastructure, government networks); fewest blocks; reviewed with the US government; Glasswing members move over without reapplying
- Models at every tier: Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1
- Anthropic's CyScenarioBench example (Claude Opus 5.5): Defense Access blocked 46 of 50 runs at some point; Red Team Access had no blocks and completed 34 of 50 tasks; without CVP every attempt was blocked (per The Register)
- Vulnerabilities: 129,000 verified by Glasswing partners (Apr–Jul 2026) + 5,500 from Anthropic's open-source scanning (Apr–Oct); 33,000+ critical/high. Anthropic estimates 'the true impact to be at least five times higher'
- The Register: of 5,674 true positives from Anthropic's own scanning, only 516 (~9%) had been patched; VulnCheck's Patrick Garrity said under 0.5% of 225 Anthropic-linked CVEs it tracks were exploited in the wild
- Available on the Claude Platform, Google Vertex AI and Microsoft Foundry; limited AWS Bedrock access. Participants must currently allow data retention; Enterprise Frontier Safeguards with zero data retention is due 'later this fall'
- Same day, JPMorgan CEO Jamie Dimon told Bloomberg TV that cyber risk had gone up 10-fold since Mythos (entry 2026-10-06-dimon-mythos-cyber-risk-10-fold)
What happened
Project Glasswing started in April 2026 as a closed group of partners allowed to use Claude Mythos Preview for defensive security work. Anthropic had also run a separate Cyber Verification Program that loosened cyber safeguards for vetted users. On Oct 6 it merged the two into one program with three tiers. Each tier has its own vetting and its own set of blocked actions, and all three include Mythos 5.1.
Anthropic also gave its first overall count of what Glasswing found: 129,000 verified vulnerabilities from partners in four months, plus 5,500 from its own scanning of open-source code. It said partners described the models as speeding up their vulnerability finding "by months or even years". The Register noted that few of Anthropic's own findings had been patched yet (about 9%). It also quoted a VulnCheck researcher who said very few Anthropic-linked CVEs had been exploited in the wild.
Why it matters
This turns Mythos-class cyber capability from an invitation-only pilot into something a much wider set of defenders can apply for, while keeping the most dangerous uses (critical infrastructure, ransomware) behind tighter tiers. It came the same week the public argument about open-weight cyber risk (GLM-5.3) and bank hacks in South Korea was at its height.
Changelog
- 2026-10-07: created
Related events
- Anthropic reveals Claude Mythos Preview, withholds it over cyber risk and launches Project Glasswing ★★★★★
- Anthropic releases Claude Fable 5.1 and Claude Mythos 5.1 ★★★★★
- Anthropic releases Claude Opus 5.5 — Fable-5.1-level performance at $4/$20, first model of the Claude 5.5 family ★★★★★
- Anthropic Frontier Red Team: open-weights GLM-5.3 nearly matches Claude Mythos Preview at exploit development, with weak safeguards ★★★★
- JPMorgan CEO Jamie Dimon says cyber risk went up 10-fold after Anthropic's Mythos ★★★
Sources (6)
- officialAnthropic: Expanding the Cyber Verification Program
- pressReuters: Anthropic opens its most powerful AI models to more security teams
- pressSiliconANGLE: Anthropic folds Project Glasswing into an expanded three-tier Cyber Verification Program
- pressThe Register: Anthropic reconfigures its cool kids security program
- pressQuartz: Anthropic expands cyber AI access program to more security firms
- pressCyberSecurityNews: Anthropic opens Claude access to red teams and verified cyber defenders
id: 2026-10-06-anthropic-cyber-verification-program-three-tiers · updated 2026-10-07 · open in the interactive timeline