AI/News

Anthropic opens three vetted tiers of cyber access to Claude: the default model is blocked on every task, the defensive tier on 46 of 50, the red-team tier on none - and partners found 129,000 verified vulnerabilities in four months

Anthropic's own page: Project Glasswing and the old verification programme merge into Defense, Red Team and Specialized Access, each with Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1. Data retention is required so Anthropic can watch for misuse; the top tier is reviewed "in collaboration with the US government".

By Daily Aletheia · Checked against the primary source · 7 October 2026 · 3 min read


Image: Anthropic - the CyScenarioBench chart from its own Cyber Verification Program announcement (solve rate for Claude Opus 5.5 by access tier), anthropic.com, 6 October 2026

Anthropic launched "a new, expanded version of our Cyber Verification Program (CVP)" on 6 October, "which makes advanced cyber capabilities and reduced blocking classifiers available to qualifying security professionals". It folds two earlier programmes into one: Project Glasswing, which gave organisations securing critical software access to Claude Mythos, and the first CVP, which gave vetted teams reduced safeguards on Opus and Sonnet.

Why the blocks exist. "Cybersecurity is inherently dual use," the page says; the generally available models "have conservative cyber safeguards that block most cyber work". The programme is the door around that.

The three tiers, in the page's words. Defense Access is for "defensive work, including security operations center and incident response tasks, reverse-engineering malware, and analyzing and validating vulnerabilities" - Anthropic expects "many organizations conducting defensive cybersecurity work to qualify" and aims "to respond to applications within a few days". Red Team Access adds "authorized penetration testing and red-teaming", organisations only, "a few weeks to review", with real-time blocks kept on "actions that could cause physical harm or mass disruption, such as deploying ransomware". Specialized Access, "which has the fewest cyber blocks", is for a limited set of organisations testing "flight operating systems, power grids, telecom networks, interbank transfer infrastructure, and government administrative networks", each reviewed "in depth in collaboration with the US government". Every tier carries Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1.

What the tiers do, measured. Anthropic ran Claude Opus 5.5 through CyScenarioBench, ten multi-stage cyber challenges, five attempts each, under each tier's safeguards. "Without CVP access, every task was blocked on the first prompt." In the Defense tier, "46 of the 50 trials were blocked at some point in the challenge, while the remaining four tasks succeeded". In the Red Team tier, "no blocks occurred, and Claude Opus 5.5 successfully completed 34 of the 50 tasks - effectively equivalent to the model's 67.6% success rate on this evaluation with no safeguards applied".

The vulnerability count. Through Glasswing, "our partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026"; Anthropic's own open-source scanning "found an additional 5,500 verified software vulnerabilities between April and October 2026"; "more than 33,000 have so far been rated as critical- or high-severity". The page calls this "likely an undercount", based on "survey data from only a subset of Glasswing partners" - "33 partner reports" - and "fewer than 50% of partners disclosed patched numbers", so it expects "the true impact to be at least five times higher".

The condition. "Data retention is required for organizations enrolled in the program so that we can monitor for cyber misuse." A zero-retention option, Enterprise Frontier Safeguards, is promised "later this fall". The programme runs on the Claude Platform, Google Cloud's Vertex AI and Microsoft Foundry; on Amazon Bedrock only for customers eligible for that safeguards product.

Sources & further reading

  1. 01Anthropic - Expanding the Cyber Verification Program, 6 Oct 2026 ↗Primary