AI·News & analysis
Anthropic opens its strongest hacking-capable AI to more security teams
Anthropic merged Project Glasswing into a bigger Cyber Verification Program with three access tiers, so more vetted defenders can use Claude Mythos 5.1 and Opus 5.5 with fewer cyber blocks.

Tide
Ripple
Sci-fi
6/10
Reality
Shipping
An AI bouncer that checks your badge before you get the hacker tools.How we rate
Anthropic expanded its Cyber Verification Program into three access tiers, giving vetted security teams Claude Mythos 5.1, Opus 5.5 and Sonnet 5.5 with fewer cyber blocks.
The top tier, for testers of power grids and flight systems, is reviewed with the US government. Through the earlier Glasswing program, partners found at least 129,000 verified vulnerabilities in four months. Defense Access applications should get answers within days, Red Team Access within weeks.
What to know
- Anthropic merged Project Glasswing and its old Cyber Verification Program into one expanded program with three tiers: Defense, Red Team and Specialized Access.
- Every tier includes Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, plus new models as they arrive.
- In Anthropic's own test, the Red Team tier blocked none of 50 attack scenarios, while regular Claude blocked every one on the first prompt.
- Glasswing partners found at least 129,000 verified software vulnerabilities between April and July 2026, with more than 33,000 rated critical or high severity.
Anthropic announced on Tuesday that it's opening its most capable cyber models to a much bigger group of security teams. Now the interesting question: how do you hand out an AI that can help find and break into security holes without handing it to the wrong people?
Wait, why is Claude blocked from cyber work at all?
Security work has an awkward problem. The same skill that helps a defender find and fix a hole can help an attacker use it. Anthropic calls this "dual use."
So the versions of Claude that anyone can sign up for ship with conservative cyber safeguards. Anthropic says these block most cyber work on Claude Opus 5.5, Claude Fable 5.1 and Claude Sonnet 5.5. The goal is to limit what a malicious user can do.
The catch: real defenders need strong tools too. A hospital's security team doesn't want to be blocked while it pulls apart a piece of malware that just hit its network.
Regular Claude can still help with the everyday stuff. Anthropic lists code review, patching known issues, finding vulnerabilities in code you own, and sorting security alerts.
What were Glasswing and the old program?
For the past six months, Anthropic ran two separate programs for trusted defenders.
- Project Glasswing: gave a group of organizations that secure the most critical software access to Claude Mythos, Anthropic's strongest cyber model.
- The original Cyber Verification Program (CVP): gave vetted security teams access to Claude Opus and Sonnet models with reduced safeguards.
Now the two are becoming one program. Anthropic says the point is to give more security organizations the capabilities they need. Every tier includes Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, plus new models as they arrive.
So what are the three tiers?
Think of it like a building with key cards. Everyone in the program gets in the front door, but only some cards open the server room. Each tier has its own verification rules and required security controls.
| Tier | What it allows | Who it's for | Review time |
|---|---|---|---|
| Defense Access | Incident response, malware analysis, checking vulnerabilities | Security teams, infrastructure operators, open-source maintainers, researchers | A few days |
| Red Team Access | Everything above, plus authorized penetration testing | Organizations only | A few weeks |
| Specialized Access | The fewest cyber blocks | Testers of safety-critical systems | In-depth review with the US government |
Defense Access
This tier covers defensive work: running a security operations center, responding to incidents, reverse-engineering malware, and analyzing vulnerabilities.
Anthropic's list of who qualifies is broad:
- Organizations: security teams at companies, nonprofits, universities and government bodies defending systems they own or maintain.
- Infrastructure: operators of critical infrastructure of any size, such as regional hospitals or municipal utilities.
- Smaller players: smaller security firms and open-source maintainers.
- Individuals: researchers with a track record of reported vulnerabilities.
Anthropic says it expects many defensive organizations to qualify and aims to answer applications within a few days.
Red Team Access
This adds authorized penetration testing and red-teaming. A "red team" is a group paid to attack its own side, so the real attackers find fewer surprises.
In-house red teams, government red teams and pen-testing firms can apply. They may only attack systems they're authorized to test. Claude will still block, in real time, actions that could cause physical harm or mass disruption, like deploying ransomware or damaging physical systems.
Reviews take a few weeks. Applicants get Defense Access while they wait. For now, individual researchers aren't eligible.
Specialized Access
This is the tier with the fewest blocks. It's for a limited set of organizations authorized to test systems that could affect people's lives or disrupt markets: flight operating systems, power grids, telecom networks, interbank transfers and government networks.
Anthropic reviews every one of these organizations in depth together with the US government. Existing Glasswing members move into this tier and don't need reapproval for current models.
Did Anthropic test whether the tiers work?
It did, with a benchmark called CyScenarioBench. It checks whether a model can plan and carry out multi-step cyber operations under realistic limits.
Anthropic ran Claude Opus 5.5 through 10 challenges, five attempts each, for 50 trials per tier. Here's what happened:
- No program access: every task was blocked on the very first prompt.
- Defense Access: 46 of 50 trials were blocked at some point; the other 4 succeeded.
- Red Team Access: no blocks at all, and Claude completed 34 of 50 tasks.
That 34 of 50 is the same completion rate the model gets with no safeguards at all, which is how Specialized Access works. In other words, the safety filters stayed out of the way where they were supposed to and stepped in where they were supposed to.
In real life If you run security for a small city water utility, you could apply for Defense Access, get an answer within days, and then ask Claude to help reverse-engineer a suspicious file without hitting a wall of refusals.
How many bugs did Glasswing actually find?
This is the part that sounds like a season finale. Anthropic says Glasswing partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026.
Anthropic's own open-source scanning added 5,500 more verified vulnerabilities between April and October, and more than 33,000 of all of them have been rated critical or high severity so far.
By the numbers: Anthropic says these figures are likely an undercount. They come from partial data in 33 partner reports and its open-source work. Because survey data covered only some partners, Anthropic expects the true impact to be at least five times higher.
Several partners told Anthropic that Mythos sped up their bug-finding by months or even years. Fewer than half disclosed how many bugs they had patched, often because fixes were still in progress.
AI finding security holes in real software is becoming a regular headline. Last week, Epic paused most development on MyChart after Mythos found flaws, and Google launched Gemini 4 Argon to vetted defenders first.
What about privacy, and how do you join?
Why it matters: organizations in the program must allow data retention, so Anthropic can watch for misuse. For security teams handling sensitive logs, that's a real trade-off.
Anthropic says a fix is coming. Enterprise Frontier Safeguards (EFS), due later this fall, combines zero data retention with safeguards. Eligible organizations will then be able to store data in cloud infrastructure they control.
Until then, organizations that already use Claude Fable 5.1 or Claude Mythos 5.1 with zero data retention can use the program the same way.
How to apply
Organizations apply through Anthropic's site. Anthropic verifies every applicant and asks for proof of the security controls each tier requires.
- Existing members: keep their current settings for older models and are automatically evaluated for Opus 5.5, Sonnet 5.5 and Mythos 5.1.
- Platforms: the Claude Platform, Google Cloud's Vertex AI and Microsoft Foundry.
- Amazon Bedrock: only for customers eligible for Enterprise Frontier Safeguards.
- Admins: must assign access to specific workspaces.
If a member gets blocked on work its tier should allow, Anthropic has a form to report it. It says it will keep refining the classifiers that decide what gets blocked.
What it means for you
- If you work in security: Defense Access is aimed broadly, including small firms, hospitals, utilities and open-source maintainers, so it's worth applying.
- If you maintain open-source code: expect more bug reports. Anthropic says it's continuing work to help secure open-source software.
- If you just use apps: more of the software you rely on may get patched faster, as AI helps defenders find holes before attackers do.
- If you use regular Claude: nothing changes. It still blocks most offensive cyber work.
The bottom line
Anthropic is turning a small, invite-only experiment into a bigger program with clear levels of access. The idea is simple: verify who you are, then give you only as much hacking power as your job needs. If the bug numbers from Glasswing hold up, defenders just got a lot more help.
Key facts
- Access tiers
- Defense, Red Team, Specialized
- Models included
- Claude Opus 5.5, Sonnet 5.5, Mythos 5.1
- Glasswing finds (Apr to Jul 2026)
- At least 129,000 verified vulnerabilities
- Critical or high severity
- More than 33,000
- Red Team tier test
- 0 of 50 tasks blocked, 34 completed
Got questions?
Quick answers, plain wordsWhat is Anthropic's Cyber Verification Program?
It's a program that lets verified security professionals use Claude models with fewer cyber safeguards than the public versions. Anthropic checks who you are and what security controls you have before turning the extra capability on.
What changed on October 6, 2026?
Anthropic merged Project Glasswing, which gave a small group access to Claude Mythos, with the older Cyber Verification Program into one bigger program. It now has three tiers: Defense Access, Red Team Access and Specialized Access.
Which Claude models are included?
Every tier includes Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, and Anthropic says new models will be added as they come out.
Who qualifies for Defense Access?
Security teams defending their own systems at companies, nonprofits, universities and government bodies, critical infrastructure operators of any size, smaller security firms, open-source maintainers, and individual researchers with a record of reported vulnerabilities.
Can individual researchers get Red Team Access?
No. Anthropic says the Red Team tier is for organizations only for now. Individual researchers can still apply for Defense Access.
What is Specialized Access?
It's the tier with the fewest cyber blocks, for a limited set of organizations authorized to test systems like flight software, power grids, telecom networks and interbank transfer systems. Anthropic reviews each one in depth with the US government.
How long does it take to get approved?
Anthropic aims to answer Defense Access applications within a few days. Red Team Access reviews take a few weeks, and applicants get Defense Access while they wait.
Is the program free?
Anthropic's announcement doesn't mention a separate fee for the program. Members use the models on their existing platforms, and Anthropic requires data retention so it can watch for misuse.
Where is the program available?
On the Claude Platform, Google Cloud's Vertex AI and Microsoft Foundry. On Amazon Bedrock it's only for customers eligible for Enterprise Frontier Safeguards.
Can regular Claude users still do security work?
Yes, within limits. Anthropic says its generally available models can still help with code review, patching known issues, finding vulnerabilities in code you own, and sorting security alerts.
SourcesAnthropic
Topics and tagsAnthropic, AI safety, Cybersecurity, anthropic
Related stories

OpenAI apologizes to Australian lawmakers for its AI agent's Medicare website hack
OpenAI's chief strategy officer Jason Kwon flew to Sydney to face a parliamentary inquiry, pledged faster disclosure, and admitted the company should have told the government sooner. Anthropic made a similar pledge.

Anthropic commits $100 million to train 10,000 engineers to deploy Claude
The new Claude Frontier Academy runs a residency modeled on medical training, with first cohorts from Accenture, McKinsey, Deloitte, Morgan Stanley and others.

Claude now sorts 120,000 emails a day for Barclays, and most of its developers are next
Barclays is scaling Anthropic's Claude across its global operations, with 16,000 colleagues already using it to help 20 million retail customers and a goal of half its developers using Claude Code by the end of 2026.
More in brief
- Tesla's Model 3 and Model Y can now power your house in a blackoutOct 6
- Google launches Nano Banana 2.1, a better image model at half the priceOct 6
- RemoveMacAI turns off Apple Intelligence on macOS 27 and frees up about 12GBOct 6
- The Emmys are leaving broadcast TV for Prime Video, and they'll stream free worldwideOct 6
- Paramount closes its $110B Warner Bros. Discovery deal, creating SkydanceOct 6
- Mistral Large 4 'Le Chonk' is a 1-trillion-parameter open model built for cyber defenseOct 6