Anthropic expands Cyber Verification Program
TECH

Anthropic expands Cyber Verification Program

36+
Signals

Strategic Overview

  • 01.
    Anthropic launched an expanded Cyber Verification Program (CVP) on October 6, 2026, integrating Project Glasswing and the earlier CVP into a single three-tier system: Defense Access, Red Team Access, and Specialized Access.
  • 02.
    All three tiers include access to Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1, with future models to be added.
  • 03.
    Defense Access covers SOC/incident response, malware reverse-engineering, and vulnerability analysis; eligible applicants include corporate security teams, nonprofits, universities, government bodies, critical infrastructure operators, small security firms, open-source maintainers, and individual researchers with disclosure records. Review takes 'a few days.'
  • 04.
    Red Team Access adds authorized penetration testing and red-teaming, is limited to organizations (not individuals), and takes a few weeks to review; real-time blocks remain for physical harm, mass disruption, ransomware deployment, or testing high-risk safety systems.
  • 05.
    Specialized Access is reserved for organizations authorized to test safety-critical systems (flight operating systems, power grids, telecom networks, interbank transfer infrastructure, government networks), vetted in collaboration with the U.S. government; existing Project Glasswing members transition automatically.
  • 06.
    CVP enrollment requires accepting data retention for misuse monitoring; Enterprise Frontier Safeguards (EFS), launching fall 2026, will allow zero-retention storage in customer-controlled cloud infrastructure.
  • 07.
    The program is available on the Claude Platform, Google Cloud Vertex AI, and Microsoft Foundry, with limited availability on Amazon Bedrock.

The Tiered Access Model: What Changes at Each Level

Anthropic's Cyber Verification Program (CVP) now sorts applicants into three tiers, each unlocking a different degree of freedom from the company's default safety restrictions. Defense Access, the entry tier, is open to corporate security teams, nonprofits, universities, government bodies, critical infrastructure operators, small security firms, open-source maintainers, and even individual researchers who can point to a track record of vulnerability disclosures; it covers SOC and incident-response work, malware reverse-engineering, and vulnerability analysis, with review taking 'a few days.'[1]Red Team Access goes further, adding authorized penetration testing and red-teaming, but it is restricted to organizations rather than individuals and takes a few weeks to clear - real-time blocks still trigger for anything resembling physical harm, mass disruption, ransomware deployment, or attacks on high-risk safety systems.[1]The top tier, Specialized Access, is reserved for organizations cleared to test safety-critical infrastructure - flight systems, power grids, telecom networks, interbank transfer rails, and government networks - vetted in direct collaboration with the U.S. government; existing Project Glasswing members, the coalition Anthropic quietly built with partners including AWS, Cisco, JPMorganChase, Microsoft, and Nvidia, transition into this tier automatically.[1]All three tiers currently include Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1, with more models promised over time.[1]

By The Numbers: Red Team Access Erases Anthropic's Own Safeguards

By The Numbers: Red Team Access Erases Anthropic's Own Safeguards
CyScenarioBench offensive-task completions out of 50 trials, by CVP access tier.

The clearest evidence of what 'fewer restrictions' actually means comes from Anthropic's own CyScenarioBench testing. With no CVP access at all, Claude Opus 5.5 was blocked on all 50 offensive-security trial tasks before it could even begin. Under Defense Access, the model still got blocked on 46 of 50 trials, completing just 4. Under Red Team Access, the blocking disappeared entirely - zero blocks - and the model completed 34 of 50 tasks, a 67.6 percent success rate that Anthropic says matches how the model performs with no safety safeguards whatsoever.[2]That is the real headline buried in a program framed as 'extending the impact' of defensive security work: for a vetted red team, Claude's offensive capability ceiling is identical to an unrestricted model.[1]IDC research director Sakshi Grover flagged a wrinkle in how that number should be read - the benchmark is Anthropic's own, not independently audited, and she argued that whether a given sequence of actions is legitimate red-teaming or an actual attack depends on authorization, target scope, and execution conditions that outsiders can't verify from the score alone.[2]Anthropic also estimates the defensive side of the ledger is underreported, saying partner-survey data suggests the true vulnerability-discovery impact of the program runs at least five times higher than the official count.[2]

Vetted, But By Whom? The Verification Gap

Two cybersecurity researchers interviewed alongside the launch backed the tiered structure only with caveats. IDC's Deepika Giri said the model works only with continuous access review, distinct short-lived agent identities, full observability, and human oversight of high-impact actions, warning that an agent's behavior can drift over time even after it clears vetting.[2]Red-teamer Vibhum Dubey raised a related accountability question: organizations granted expanded access still need to define, in advance, who is responsible when an autonomous AI system takes a consequential action.[2]Anthropic's own user base is testing that gap in real time. Reception split between relief that individual bug-hunters can now qualify and frustration that the bar for entry seems arbitrary - one user described getting accepted into the program simply by describing their use case as 'homework,' while another, a penetration tester who had collected roughly $10,000 in bug bounty payouts across six accepted vulnerability reports, said they were rejected. That inconsistency, more than any policy language, is what's fueling skepticism that 'vetted' means something more rigorous than a short application form.

Vulnerabilities Found vs. Vulnerabilities Exploited

The program's headline defensive numbers are large: Project Glasswing partners surfaced more than 129,000 verified vulnerabilities between April and July 2026, and Anthropic's own open-source scanning added roughly 5,500 more through October, with over 33,000 of the combined total rated critical or high severity.[1]But volume of discovery is not the same as real-world danger. Of the roughly 300 CVEs Anthropic has been credited with surfacing, independent tracking found only two - a Ghost CMS SQL injection flaw (CVE-2026-26980) and a Rejetto HTTP File Server session-forgery bug (CVE-2026-61500) - have actually seen active exploitation in the wild, a rate of under 1 percent.[3]That gap is part of why Anthropic is pairing expanded access with new guardrails on the data side: enrolling in CVP requires organizations to accept data retention for misuse monitoring, a tradeoff Anthropic plans to soften later this year with Enterprise Frontier Safeguards, which will allow zero-retention storage inside a customer's own cloud infrastructure.[1]

Historical Context

2026-04
Anthropic limited rollout of Claude Mythos over fears hackers could misuse it for cyberattacks, launching Project Glasswing as an invite-only coalition program for critical-software security.
2026-04 to 2026-07
Partners identified at least 129,000 verified software vulnerabilities, with Anthropic's own open-source scanning (through October) adding 5,500 more; over 33,000 total rated critical or high severity.
2026-08-21
Announced Claude Mythos 5 vulnerability scanning in Claude Security for Enterprise customers alongside the $35M Defender Advantage Fund (0xDAF) for open-source defense.
2026-09-22
Claude Opus 5.5 launched, later becoming one of the three models included at every CVP access tier.
2026-10-06
Announced the expanded three-tier Cyber Verification Program, merging Project Glasswing into it.

Power Map

Key Players
Subject

Anthropic expands Cyber Verification Program

AN

Anthropic

Program operator; announced the CVP expansion and Project Glasswing merger

PR

Project Glasswing coalition (AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, Linux Foundation, Microsoft, Nvidia, Palo Alto Networks)

Original partners whose Claude Mythos access is folded into the new Specialized Access tier

BO

Booz Allen, Comcast

Named partners who shared experiences using Claude Mythos for codebase security

CR

CrowdStrike, Palo Alto Networks, SentinelOne, Trend Micro (TrendAI), Microsoft Security, Wiz, Zscaler

Security vendors integrating Claude Opus/Mythos capabilities into commercial products

AC

Accenture, BCG, Deloitte, Infosys, PwC

Professional services firms deploying Claude-based security tools for clients

U.

U.S. government

Collaborates with Anthropic on vetting organizations for Specialized Access to critical infrastructure systems

OP

OpenAI

Comparison point - reportedly uses 'clear, objective criteria' for GPT-5.4-Cyber access rather than Anthropic's tiered vendor model

Fact Check

3 cited
  1. [1] Cyber Verification Program
  2. [2] Anthropic widens access to AI cyber capabilities for vetted security teams
  3. [3] Anthropic Expands Claude Access for Cyber Defenders

Source Articles

Top 5

THE SIGNAL.

Analysts

“Cautioned that Anthropic's CyScenarioBench evaluation should be read as vendor-conducted rather than independently verified, saying: 'Because the steps can resemble an attacker's, legitimacy depends on authorization, target scope and execution conditions, not on the technique itself.'”

Sakshi Grover, Research Director at IDC
Independent analyst commentary on CVP benchmark testing

“Said the tiered model is workable only with continuous access review, distinct short-lived agent identities, full observability, and human oversight of high-impact actions, warning that agent behavior can drift over time: 'Give it an identity and grant short-lived access only for the task at hand, complete observability and control over its actions.'”

Deepika Giri, VP Asia/Pacific AI Platforms at IDC
Supportive of the tiered approach, conditionally

“Emphasized that organizations using the expanded access must clearly define who is responsible for actions taken by autonomous AI systems.”

Vibhum Dubey, Cybersecurity Researcher/Red Teamer
Accountability concerns
The Crowd

“We're expanding our Cyber Verification Program to give security professionals broader access to our most capable models. Through this program, verified security professionals can access Claude Mythos 5.1, Opus 5.5, and Sonnet 5.5 with safeguards designed for defensive work.”

@@AnthropicAI5516

“We expanded the Cyber Verification Program! OSS maintainers and individual researchers with a track record of reported vulns can qualify for the Defense Access tier. Here's how to apply: https://t.co/8zZUswBoKx”

@@cjav_dev214

“Anthropic is giving cybersecurity teams expanded access to its most powerful AI Anthropic restructured its Cyber Verification Program into three tiers, letting a broader range of security orgs”

@@qz1

“Finally! They're expanding the cyber verification program”

@u/mawcopolow61
Broadcast
How Anthropic uses Claude in Cybersecurity

How Anthropic uses Claude in Cybersecurity

Claude's Cyber Verification Program (CVP): How to Apply, ft. Jason Haddix aka jhaddix

Claude's Cyber Verification Program (CVP): How to Apply, ft. Jason Haddix aka jhaddix

Anthropic Expands AI Cybersecurity Program as Nearly 200 Groups Gain Access | WION

Anthropic Expands AI Cybersecurity Program as Nearly 200 Groups Gain Access | WION

Anthropic expands Cyber Verification Program — AI News | Agentic Brew