Anthropic Expands Cyber Verification Program With Three Tiers of Claude Access

Summary
Anthropic has merged Project Glasswing into its Cyber Verification Program, creating three access tiers for security professionals using advanced Claude models, with safeguards tailored to the work and its risks.
Key points
- The expanded program combines Project Glasswing with Anthropic's existing Cyber Verification Program.
- Defense Access supports defensive work such as security operations, incident response, malware reverse engineering, and vulnerability analysis.
- Red Team Access is for authorized penetration testing; Anthropic says it will block actions posing risks such as ransomware deployment or physical harm.
- Specialized Access, with the fewest cyber-use limitations, is reserved for vetted organizations testing safety-critical or high-impact systems; applications will receive in-depth review with the US government.
- Anthropic says partners found at least 129,000 verified software vulnerabilities between April and July, while open-source scanning found another 5,500 between April and October; more than 33,000 were rated critical or high severity.
- A security executive cautioned that faster discovery may not improve safety if remediation cannot keep pace, and that vetting does not eliminate risks such as compromised accounts or insider misuse.
Article Details
- Event Type
- Anthropic expanded its Cyber Verification Program by merging Project Glasswing into a tiered access system for advanced AI cyber capabilities.
- Impact
- The program provides vetted security professionals with different levels of access to advanced Claude models. Anthropic reported that partner use uncovered at least 129,000 verified software vulnerabilities from April through July and that open-source scanning found another 5,500 from April through October; more than 33,000 of the verified vulnerabilities were rated critical or high severity. Anthropic says safeguards remain in place, while SOCRadar CISO Ensar Seker cautioned that faster discovery may increase remediation backlogs and that tiering alone does not prove misuse has been prevented.
People
Vendors
AnthropicAnthropic has merged Project Glasswing into its existing Cyber Verification Program (CVP) to create an expanded, tiered program that gives select security professionals access to advanced AI cyber capabilities withSOCRadarSOCRadar CISO Ensar Seker tells Dark Reading that although the 129,000 figure signals AI can accelerate the vulnerability discovery window, the more important metric will be how much AI shortens the period during which
Products
Claude MythosMicrosoft, Google, Linux Foundation, JPMorganChase, and Nvidia. The initiative provides access to Claude Mythos, Anthropic's most advanced cyber large language model (LLM). The company decided to limit broaderClaude OpusThe CVP previously covered two other models, Claude Opus and Sonnet, with a single level of access. With Project Glasswing, it grants three different levels of cyber capabilities.Claude Sonnet"Each tier includes access to our most capable models, including Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and new models moving forward," Anthropic's Oct. 6 announcement states. The expanded CVP turns the