VMTech
Discuss a project →

Anthropic broadens Claude access for verified cyber teams

Anthropic broadens Claude access for verified cyber teams

Anthropic has expanded access to its advanced Claude models for vetted cybersecurity professionals through its Cyber Verification Program (CVP), following Project Glasswing’s identification of at least 129,000 verified software vulnerabilities between April and July 2026. Anthropic said more than 33,000 of those flaws have been rated critical or high severity.

The company also reported finding another 5,500 verified vulnerabilities between April and October through open-source scanning. It cautioned that the Glasswing total is likely an undercount because it is based on survey responses from only part of its partner base, and estimated the true impact could be at least five times higher.

Three access levels for cyber work

CVP is structured around three tiers intended to match a team’s authorised activity. Defense Access is aimed at incident response, malware reverse engineering, vulnerability analysis and validation. Red Team Access adds authorised penetration testing and red-teaming. Specialized Access has the fewest safeguards and is reserved for a limited group of verified organisations authorised to test safety systems.

The programme includes Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, as well as future models. Anthropic frames the approach as a way to provide defenders with capabilities that have dual-use potential, while applying access controls appropriate to the work being performed.

Safeguards vary by tier

Anthropic cited a CyScenarioBench evaluation of Claude Opus 5.5 to illustrate the difference between tiers. In Defense Access, safeguards blocked 46 of 50 tasks. In Red Team Access, no tasks were blocked and the model completed 34 of 50 tasks, the same completion result reported when no safeguards were applied. Without CVP access, every task was blocked at the first prompt.

The results show that the programme is not simply a general reduction in guardrails. It is a tiered model in which vetted users can obtain capabilities relevant to defensive analysis or authorised testing, while the most permissive setting remains restricted to a small group testing safety systems.

Discovery volume is not exploitation evidence

The scale of Glasswing’s findings should not be treated as a direct measure of active threat. VulnCheck researcher Patrick Garrity found that only two of 300 vulnerabilities attributed to Anthropic or Project Glasswing, or 0.67%, had been exploited in the wild. The sample included 39 critical, 141 high, 81 medium and 18 low-severity vulnerabilities.

The two flaws reported as actively exploited were CVE-2026-26980, an SQL injection vulnerability in Ghost CMS, and CVE-2026-61500, a session-forgery issue in Rejetto HTTP File Server. The distinction matters because AI can lower the barrier to finding flaws without making every discovered issue practical or valuable for attackers.

The dual-use debate also extends beyond discovery. The risk associated with Claude used to breach OpenAI systems illustrates why powerful models require controls around testing and use, while Veracode reported that roughly 44% of AI code-generation tasks introduced a risky security vulnerability in its tests. Its average security pass rate across models was 56%, compared with 55% in its first report.

What security teams should do

For organisations considering AI-assisted security work, the immediate priority is disciplined validation. Treat model-generated findings as inputs to triage, reproduce and assess issues in the relevant environment, and prioritise remediation using exploitability as well as severity. The same review discipline should apply to AI-generated patches before they reach production pipelines.

#cybersecurity#anthropic#vulnerability#aisecurity
Open analytics
On the site 0 views
min read 4 07.10.2026
Instagram

Anthropic broadens Claude access for verified cyber teams

Open the post on Instagram ↗