Anthropic expanded its Cyber Verification Program on October 6, 2026, merging it with Project Glasswing into a single programme with three access tiers. Each tier gives vetted security professionals fewer cyber blocks on Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1. Anthropic also disclosed that Glasswing partners found at least 129,000 verified software vulnerabilities between April and July 2026, more than 33,000 of them rated critical or high severity.
Why do security teams need a special programme at all?
Because Anthropic’s public models deliberately block most cyber work. Cybersecurity is dual use: the steps that let a defender prove and patch a flaw are the same steps an attacker uses to exploit it. So the generally available versions of Opus 5.5, Fable 5.1 and Sonnet 5.5 refuse a lot of legitimate security tasks. The programme is how verified defenders get those blocks lifted, in proportion to how much they need.
What are the three tiers?
- Defense Access: incident response, malware reverse-engineering, and validating vulnerabilities. Open to in-house security teams, critical infrastructure operators of any size such as regional hospitals or local utilities, smaller security firms, open-source maintainers, and individual researchers with a track record. Anthropic aims to answer applications within a few days.
- Red Team Access: adds authorised penetration testing. Organisations only, review takes a few weeks, and applicants sit in Defense Access meanwhile. Actions that could cause physical harm or mass disruption, such as deploying ransomware, stay blocked.
- Specialized Access: fewest blocks, for a small set of organisations authorised to test systems where failure could hurt people or disrupt markets, such as flight software, power grids, telecoms and interbank payments. Reviewed in collaboration with the US government. Existing Glasswing members move here automatically.
Do the tiers actually work?
Anthropic tested Opus 5.5 on CyScenarioBench, ten multi-stage cyber operation challenges, five attempts each per tier. Without the programme, every task was blocked on the first prompt. In Defense Access, 46 of 50 attempts were blocked at some point. In Red Team Access, nothing was blocked and Opus completed 34 of 50, matching its 67.6% success rate with no safeguards. That is Anthropic grading its own controls, but the spread between tiers is the behaviour you would want.
How credible are the 129,000 vulnerabilities?
Treat it as a lower bound with soft edges. The figure comes from survey data from 33 partner reports, Anthropic says the real number is likely at least five times higher, and fewer than half of partners disclosed how many flaws they had patched. Anthropic’s own open-source scanning found another 5,500 between April and October. The scale is plausible, and partners such as Booz Allen and Comcast have described months or years of work compressed, but the methodology is self-reported.
Is there a privacy catch?
Yes. Enrolled organisations must allow data retention so Anthropic can monitor for misuse, which is a real cost for teams handling sensitive incidents. Anthropic says a feature called Enterprise Frontier Safeguards, due later this fall, will let eligible organisations keep that data in cloud infrastructure they control. The programme runs on the Claude Platform, Google Cloud Vertex AI and Microsoft Foundry, but on Amazon Bedrock only for customers eligible for that new feature.
The timing is pointed. Mistral launched Large 4 the same day, highlighting that Opus 5.5 scores near zero on one vulnerability test because it refuses. This is Anthropic’s answer: the capability exists, gated by verification rather than open weights. It extends the same logic as Google’s Fairwind programme, and lands a week after Microsoft warned that attackers now weaponise flaws in under 24 hours.
Apply or read the details in Anthropic’s announcement.




