On October 6, 2026, Anthropic announced an expanded Cyber Verification Program (CVP) that gives vetted security professionals access to advanced Claude capabilities with fewer cybersecurity restrictions.
This initiative integrates its existing verification program and Project Glasswing into three distinct access tiers focused on defensive analysis, authorized offensive testing, and assessments of sensitive infrastructure.
According to the announcement, all tiers include Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and future models. Access depends on applicants’ verification status, operational scope, and required security controls, so it is not fully unrestricted.
1. Defense Access: This tier supports security operations, incident response, malware reverse engineering, and vulnerability analysis and validation. Eligible applicants include enterprise security teams, universities, government bodies, critical infrastructure operators, smaller security firms, open-source maintainers, and individual researchers with documented vulnerability disclosures. Anthropic aims to provide application decisions within a few days.
2. Red Team Access: This tier allows for authorized penetration testing and adversarial assessments but is limited to organizations, including internal red teams and penetration testing firms. Individual researchers cannot currently qualify. Reviews may take several weeks, with qualifying organizations receiving Defense Access during the assessment period. This tier also includes real-time blocking for activities that could cause physical harm or widespread disruption, such as ransomware deployment, damage to physical systems, and testing of high-risk safety systems.
3. Specialized Access: This tier imposes the fewest cyber restrictions for verified organizations assessing sensitive systems, including aviation software, power grids, telecommunications, interbank infrastructure, and government networks. Anthropic conducts reviews of applicants in collaboration with the US government, and existing Glasswing participants can transition without needing reapproval for the current models.
Anthropic evaluated Opus 5.5 using CyScenarioBench, conducting five attempts across each of 10 multistage cybersecurity challenges for each access tier.
Without CVP access, safeguards blocked every task at the initial prompt. Defense Access blocked 46 out of 50 trials, with four tasks succeeding.
Red Team Access reported no blocks and completed 34 out of 50 tasks, which is approximately in line with the reported 67.6% success rate without safeguards.
These results measure performance on selected offensive scenarios and do not establish that every permitted real-world operation is safe.
Anthropic reports that Glasswing partners identified at least 129,000 verified vulnerabilities between April and July 2026. Their open-source scanning identified another 5,500 vulnerabilities between April and October. More than 33,000 of these were classified as critical or high severity.
The company cautions that these findings depend on partial partner reporting, varying triage practices, and incomplete patch disclosures. Therefore, the discovery totals should not be interpreted as the total number of remediated vulnerabilities.
CVP generally requires data retention for monitoring misuse. Planned Enterprise Frontier Safeguards would allow eligible organizations to retain data within their controlled infrastructure.
The announcement also details temporary zero-retention exceptions. Access is provided through the Claude Platform, Vertex AI, and Microsoft Foundry. At the same time, eligibility for Amazon Bedrock is tied to these safeguards.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…
wolfSSL has released wolfSSH version 1.6.0, which addresses five security vulnerabilities, including a critical flaw…