Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws

anthropic-expands-claude-access-for-vetted-cyber-teams-as-glasswing-finds-129,000-flaws
Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws

Ravie LakshmananOct 07, 2026Artificial Intelligence / Vulnerability

Anthropic on Tuesday said it’s expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company claimed its Project Glasswing initiative uncovered at least 129,000 verified software vulnerabilities between April and July 2026.

The company said it also found an additional 5,500 verified software vulnerabilities between April and October 2026 through open-source scanning efforts.

“Of these verified vulnerabilities, more than 33,000 have so far been rated as critical- or high-severity,” Anthropic said. “This is likely an undercount, as it is based on survey data from only a subset of Glasswing partners. As such, we expect the true impact to be at least five times higher.”

The updated program, called the Cyber Verification Program (CVP), features three access tiers, allowing organizations and security teams to apply for one that best aligns with their work. Each tier comes with access to its models, including Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and new models moving forward.

The three access levels are detailed below –

  • Defense Access, which is for defensive work, such as incident response, malware reverse engineering, and vulnerability analysis and validation.
  • Red Team Access, which adds authorized penetration testing and red-teaming to the defensive use cases.
  • Specialized Access, which has the fewest safeguards and is reserved for a limited set of verified organizations that are authorized to test safety systems.

According to a CyScenarioBench evaluation, its safeguards blocked 46 of 50 tasks on Claude Opus 5.5 in the Defense Access tier, while the Red Team Access tier on the same model did not block any tasks, and completed 34 of 50, which is the same completion rate as when no safeguards are applied. Without CVP access, every task was blocked on the first prompt.

“These evaluations give us confidence that we can make advanced cyber capabilities safely available to a broader set of defenders, expanding the defensive efforts we began with Project Glasswing,” Anthropic said.

The AI company said it’s making these tools available to defenders given their dual-use nature, and to help them secure systems using the same capabilities that could be weaponized by a bad actor for malicious purposes.

In an analysis published late last month, VulnCheck researcher Patrick Garrity revealed that only 2 of the 300 vulnerabilities discovered by Anthropic or Project Glasswing, or 0.67%, have been exploited in the wild. Of these, 39 have been classified as critical, 141 as high, 81 as medium, and 18 as low in severity.

The two vulnerabilities that have witnessed active exploitation efforts are CVE-2026-26980, an SQL injection flaw in Ghost CMS, and CVE-2026-61500, a session forgery flaw in Rejetto HTTP File Server.

If anything, the findings suggest that while AI is lowering the barrier to vulnerability discovery, not every security flaw it uncovers is necessarily exploitable by threat actors or capable of causing significant impacts. Moreover, as demonstrated by 1Password and Veracode, AI-generated vulnerability patches can themselves introduce new security risks of their own.

“Roughly 44% of AI code generation tasks introduced a risky security vulnerability in tests,” Veracode said. “The average security pass rate across models is 56% – barely changed from 55% in the first report. In other words, security performance has stayed flat while the amount of AI-generated code entering pipelines has surged.”

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Leave a Reply

Your email address will not be published. Required fields are marked *