Anthropic expands cyber verification program with new access tiers for penetration testing

Anthropic expands cyber verification program with new access tiers for penetration testing

N
News Editor
2026-10-07 00:39:53
Anthropic said on Oct. 6 U.S. time that it is expanding its Cyber Verification Program, giving approved cybersecurity professionals access to Claude Mythos 5.1, Opus 5.5, and Sonnet 5.5 with fewer safety blocks. The company has folded its earlier Project Glasswing and CVP tracks into one program and split access into three tiers: Defensive Access, Red Team Access, and Special Access. The update also opens the door, for the first time, to authorized penetration testing and red-team exercises. Anthropic said the change is meant to reflect the dual-use nature of cybersecurity work. General public versions of Opus 5.5, Fable 5.1, and Sonnet 5.5 retain stricter protections that block most cyber tasks, while verified users can apply for more permissive access depending on use case and target environment. The highest tier covers a small set of organizations authorized to test systems tied to human safety or market disruption, including power grids, telecom networks, interbank transfer infrastructure, aviation operations systems, and government administrative networks. The company also published benchmark data and Glasswing results. In CyScenarioBench testing, Red Team Access completed 34 of 50 runs without blocks, which Anthropic said was materially similar to the 67.6% success rate seen with no safeguards. Separately, Glasswing partners found at least 129,000 verified software vulnerabilities between April and July 2026, while Anthropic’s own open-source scanning found another 5,500 from April to October.

Anthropic announced on Oct. 6 U.S. time that it is expanding its Cyber Verification Program, or CVP, allowing approved cybersecurity professionals to use Claude Mythos 5.1, Opus 5.5, and Sonnet 5.5 with fewer safety restrictions.

The revised program now has three access tiers and, for the first time, includes authorized penetration testing and red-team exercises.

Project Glasswing and CVP merged into one program

Anthropic said cybersecurity capability is inherently dual-use. The same ability that helps defenders identify and patch vulnerabilities can also be used by attackers to exploit them. Because of that, the general-access versions of Opus 5.5, Fable 5.1, and Sonnet 5.5 keep conservative cyber safeguards that block most security work.

Over the past six months, Anthropic had offered trusted access through two channels. Project Glasswing gave organizations protecting critical software access to Claude Mythos, while CVP gave vetted cyber teams lower-friction access on Opus and Sonnet. The latest revision combines those two tracks into a single program.

Three access levels now define the program

Tier 1: Defensive Access

The first tier, Defensive Access, covers security operations centers, incident response, malware reverse engineering, and vulnerability analysis and validation. Eligible applicants include companies, nonprofits, universities, and government cyber teams defending their own systems. It also covers critical infrastructure operators of any size, including regional hospitals and municipal utilities, as well as small cybersecurity firms, open-source project maintainers, and individual researchers with a record of vulnerability disclosure.

Anthropic said it expects most organizations doing defensive work to qualify and that applications will receive a response within a few days.

Tier 2: Red Team Access

The second tier, Red Team Access, adds authorized penetration testing and red-team exercises on top of defensive uses. It is aimed at internal enterprise red teams, government red teams, and penetration testing firms, and may only be used against systems the applicant is authorized to test.

Anthropic said activities such as deploying ransomware, damaging physical systems, or conducting penetration testing against high-risk safety systems that could cause physical harm or widespread disruption will still be blocked in real time. Review for this tier takes several weeks. During that process, applicants are first placed into Defensive Access. At present, only organizations can apply for this level; individual researchers are not eligible.

Tier 3: Special Access

The third tier, Special Access, has the fewest restrictions. It is limited to a small number of verified organizations authorized to test systems where failures could affect human life or disrupt markets. Anthropic listed aviation operations systems, power grids, telecommunications networks, interbank transfer infrastructure, and government administrative networks as examples.

Anthropic said each organization in this tier is currently subject to in-depth review in coordination with the U.S. government. Existing Project Glasswing members will move into the tier directly without going through a new review. Payward, the parent company of cryptocurrency exchange Kraken, joined Project Glasswing in August and falls into this group.

Platforms and data retention rules

Organizations admitted to the program must retain data so Anthropic can monitor potential cyber abuse.

CVP is currently available through the Claude platform, Google Cloud Vertex AI, and Microsoft Foundry. Amazon Bedrock is available only to customers that qualify under a specific enterprise protection program.

Benchmark results: Red Team Access completed 34 of 50 runs

To test how the tiered controls work, Anthropic evaluated Opus 5.5 with CyScenarioBench, a benchmark that measures whether a model can plan and carry out multi-stage cyber operations under realistic constraints.

Across 10 tasks run five times each, the general version was blocked at the first prompt on every task. Under Defensive Access, 46 of 50 runs were blocked during execution and the remaining four completed. Under Red Team Access, none of the runs were blocked, and 34 completed. Anthropic said that result was materially similar to the 67.6% success rate recorded with no safeguards at all.

Glasswing partners found at least 129,000 vulnerabilities

Anthropic also released results from Project Glasswing. According to the company, partners found at least 129,000 validated software vulnerabilities between April and July 2026. Anthropic’s own open-source scanning found another 5,500 from April to October, and more than 33,000 of those findings have already been rated critical or high risk.

Anthropic said those figures come from survey data submitted by only part of its partner base and should be treated as an underestimate. The company expects the real impact to be at least five times higher.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.