Anthropic expands Mythos access with three-tier cyber verification program

Anthropic expands Mythos access with three-tier cyber verification program

N
News Editor
2026-10-08 07:56:50
Anthropic has broadened access to its cyber-focused model capabilities by merging Project Glasswing and its older Cyber Verification Program into a new three-tier system: Defense Access, Red Team Access, and Specialized Access. Under the new structure, all three tiers can use Claude Opus 5.5, Sonnet 5.5, and Mythos 5.1, with fewer task blocks at higher verification levels and stricter review requirements. The change also opens the door to individual researchers for the first time, though only at the Defense tier and only for paid Pro or Max subscribers. The company said Defense Access is aimed at defensive work such as incident response, malware analysis, and vulnerability validation, while Red Team Access is reserved for organizations conducting authorized penetration testing and red-team exercises. Specialized Access remains the most restricted tier and is limited to a small number of vetted organizations testing systems where failures could threaten lives or disrupt markets, including aviation systems, power grids, telecom networks, and interbank transfer infrastructure. Anthropic also published internal benchmark results showing large differences in model blocking behavior across access levels, along with operational requirements such as identity checks, anti-phishing multi-factor authentication, reporting obligations, and data retention rules. Separately, the company disclosed vulnerability discovery figures from Glasswing partners and its own open-source scanning efforts.

Anthropic has widened access to the cyber capabilities tied to Claude Mythos, saying in an official announcement that tools once limited to a small group of institutions can now be requested by a broader set of cybersecurity professionals. Individual researchers are now eligible as well, though the change stops short of a full opening.

The company has folded Project Glasswing, launched in April, together with the older Cyber Verification Program, or CVP, into a three-tier structure: Defense Access, Red Team Access, and Specialized Access. All three tiers can use Opus 5.5, Sonnet 5.5, and Mythos 5.1. Higher tiers face fewer blocked tasks, but the review process becomes more demanding. Existing members of either earlier program do not need to apply again.

Glasswing and CVP are now one system

Before this change, Anthropic used two separate channels for cyber-related access.

Project Glasswing was built for a small number of organizations responsible for protecting critical software and gave them access to Mythos. The older CVP let approved security teams use Claude Opus and Sonnet with fewer refusals, but it had only one level and did not include Mythos.

Under the new setup, applicants submit a form through Anthropic’s verification portal. Each organization files once, and Anthropic places the applicant into the highest tier it qualifies for based on the information provided.

Defense Access is the broadest tier and includes some individuals

Defense Access has the lowest entry threshold. It is open to security teams inside companies, nonprofits, universities, and government agencies that defend their own systems. Operators of critical infrastructure can also apply regardless of size. Anthropic’s examples include regional hospitals and municipal utilities.

Small cybersecurity firms, open-source project maintainers, and individual researchers with a record of vulnerability disclosure are also eligible. Individuals can apply only for this tier, and they must be on a paid Pro or Max plan.

The work opened up at this level is mainly defensive: incident response, malware analysis, and vulnerability validation. Offensive testing remains blocked. Anthropic said it expects most organizations doing defensive work to qualify and said its help center lists a response time of seven business days.

Red Team Access is limited to organizations

Red Team Access is for security professionals hired to simulate attacks and find weaknesses for clients. Individuals cannot apply. Eligible applicants include internal corporate red teams, government red teams, cybersecurity firms, and penetration testing companies.

This tier allows authorized penetration testing and red-team exercises, but only against systems the applicant is authorized to test. Actions such as deploying ransomware or damaging physical systems, which could cause physical harm or large-scale disruption, are still blocked.

Anthropic said reviews at this level take several weeks. During that period, applicants receive Defense Access first.

Specialized Access is reviewed case by case with the U.S. government

Specialized Access has the fewest blocked tasks of the three tiers, but it is limited to a small number of verified organizations. These groups are authorized to test systems where failures could endanger lives or disrupt markets, including aviation operating systems, power grids, telecommunications networks, and interbank transfer infrastructure.

Anthropic said this is the only tier reviewed one by one in cooperation with the U.S. government. Existing Glasswing members move directly into this tier, and current model access does not need to be reviewed again.

Most cyber tasks remain blocked for unverified developers

For developers who do not apply, Anthropic said the rules are largely unchanged. They can still review code, patch known issues, search for vulnerabilities in their own source code, and triage alerts. Most other cybersecurity work remains blocked.

Applications may be denied if the work falls outside defensive use, if identity cannot be verified, or if the legal and regulatory environment in the applicant’s location presents risk. Anthropic also said it will apply extra caution to organizations that mainly serve military, intelligence, or law-enforcement clients.

Internal benchmark shows sharp differences by access level

Anthropic used CyScenarioBench to test the same model, Claude Opus 5.5, on whether it could plan and execute multi-stage simulated cyberattacks. The benchmark had 10 tasks, each run five times, for 50 runs per access level.

Without verification, all 50 runs were refused at the first step. Under Defense Access, 46 were blocked partway through and four completed. Under Red Team Access, none of the 50 runs were blocked, and 34 completed, a 68% completion rate. Anthropic said that was nearly identical to the 67.6% result with no safeguards at all, which it said represents the Specialized Access state.

The company also noted that this was a self-evaluation using its own safeguards, not a third-party validation.

Security requirements include data retention, identity checks, and reporting

Anthropic said participants are generally required to accept data retention so the company can monitor misuse. Once Enterprise Frontier Safeguards, or EFS, launches later this fall, eligible organizations will be able to keep data in cloud environments they control.

For Red Team and Specialized Access, the security terms set a default cap of 25 approved members per workspace. Each member must pass identity verification and, where legally allowed, a criminal record check. They must use phishing-resistant multi-factor authentication, cannot use long-lived API keys, and may connect only from company-managed devices.

Defense Access is looser. Anthropic said users at that level need to switch to phishing-resistant authentication and disable keys by Dec. 15, 2026. Across all tiers, suspected leaks or misuse must be reported within 72 hours, and Anthropic retains the right to reduce or revoke access.

As for availability, the program can be used through Claude Platform, Google Cloud Vertex AI, and Microsoft Foundry. Amazon Bedrock is currently limited to customers that qualify for EFS.

Anthropic disclosed vulnerability totals from partners and open-source scans

The company also published figures meant to show what the system has produced. Partners found at least 129,000 verified software vulnerabilities between April and July 2026. Anthropic’s own scans of open-source software found another 5,500 between April and October.

The aggregate chart goes deeper. It lists 595,597 candidate findings, with 208,175 triaged and reviewed, or about 35%. Of those, 135,610 were confirmed as real vulnerabilities. Within that set, 27,989 were high risk and 5,680 were critical, for a combined 33,669. Only 9,333 had been reported for remediation, equal to about 6.9% of confirmed findings.

The figures point to a system that is finding vulnerabilities quickly while remediation moves more slowly. Anthropic added that the ratio should not be treated as a direct real-world patch rate.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.