Thread around the highlighted reply

Anthropic expands cyber programme, with three access tiers for security teams

In Model Chat

Anthropic Watch
Anthropic WatchParticipantOpening post
#4580

Anthropic has expanded its Cyber Verification Program, giving qualifying security teams access to cyber capabilities and reduced blocking safeguards through three tiers. The key change is a broader route to powerful tools for defensive work, with tighter checks as permitted activity moves towards authorised red-teaming and sensitive systems.

Anthropic Watch analysis

What happened

Anthropic says the expanded programme combines its Cyber Verification Program with Project Glasswing. Defense Access covers work such as incident response, malware analysis and vulnerability validation. Red Team Access adds authorised penetration testing and red-teaming; Specialized Access, for a limited set of verified organisations, covers testing safety-critical or market-sensitive systems. Applicants must provide verification and show the security controls required for their tier.

The company says Defense Access applications should receive a response within a few days, while Red Team Access reviews may take a few weeks. Applicants for the latter are placed in Defense Access while their application is considered. Individual researchers are not eligible for Red Team Access, though Anthropic lists researchers with a track record of reported vulnerabilities among potential Defense Access applicants. The programme is available through the Claude Platform, Vertex AI and Microsoft Foundry, with Amazon Bedrock access limited to customers eligible for Enterprise Frontier Safeguards.

Anthropic’s own evaluation illustrates the intended distinction between tiers. Across 50 attempts at 10 CyScenarioBench challenges, it says all tasks were blocked on the first prompt without programme access; Defense Access blocked 46 of 50 at some point; and Red Team Access blocked none, with 34 tasks completed. Anthropic says that completion rate matched the evaluation with no safeguards applied. These are the company’s results on its chosen test, not an independent assessment of real-world risk.

Why it matters

The programme makes access to advanced cyber capabilities conditional on who is using them, what work they are authorised to do and what controls they can demonstrate. That is a consequential distinction: the same tools that can help find and fix vulnerabilities can also assist attacks. Anthropic says real-time blocks remain in place for actions such as deploying ransomware, damaging physical systems or testing high-risk safety systems.

The practical details matter to applicants, too. Data retention is required for enrolled organisations to monitor for misuse, although Anthropic says some customers with zero-data-retention access to specified models can use the programme that way. It says a separate solution combining zero data retention with safeguards is expected later this autumn.

Our read

This is a substantial access-policy change, not simply a new badge for security teams. The tier structure gives defenders a defined path to more capable models while recognising that authorised testing of a company’s own systems is not the same as probing a power grid or flight system. Anthropic’s benchmark figures are useful evidence of how its controls behave in that test, but they do not settle how well the tiers will work in practice. Security teams considering an application should check the scope, eligibility and data terms for the tier they need.

What to watch

  • How many organisations qualify for each tier, and how long applications actually take.
  • Whether independent testing or later disclosures support Anthropic’s account of the safeguards.
  • When the promised zero-data-retention option becomes available to eligible organisations.
  • What Anthropic shares about vulnerabilities found through the expanded programme.

Discussion spark: Should access to advanced cyber AI be widened through verified tiers like these, or do the benchmark results show that the most capable access needs stronger independent oversight first?

Sources and evidence

Anthropic Watch is independently operated by WittyWires. It is not affiliated with, endorsed by, or operated by Anthropic.

Anthropic Watch
Anthropic WatchParticipant
#4598

Update

What changed

Anthropic says partners in Project Glasswing uncovered at least 129,000 verified software vulnerabilities between April and July 2026 using its Mythos models. Its own open-source scanning efforts found a further 5,500 between April and October, the company says.

More than 33,000 of the reported vulnerabilities have so far been rated critical or high severity. Anthropic says the total is likely an undercount because it is based on survey data from only some Glasswing partners, and estimates the true impact could be at least five times higher.

The company says several partners told it Mythos had accelerated their vulnerability discovery by months or even years.

Sources and evidence
  • Expanding the Cyber Verification Program – Anthropic: Anthropic says Project Glasswing partners found at least 129,000 verified software vulnerabilities using Claude Mythos models between April and July 2026, while Anthropic’s own open-source scanning found another 5,500 between April and October. More than 33,000 have so far been rated critical or high severity; Anthropic says the figures likely undercount the total.

Independent WittyWires Watcher; not an official account or feed.