security
Company’s Project Glasswing and Cyber Verification Program metamorphose into triple tier threat hunting club
Only a week after warning about the perils of competitor Z.ai’s GLM-5.3 model and its advanced cybersecurity capabilities, Anthropic has expanded its Cyber Verification Program (CVP) – or rather, reconfigured it.
“For the past six months, we’ve enabled trusted access through two programs: Project Glasswing and the CVP,” the AI biz said. “Now, we’re integrating these programs into one expanded offering, designed to give more security organizations access to the capabilities they need to protect their systems.”
Project Glasswing and CVP launched in April 2026 alongside the debut of Mythos, the company’s highly capable and equally hyped frontier model. Project Glasswing gave partners early access to Mythos so they could scour their systems for vulnerabilities before attackers beat them to it.
VulnCheck researcher Patrick Garrity was not particularly impressed with CVEs identified by Project Glasswing, noting that fewer than 0.5 percent of the 225 Anthropic-linked vulnerabilities he tracked were being exploited in the wild. And Anthropic’s own warning last month about the risks posed by GLM-5.3 somewhat undermines the idea that there’s anything special about its own Mythos model.
Even so, Anthropic says that its security program has allowed its partners to spot at least 129,000 verified software vulnerabilities between April and July 2026. And the biz claims that its own open source scanning efforts revealed an additional 5,500 verified vulnerabilities between April and October.
“Of these verified vulnerabilities, more than 33,000 have so far been rated as critical- or high-severity,” Anthropic said. “This is likely an undercount, as it is based on survey data from only a subset of Glasswing partners. As such, we expect the true impact to be at least five times higher.”
When these might get patched is unclear. The company’s own figures indicate that of 5,674 true positive vulnerabilities, 3,014 are high severity, and 1,522 are critical severity, yet only 516 have been patched. Given industry boasting about the cybersecurity prowess of AI models, generating a fix, testing it, and deploying it ought to be nearly automatic at this point.
But the gap between identification and remediation suggests there’s a lot of slack in the system that needs to be ironed out.
Two programs into one with three tiers
Now Anthropic’s two programs, one intended for organizations and one for individual security professionals, have been merged and reconfigured into three tiers. The AI biz has not explained why, but its stated intent is to tie model capabilities to specific tasks: Defense Access, Red Team Access, and Specialized Access. Depending on the tier, participants will encounter more or fewer blocks on security-related tasks.
As a measure of program participation value, Anthropic said that based on five attempts at 10 CyScenarioBench challenges, those without CVP access got blocked on every attempt.
Defense Access is intended for security teams at companies, nonprofits, universities, and government organizations that focus on system defense. In this tier, Claude Opus 5.5 faced refusals in 46 of 50 attempts and succeeded four times.
Red Team Access is for penetration testing and offensive cyber evaluation, and participants will still face model refusals for model interactions that would cause physical harm or mass disruption. Specifically, Claude Opus 5.5 completed 34 of the 50 tasks with Red Team Access safeguards enabled, a rate similar to what would be expected from Specialized Access.
Specialized Access sounds like a rebranding of Glasswing – it’s “reserved for a limited set of verified organizations that are authorized to test safety systems that could impact people’s lives or disrupt markets, such as flight operating systems, power grids, telecom networks, interbank transfer infrastructure, and government administrative networks.”
Those granted admission to this exclusive tier will face the fewest model refusals, not counting anyone using abliterated open-weight models that have had their guardrails suppressed.
For the next month or two, program participants will need to allow their data to be retained by Anthropic as part of its AI safety requirements. But soonish, the company’s Enterprise Frontier Safeguards program will offer zero data retention. Organizations already granted zero data retention while using Claude Fable 5.1 or Claude Mythos 5.1 can participate in CVP under those same terms.®
Click Here For The Original Source
