AI
Published 2026-10-06
Verified 2026-10-07

Anthropic folds Project Glasswing into an expanded Cyber Verification Program with three tiers (Defense, Red Team, Specialized) giving vetted security teams reduced cyber safeguards on Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1

Anthropic announced on 6 October 2026 an expanded Cyber Verification Program (CVP) that merges Project Glasswing, which gave organisations securing critical software access to its Claude Mythos models, with the earlier CVP, which gave vetted security teams reduced safeguards on Claude Opus and Sonnet. Each of the three new tiers includes Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and future models. Defense Access covers SOC and incident response work, malware reverse engineering and vulnerability analysis, and is open to company, nonprofit, university and government security teams defending their own systems, critical infrastructure operators of any size, smaller security firms, open-source maintainers and individual researchers with a record of reported vulnerabilities; Anthropic aims to answer within days. Red Team Access adds authorised penetration testing and red teaming, is for organisations only and takes weeks to review, and still blocks actions such as deploying ransomware or damaging physical systems. Specialized Access, with the fewest blocks, is for a small set of organisations authorised to test safety-critical systems such as flight systems, power grids, telecom networks and interbank transfer infrastructure, vetted with the US government; Glasswing members move into it. Data retention is required so Anthropic can watch for misuse. Anthropic says Glasswing partners found at least 129,000 verified vulnerabilities between April and July 2026 and its own open-source scanning found 5,500 more; in its CyScenarioBench test, Defense-tier safeguards blocked 46 of 50 offensive trials and the Red Team tier blocked none. Primary: Anthropic; wire: iTnews (Reuters).

Product
Anthropic Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1 (Cyber Verification Program)
Versions
n/a — access program; no CVE
Exploited in Australia?
unknown
Patch to
Australian SOC, incident response and critical infrastructure teams that want AI help with malware analysis or vulnerability triage can apply for Defense Access. Before you do, check that mandatory data retention fits your data-handling and sovereignty obligations, decide which systems and data staff may put into the models, and keep authorisation records for any red-team work.

Primary: Anthropic — Expanding the Cyber Verification Program (6 Oct 2026) · Vendor: Anthropic — Project Glasswing · iTnews — Anthropic opens its most powerful AI models to more security teams (7 Oct 2026)

ai