Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws
- ID
- 32698
- Status
- summarized
- Published
- 07 Oct 2026, 4:07 PM
- Fetched
- 07 Oct 2026, 6:30 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/10/anthropic-expands-claude-access-for.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.5
- Created
- 07 Oct 2026, 6:30 PM
- Tags
- Audience
- developersai_ml_learnersai_agent_users
What happened
Anthropic is expanding its Cyber Verification Program (CVP), a three-tier scheme — Defense Access, Red Team Access, and Specialized Access — that gives vetted security teams reduced-safeguard access to Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1. Alongside it, Anthropic says its Project Glasswing initiative found at least 129,000 verified software vulnerabilities between April and July 2026 (plus 5,500 more via open-source scanning through October), with more than 33,000 rated critical or high severity. Anthropic also published a CyScenarioBench result: safeguards blocked 46 of 50 tasks on Opus 5.5 in the Defense tier, while the Red Team tier blocked none and completed 34 of 50 — the same completion rate as with no safeguards at all.
Why it matters
The only hard numbers here are self-reported by the vendor, and Anthropic itself says the 129,000 figure is 'likely an undercount' that it expects to be 'at least five times higher' — so treat these as marketing-adjacent claims, not audited findings. The operationally useful part is the CyScenarioBench breakdown: guardrails on Opus 5.5 blocked 46 of 50 cyber tasks in Defense Access but zero in Red Team Access, which is the concrete measure of what 'vetted reduced-safeguard access' actually unlocks. If your team does incident response, malware reverse engineering, or authorized pentesting, the decision is whether applying to a tier is worth the vetting overhead versus your current tooling — and note the tiers are gated by authorization, not by region, so there is no stated Malaysian or SEA-specific track.
Discussion angle
The 34-of-50 completion rate with no safeguards is identical to the Red Team tier's rate — so what is the guardrail actually costing, and should anyone trust a 129,000-vulnerability count that the vendor says is five times too low?