Wednesday, October 7, 2026
Tech Beat
Oct 5, 2026, 4:00 PMCybersecurity

Anthropic Expands Claude Cyber Access With Three Tier CVP

Anthropic expands CVP with three access tiers, advanced Claude models, stricter vetting and benchmark data to give verified cyber defenders more power.

Listen to this briefingAudio briefing

Summary

On Oct. 6, 2026, Anthropic combined its six month Cyber Verification Program and Project Glasswing into three verified tiers offering Claude Opus 5.5, Sonnet 5.5, Mythos 5.1 and future models. Defense Access covers incident response, malware and vulnerability work for system owners, critical infrastructure, security firms, open source maintainers and established researchers, with reviews targeted within days. Organization-only Red Team Access adds authorized penetration testing, takes weeks to review with interim Defense access, but blocks ransomware, physical harm, mass disruption and high risk safety testing. Specialized Access, deeply vetted with the US government, covers selected flight, power-grid, telecom, interbank and government systems; Glasswing members transfer without reapproval.

Generally available Opus 5.5, Sonnet 5.5 and Fable 5.1 retain conservative safeguards but allow code review, patching, owned-code vulnerability discovery and alert triage. CVP requires data retention for misuse monitoring. Enterprise Frontier Safeguards, due later in fall 2026, will pair zero retention with customer-controlled cloud storage; eligible Fable 5.1 or Mythos 5.1 customers retain zero retention meanwhile. CVP is available on Claude Platform, Google Cloud Vertex AI and Microsoft Foundry; Amazon Bedrock requires EFS eligibility. Applicants must prove identity and security controls, while existing members retain settings and receive automatic upgrade assessments.

Across five attempts on each of 10 CyScenarioBench challenges, general Opus 5.5 blocked all 50 trials immediately; Defense blocked 46, with four successes; Red Team blocked none and completed 34, matching the unsafeguarded 67.6% Specialized proxy. Glasswing partners found at least 129,000 verified vulnerabilities from April to July 2026; Anthropic found 5,500 more in open source through October, including over 33,000 critical or high severity. Booz Allen and Comcast reported months or years faster discovery. Based on 33 partial reports, uneven triage and patch data from under 50%, Anthropic estimates actual impact at least fivefold higher. Classifier refinements and further open source and critical infrastructure findings are due within weeks.

Positives

  • 129,000 verified vulnerabilities were found by Project Glasswing partners between April and July 2026.
  • 5,500 additional open source vulnerabilities were verified by Anthropic between April and October 2026.
  • 34 of 50 CyScenarioBench trials succeeded under Red Team Access, matching the unsafeguarded 67.6% completion rate.
  • Defense Access applications are expected to receive decisions within days, widening advanced Claude access beyond Project Glasswing.
  • Enterprise Frontier Safeguards will combine zero data retention with customer-controlled cloud storage later in fall 2026.

Risks & concerns

  • 46 of 50 Defense Access trials were blocked, showing that legitimate defensive work may still trigger safeguards.
  • Red Team Access excludes individual researchers and requires reviews lasting several weeks.
  • CVP requires data retention for misuse monitoring until Enterprise Frontier Safeguards becomes available, except for limited eligible customers.
  • Fewer than 50% of Project Glasswing partners disclosed patch numbers, leaving remediation progress significantly undercounted.
  • Reduced safeguards create dual-use risk, requiring continued blocks on ransomware, physical harm and mass disruption.
Primary sourceAnthropic Newshttps://www.anthropic.com/news/cyber-verification-program
Read full article
Editorial note: Tech Beat summarizes and analyzes third-party reporting. The source link is the authoritative article. This page does not reproduce the full source text.

More From The Wire

CybersecurityOct 6

OpenAI Agents Target Wikipedia Tools and Flood Wikimedia With Traffic

CybersecurityOct 5

MCP Trust Flaws Let AI Agents Turn Prompts Into Internal Attacks

CybersecurityOct 5

Denmark CPR Breach Exposes Records of 8 Million People