October 6, 2026
Anthropic expands the Cyber Verification Program with three access tiers
Defense, Red Team and Specialized Access tiers give vetted defenders — including open-source maintainers — reduced cyber safeguards on Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1.
On October 6, 2026 Anthropic relaunched its Cyber Verification Program (CVP), merging it with Project Glasswing access. Generally available Claude models have conservative cyber safeguards that block most offensive-looking security work; CVP lifts some of those blocks for verified professionals.
There are three tiers. Defense Access covers incident response, malware reverse engineering and vulnerability validation, and explicitly lists open-source maintainers and individual researchers with a track record as eligible. Red Team Access adds authorized penetration testing for organisations. Specialized Access, with the fewest blocks, is reserved for organisations testing safety-critical systems and is reviewed together with the US government; Glasswing members move there.
Anthropic also reported that Glasswing partners uncovered at least 129,000 verified vulnerabilities between April and July 2026, and its own open-source scanning found another 5,500 verified vulnerabilities between April and October.
Sources
Want to see what an AI audit finds in your project? Quick scans are free and take a few minutes.
Scan a repository