Analysis · 2 min read

Anthropic Merges Glasswing Into a Three Tier Cyber Verification Program

Anthropic folded Project Glasswing into an expanded Cyber Verification Program with Defense, Red Team, and Specialized tiers, citing more than 129000 verified vulnerabilities found by partners since April.

By Classy AI News · October 6, 2026

Anthropic Merges Glasswing Into a Three Tier Cyber Verification Program

What changed

On 6 October 2026, Anthropic announced an expanded Cyber Verification Program that merges two six month efforts: Project Glasswing, which gave critical software defenders access to Claude Mythos, and the original CVP, which offered vetted security teams reduced blocking on Claude Opus and Sonnet models.

The unified program has three tiers:

Defense Access for incident response, malware analysis, and defensive work on systems teams own or maintain.

Red Team Access for authorized penetration testing and red teaming, limited to organizations rather than individual applicants.

Specialized Access with the fewest cyber blocks, reserved for organizations vetted with the U.S. government to test safety critical systems such as power grids, telecom networks, and interbank transfer infrastructure. Existing Glasswing members transition here without reapproval for current models.

All tiers include Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1, plus future models. Anthropic reported Glasswing partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026, with more than 33,000 rated critical or high severity, plus 5,500 additional findings from Anthropic open source scanning between April and October.

Security operations center with analysts monitoring network dashboards

Why it matters

Frontier cyber models are now explicitly tiered products, not one public API with uniform safeguards. That forces CISOs to decide whether their workflows qualify for reduced classifiers or remain on consumer grade blocking that may miss novel exploit chains.

The vulnerability counts, if even directionally correct, also reframe AI cyber capability as a net defensive multiplier when access is gated, countering narratives that stronger models only help attackers.

Who is affected

Enterprise security leaders must map incident response, red team, and critical infrastructure testing to the tier they can realistically qualify for, noting individual researchers are limited to Defense Access.

Cloud procurement teams on Vertex AI, Microsoft Foundry, and Amazon Bedrock should confirm CVP availability varies by platform and that Enterprise Frontier Safeguards apply on Bedrock.

Regulators and ISACs should track Specialized Access vetting as a de facto pre release channel for the most capable cyber models.

What to do next

Assign an owner to submit a single organizational CVP application with accurate security control attestations rather than letting individual researchers apply piecemeal. Document which workflows require Red Team or Specialized tiers before planning Mythos dependent automation.

Laptop displaying code and security analysis tools on a desk

What to watch

Watch Anthropic's promised follow up on open source scanning lessons, U.S. government expansion of Specialized Access eligibility internationally, and competitor programs that mirror tiered defender access rather than broad release.

Sources

  1. Primary. Anthropic, Expanding the Cyber Verification Program (6 October 2026). Tier structure, model access, and vulnerability statistics.
  1. Secondary. Reuters via StreetInsider, Anthropic opens its most powerful AI models to more security teams (6 October 2026). Independent reporting on tiers and Glasswing merge.

Newsletter

Get the dispatch

One field. One email when we publish. Privacy.