Anthropic Expands Claude Access For Cyberdefenders logo

Anthropic Expands Claude Access For Cyberdefenders

Anthropic merged two security programs into a single Cyber Verification Program giving vetted cybersecurity professionals reduced safeguards on its top models.

By the Numbers

129,000
Glasswing vulnerabilities
5,500
Anthropic's own scan
33,000+
Critical/high-severity
33 partner reports
Based on
Opus 5.5, Sonnet 5.5, Mythos 5.1
Models covered
ShareXLinkedInEmail

THE RUNDOWN

1

The program splits into three tiers โ€” Defense, Red Team and Specialized Access โ€” each unlocking different cyber safeguards on Claude.

2

Glasswing partners plus Anthropic's own scanning found 134,500 combined vulnerabilities between April and July, over 33,000 of them critical or high-severity.

3

Anthropic says the count is based on just 33 partner reports and is likely an undercount by 5x or more.

4

Partners told Anthropic that Claude's Mythos-class models cut vulnerability-finding time by months or even years.

The VC Read

Value Add VC analysis

The diligence question nobody's asking: what's Anthropic's actual process for revoking Defense-tier access once granted, and how fast? A verification program is a static gate, not continuous monitoring โ€” the real security test is whether Anthropic can pull a credentialed account's reduced-safeguard access within hours of a compromise. Also worth tracking: Anthropic's own 5x-undercount admission means the real vulnerability number could be closer to 650,000 than 134,500 โ€” a gap that large should make anyone citing these stats add a caveat.

Analysis

Anthropic on Tuesday announced an expanded, three-tier Cyber Verification Program (CVP) that folds in Project Glasswing and gives vetted cybersecurity professionals reduced safeguards on Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1, plus future models. Anthropic disclosed that Glasswing partners alone found 129,000 verified vulnerabilities between April and July, with the company's own open-source scanning turning up another 5,500 โ€” more than 33,000 of the combined total rated critical or high-severity.

Three Tiers, Three Risk Levels

The program splits access by what a verified organization is allowed to do with a less-restricted Claude:

โ€œExisting Project Glasswing members move into this tier automatically.โ€

- Defense Access โ€” defensive work only (SOC monitoring, incident response, malware reverse-engineering), open to company security teams, nonprofits, universities, government bodies, critical infrastructure operators and even individual researchers, with a review turnaround of a few days.

- Red Team Access โ€” adds authorized penetration testing and red-teaming on systems an organization has permission to test, open only to organizations (not individuals), with real-time blocks still in place for anything that could cause physical harm or mass disruption, and a multi-week review.

- Specialized Access โ€” the fewest cyber blocks of the three, reserved for a limited set of organizations testing safety-critical systems like flight-operating software, power grids, telecom networks, interbank transfer infrastructure and government administrative networks, reviewed in collaboration with the US government. Existing Project Glasswing members move into this tier automatically.

Anthropic itself flagged the vulnerability count as incomplete: the combined figure is based on just 33 partner reports, a fraction of the full Glasswing roster, and the company said plainly, "This is likely an undercount... we expect the true impact to be at least five times higher." One quote from partners stood out: several told Anthropic that Claude's Mythos-class models had "increased their rate of vulnerability finding by months or even years" compared with working without it.

Anthropic previously leaned hard into AI-safety messaging in its own IPO filing, and this expansion cuts the other direction โ€” loosening restrictions, not tightening them, for a credentialed subset of users. That's a deliberate signal to the security industry that Anthropic sees defenders, not only attackers, as the group that most needs an uncensored Claude.

The obvious limitation: a verification program is only as strong as its vetting, and Anthropic has not disclosed exactly how it screens applicants for Defense- or Red Team-tier access, or what stops a credentialed account from being compromised and misused by someone who was never vetted at all. The vulnerability count is also explicitly partial and self-reported by partners who have a commercial reason to showcase strong results, which is a different kind of number than an independently audited total.

For security teams, the practical takeaway is narrower than the headline: this expands who can ask Claude harder questions, not what Claude is newly capable of doing.

ShareXLinkedInEmail

Key Sources

2 sources

Reported by Anthropic ยท Analysis by Value Add Pulse.

โ† Back to Pulse

THE WIRE in your inboxโ€” Tech, startup & VC news with The VC Read, a few times a week. Free to subscribe, no spam.