Urgent.News

What's breaking now, across thousands of outlets.

AI

Anthropic reconfigures its cool kids security program

Company's Project Glasswing and Cyber Verification Program metamorphose into triple tier threat hunting club

Anthropic reconfigures its cool kids security program

A week after cautioning about the advanced cybersecurity features of competitor Z.ai's GLM-5.3 model, Anthropic has restructured its Cyber Verification Program (CVP). The AI company formerly utilized two programs - Project Glasswing and the CVP - to provide trusted access to security organizations. Now, these programs have been integrated into a single expanded offering.

Project Glasswing and the CVP were launched in April 2026 alongside Anthropic's debut of its powerful frontier model, Mythos. While Project Glasswing offered partners early access to Mythos to identify vulnerabilities in their systems, there were concerns about the effectiveness of the identified vulnerabilities, with only fewer than 0.5% of the 225 Anthropic-linked vulnerabilities being exploited in the wild.

Anthropic claims that its security program has enabled partners to discover at least 129,000 verified software vulnerabilities between April and July 2026. Additionally, Anthropic's open-source scanning efforts uncovered an additional 5,500 verified vulnerabilities between April and October. However, the company believes that the actual impact is at least five times higher, as the data is based on survey information from only a subset of Glasswing partners.

Of these verified vulnerabilities, more than 33,000 have been rated as critical or high severity. Despite this, only 516 vulnerabilities have been patched. This indicates a significant gap between vulnerability identification and remediation, suggesting that there is much room for improvement in the system.

Anthropic's CVP has been restructured into three tiers: Defense Access, Red Team Access, and Specialized Access. The Defense Access tier is designed for security teams in companies, nonprofits, universities, and government organizations, focusing on system defense. The Red Team Access tier is aimed at penetration testing and offensive cyber evaluations, with participants still facing model refusals for certain interactions.

Specialized Access, formerly known as Glasswing, is reserved for a select group of verified organizations authorized to test safety systems that could impact people's lives or disrupt markets.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in AI

More from Tuesday 6 October →