Urgent.News

What's breaking now, across thousands of outlets.

AI

Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws

Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company claimed its Project Glasswing initiative uncovered at least 129,000 verified software vulnerabilities between April and July 2026. The company said it also found an additional

Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws

Anthropic has broadened its Cyber Verification Program (CVP) by introducing three access tiers for verified security professionals to utilize Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1 in defensive security operations. The expanded program goes beyond the previous single-level access approach for Opus and Sonnet, while maintaining necessary controls for cyber-related usage.

The key aspects of the updated program include:

1. Tiered framework: The program now consists of three access tiers, accommodating multiple cyber-capable models as it evolves, rather than treating access as a single, fixed entitlement.

2. Access structure: Organizations must complete verification through the CVP Verification Portal, attest to relevant security controls, and agree to tier-specific usage requirements.

3. Model inclusion: The program explicitly supports Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1, which can be accessed across various cloud environments.

4. Enterprise safeguards: The program retains important security measures, such as zero data retention options in certain configurations, to ensure sensitive information is handled appropriately.

5. Transition for existing participants: Current CVP members can seamlessly transition into the updated program, with access details determined by the organization's own verification and platform conditions.

The expansion emphasizes the importance of verification and policy frameworks in AI usage, particularly in defensive security work. Businesses considering the program should evaluate it as a controlled access program rather than a standard software subscription. Security teams must establish who will use the models, their defensive workflows, the data to be supplied, and how the organization's cloud configuration manages retention.

The availability of zero data retention in some configurations may be valuable for organizations requiring stronger rules for security information. However, this is not a universal setting and should be confirmed for the specific environment before designing a workflow.

Ultimately, businesses can leverage the expanded model coverage to explore AI assistance in defensive processes, such as incorporating approved AI tools into existing investigation, analysis, or security documentation workflows. However, it is crucial to implement defined inputs, human review, escalation paths, and clear boundaries for sensitive information.

Businesses should focus on four key questions to determine their eligibility, appropriate tier, available models, and suitable defensive workflows that can be tested with meaningful human oversight.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at thehackernews.com →

More in AI

More from Wednesday 7 October →