The AI company said Tuesday that its revamped Cyber Verification Program (CVP) will provide approved security professionals with access to advanced models to identify and address vulnerabilities in critical software, Reuters reported.
Under Anthropic’s Project Glasswing initiative, participating organizations identified at least 129,000 verified vulnerabilities between April and July, according to the company. Anthropic said its own open-source scanning efforts uncovered another 5,500 vulnerabilities between April and October.
***
More than 33,000 of the vulnerabilities identified so far were rated critical or high severity. Anthropic said the figures are likely an undercount and estimated that the actual impact could be at least five times greater because the data came from a limited group of partners.
The expanded CVP combines two programs operated by Anthropic over the past six months. Glasswing provided organizations responsible for securing critical software with access to Claude Mythos, while the original CVP gave vetted security teams access to Claude Opus and Sonnet models with reduced safeguards.
The new program has three tiers with different verification requirements and security controls. All three provide access to Claude Opus 5.5, Sonnet 5.5, Mythos 5.1 and future models.
The Defense tier is intended for activities including incident response and malware analysis. Security teams, critical infrastructure operators, open-source maintainers and researchers with a history of reporting vulnerabilities can apply.
The Red Team tier allows authorized penetration testing and red-team operations, but applications are limited to organizations.
The Specialized tier has the fewest restrictions and is reserved for a small number of organizations authorized to test safety-critical systems, including power grids, flight systems and interbank transfer infrastructure.
Anthropic said each participant is vetted in coordination with the US government, while organizations already participating in Project Glasswing will move into the Specialized tier.
The company’s decision to provide broader access to its most capable cybersecurity models comes after the April launch of Claude Mythos Preview raised concerns that increasingly capable AI systems could be used to identify and exploit software vulnerabilities before they are fixed.


