dotsfeed
← News

Anthropic launches three-tier Cyber Verification Program after Glasswing partners found 129,000 vulnerabilities

Verified· Oct 7, 2026Published Oct 7, 2026

Anthropic is merging Project Glasswing and its Cyber Verification Program into a three-tier access program, giving vetted security teams reduced safeguards on its most capable Claude models after partners surfaced over 129,000 verified vulnerabilities.

What happened

Anthropic announced on Tuesday, October 6, 2026, a revamped Cyber Verification Program with three access tiers. It combines two programs the company has run for six months: Project Glasswing, which gave organizations securing critical software access to Claude Mythos, and the original Cyber Verification Program, which gave vetted security teams reduced safeguards on Claude Opus and Sonnet models.

All three tiers include access to Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and new models going forward.

The Defense tier covers incident response and malware analysis. It is open to security teams, critical-infrastructure operators, open-source maintainers, and researchers with a record of reporting vulnerabilities.

The Red Team tier adds authorized penetration testing and red-teaming, and only organizations can apply.

The Specialized tier has the fewest restrictions. It is reserved for a small group of organizations authorized to test safety-critical systems such as power grids, flight systems, and interbank transfer infrastructure. Anthropic vets each member together with the US government, and existing Glasswing members move into this tier.

The context: Project Glasswing partners found at least 129,000 verified vulnerabilities between April and July, more than 33,000 of them rated critical or high severity. Anthropic's own open-source scanning found 5,500 more between April and October. Anthropic said the figures are likely an undercount and expects the true impact to be at least five times higher.

Why it matters

Anthropic is trying to solve the dual-use problem directly: the same model that finds and fixes vulnerabilities can also exploit them. Vetted defenders get fewer automated blocks, while the generally available models keep conservative cyber safeguards that block most offensive work.

The Specialized tier is effectively a government-vetted license to run Claude against safety-critical systems, which shows how seriously labs are taking the offensive upside of their most capable models.

For the agent era, this tiered trust model is a preview of how labs will gate the most sensitive agent skills as always-on agents like Dots take on cyber-adjacent work.

Sources

Verified October 7, 2026.

Sources

Get updates like this every morning

  1. ① Email
  2. ② Card on Stripe
  3. ③ 7 days free

Then $2/month · cancel anytime in one click