anthropic.com web signal

Anthropic Opens Three-Tier CVP Folding In Project Glasswing

TL;DR

  • Anthropic launched an expanded Cyber Verification Program on October 6 with three tiers: Defense Access, Red Team Access, and Specialized Access for safety-critical systems.
  • Glasswing partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026, with more than 33,000 rated critical or high-severity.
  • On CyScenarioBench, Red Team Access produced zero blocks and completed 34 of 50 tasks, a 67.6% success rate matching the model with no safeguards.

Anthropic rolled out an expanded Cyber Verification Program on October 6 that merges its earlier Project Glasswing initiative into a single three-tier structure, giving vetted security professionals access to Claude Opus 5.5, Sonnet 5.5, and Mythos 5.1 with cybersecurity blocking classifiers reduced or removed. "We're launching a new, expanded version of our Cyber Verification Program (CVP), which makes advanced cyber capabilities and reduced blocking classifiers available to qualifying security professionals," the company wrote.

Defense Access covers security operations center work, incident response, malware reverse-engineering, and vulnerability validation. Red Team Access adds authorized penetration testing. Specialized Access, the narrowest tier, is reserved for organizations authorized to test safety-critical systems; the company says those reviews are currently handled in collaboration with the U.S. government.

The scale numbers come from the retired Glasswing program. "Through the program, our partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026," the announcement says, with more than 33,000 of those rated critical or high-severity. Anthropic's own open-source scanning found another 5,500. Booz Allen and Comcast contributed case studies on using Claude Mythos against their codebases.

The internal evaluation is where the tiering shows its teeth. Across 50 trials on Anthropic's CyScenarioBench, a model without CVP access was blocked on every task, Defense Access blocked 46 of 50, and the Red Team tier blocked none. "In the Red Team Access tier, no blocks occurred, and Claude Opus 5.5 successfully completed 34 of the 50 tasks—effectively equivalent to the model's 67.6% success rate on this evaluation with no safeguards applied," the post says.

Enrollment is not frictionless. Organizations must enable data retention for misuse monitoring; a zero-data-retention alternative is slated for an Enterprise Frontier Safeguards rollout this fall. Defense Access reviews run in days, Red Team Access reviews in several weeks. Existing Project Glasswing members transition automatically.