Anthropic’s Claude AI now available to cybersecurity red teams
Key Takeaways Anthropic has significantly expanded its Cyber Verification Program (CVP) for its Claude AI models. The updated program, launched October 6, 2026, now offers three distinct access tiers...
Key Takeaways
- Anthropic has significantly expanded its Cyber Verification Program (CVP) for its Claude AI models.
- The updated program, launched October 6, 2026, now offers three distinct access tiers (Defense, Red Team, Specialized) with varying levels of cybersecurity safeguards removed for verified professionals.
- This initiative grants cybersecurity researchers and authorized red teams greater flexibility to use Claude models, including Opus 5.5, Sonnet 5.5, and Mythos 5.1, for vulnerability discovery and penetration testing.
- While public Claude models maintain strict cyber restrictions, verified users can access models with fewer limitations, enabling more advanced security testing and research.
- Anthropic reported that its Glasswing partners identified over 129,000 verified vulnerabilities from April to July 2026, showcasing the program’s potential impact.
Anthropic has announced a major update to its Cyber Verification Program, providing enhanced access to its advanced Claude AI models for a select group of verified cybersecurity professionals. Unveiled on October 6, 2026, this expansion introduces a tiered access system designed to support defensive research, authorized penetration testing, and the rigorous evaluation of critical infrastructure systems where failures could have catastrophic consequences.
Table Of Content
The updated program integrates models such as Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1, along with future iterations. It consolidates previous initiatives, including Project Glasswing, into a single, cohesive offering. This streamlines access pathways, aligning permissions precisely with the specific security objectives of each participating team.
This strategic move by Anthropic directly addresses a fundamental paradox in cybersecurity: the very tools capable of identifying vulnerabilities can also be misused by malicious actors. To mitigate this, Anthropic’s publicly available models will continue to enforce stringent cyber safeguards. In contrast, verified users within the expanded program will encounter fewer restrictions, tailored to their pre-approved activities. Public access to Claude still facilitates essential tasks like code review, patch development, vulnerability discovery within owned source code, and security alert triage.
Three Cybersecurity Access Tiers
Defense Access
The Defense Access tier is tailored for security operations, incident response, malware reverse engineering, and vulnerability analysis. This tier is open to a broad range of applicants, including corporate security teams, academic institutions, government agencies, healthcare providers, utility companies, smaller security firms, and maintainers of open-source projects. Individual researchers with a documented history of reporting vulnerabilities are also eligible. Anthropic aims to process these applications within a few days.
Red Team Access
Building on Defense Access, the Red Team Access tier enables authorized penetration testing and broader red-teaming exercises. Eligibility for this tier is restricted to organizations, encompassing internal red teams, government security teams, and specialized security testing companies. A critical requirement is that users must possess explicit permission to test their designated targets. Even within this advanced tier, real-time controls remain active to prevent actions such as ransomware deployment, physical system damage, or penetration testing involving high-risk safety-critical systems.
Reviews for Red Team Access can extend over several weeks. During this assessment period, qualifying applicants are granted Defense Access, allowing them to commence defensive security work while Anthropic completes its comprehensive evaluation for broader red-teaming permissions.
Specialized Access
The Specialized Access tier offers the fewest cyber-related blocks and is reserved for a highly restricted group of organizations. These entities are authorized to conduct testing on critical national infrastructure, including power grids, flight control systems, telecommunications networks, interbank transfer systems, and sensitive government networks. Anthropic collaborates directly with the U.S. government to vet organizations applying for this tier. Existing members of the former Glasswing program will automatically transition into this Specialized Access tier for current models, leveraging their prior approvals.
Testing and Vulnerability Findings
Anthropic rigorously tested Claude Opus 5.5 using its internal CyScenarioBench, a benchmark designed to evaluate multi-stage cyber operations. Across 50 testing attempts for each access setting, the public access version of Claude successfully blocked every task at the initial prompt. In contrast, Defense Access blocked 46 attempts, with four tasks successfully completed. Red Team Access registered no blocks and completed 34 tasks, achieving a success rate closely aligned with the 67.6% reported without any safeguards. It is important to note that these are company-generated benchmark results and do not definitively prove that malicious requests cannot bypass controls under real-world conditions.
Furthermore, Anthropic reported substantial vulnerability discoveries. Between April and July 2026, Glasswing partners identified a minimum of 129,000 verified vulnerabilities. An additional 5,500 vulnerabilities were uncovered through Anthropic’s open-source scanning efforts from April to October of the same year, with over 33,000 of these findings categorized as high or critical severity. However, these figures are based on partial reports from partners, and fewer than half disclosed the number of patches applied. Therefore, these discovery totals should not be interpreted as a measure of completed fixes.
The CVP generally mandates data retention for misuse monitoring purposes, though temporary exceptions can be made for eligible zero-retention customers. Future Enterprise Frontier Safeguards are planned to allow qualifying organizations to maintain monitoring data within their own controlled cloud infrastructure.
Organizations interested in applying for CVP can do so by providing proof of the required security controls via the application portal. Access to Claude models under CVP is available through the Claude Platform, Google Cloud Vertex AI, and Microsoft Foundry. Access via Amazon Bedrock requires eligibility for Enterprise Frontier Safeguards. Existing members of the program will retain their current settings and undergo automatic evaluation for access to newer models.
What You Should Do
- If your organization conducts cybersecurity research, penetration testing, or red-teaming, evaluate applying for Anthropic’s Cyber Verification Program to leverage advanced AI capabilities.
- Ensure your organization meets the stringent security control requirements and has clear authorization for any penetration testing activities before applying for Red Team or Specialized Access.
- For organizations concerned about data retention, investigate the upcoming Enterprise Frontier Safeguards for options to manage monitoring data within your own cloud infrastructure.
- Stay informed on Anthropic’s updates regarding CVP and new model releases to maximize the utility of AI in your cybersecurity operations.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.