[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDWB9E5hjXdDRNDRpU56jhcn6FxTQmHDbuG3AoGml2X0":3},{"article":4,"iocs":55},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":34,"category":35,"article_tags":39},"82e0f90f-8290-4ba0-b8c6-fab3a1172d66","Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws","anthropic-expands-claude-access-for-vetted-cyber-teams-as-glasswing-finds-129-00-ecbf8c","Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company claimed its Project Glasswing initiative uncovered at least 129,000 verified software vulnerabilities between April and July 2026. The company said it also found an additional","Anthropic is expanding its Cyber Verification Program (CVP) to allow vetted cybersecurity professionals more access to its AI models, including Claude Opus 5.5, with reduced safeguards. This initiative, alongside Project Glasswing, reportedly uncovered over 129,000 software vulnerabilities between April and July 2026, with over 33,000 rated critical or high-severity. While AI is proving effective in vulnerability discovery, analysis suggests a low rate of actual exploitation for these AI-found flaws.","Anthropic expands Claude access for cyber teams and claims Project Glasswing found 129,000 software vulnerabilities.","Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws Ravie LakshmananOct 07, 2026Artificial Intelligence \u002F Vulnerability Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company claimed its Project Glasswing initiative uncovered at least 129,000 verified software vulnerabilities between April and July 2026. The company said it also found an additional 5,500 verified software vulnerabilities between April and October 2026 through open-source scanning efforts. \"Of these verified vulnerabilities, more than 33,000 have so far been rated as critical- or high-severity,\" Anthropic said. \"This is likely an undercount, as it is based on survey data from only a subset of Glasswing partners. As such, we expect the true impact to be at least five times higher.\" The updated program, called the Cyber Verification Program (CVP), features three access tiers, allowing organizations and security teams to apply for one that best aligns with their work. Each tier comes with access to its models, including Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and new models moving forward. The three access levels are detailed below - Defense Access, which is for defensive work, such as incident response, malware reverse engineering, and vulnerability analysis and validation. Red Team Access, which adds authorized penetration testing and red-teaming to the defensive use cases. Specialized Access, which has the fewest safeguards and is reserved for a limited set of verified organizations that are authorized to test safety systems. According to a CyScenarioBench evaluation, its safeguards blocked 46 of 50 tasks on Claude Opus 5.5 in the Defense Access tier, while the Red Team Access tier on the same model did not block any tasks, and completed 34 of 50, which is the same completion rate as when no safeguards are applied. Without CVP access, every task was blocked on the first prompt. \"These evaluations give us confidence that we can make advanced cyber capabilities safely available to a broader set of defenders, expanding the defensive efforts we began with Project Glasswing,\" Anthropic said. The AI company said it's making these tools available to defenders given their dual-use nature, and to help them secure systems using the same capabilities that could be weaponized by a bad actor for malicious purposes. In an analysis published late last month, VulnCheck researcher Patrick Garrity revealed that only 2 of the 300 vulnerabilities discovered by Anthropic or Project Glasswing, or 0.67%, have been exploited in the wild. Of these, 39 have been classified as critical, 141 as high, 81 as medium, and 18 as low in severity. The two vulnerabilities that have witnessed active exploitation efforts are CVE-2026-26980, an SQL injection flaw in Ghost CMS, and CVE-2026-61500, a session forgery flaw in Rejetto HTTP File Server. If anything, the findings suggest that while AI is lowering the barrier to vulnerability discovery, not every security flaw it uncovers is necessarily exploitable by threat actors or capable of causing significant impacts. Moreover, as demonstrated by 1Password and Veracode, AI-generated vulnerability patches can themselves introduce new security risks of their own. \"Roughly 44% of AI code generation tasks introduced a risky security vulnerability in tests,\" Veracode said. \"The average security pass rate across models is 56% – barely changed from 55% in the first report. In other words, security performance has stayed flat while the amount of AI-generated code entering pipelines has surged.\" Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  artificial intelligence, Penetration Testing, security research, Vulnerability ⚡ Top Stories This Week ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members How Financial Services Companies Can Modernize Their Software Supply Chain US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access Zero Trust for AI Agents Starts With Fixing Zero Visibility ⭐ Featured Resources Discover Hidden AI Agents and Lock Down Their Access — Get a Demo The CISO Playbook for Board-Ready Security Reporting The Browser Attacks Your Security Stack Is Missing 41 Cybersecurity Courses. One Week to Level Up Your Skills","https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Fanthropic-expands-claude-access-for.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEimg1tAvNh5aMWuNTZXjb4kKfxIQ0iWkuo2bCznozA8oz2Fm36WzbPnBI1bBDX5Mc3hpyOMIcjS_fcdYzzpQnrtUkex17u0_fn7r3bgcRYEN4o2hoGf4vlw5hQKEgcDd2VoVT2P9unKzsVOlly1QFlu6WfySqGPZ4Pf7xrZXaL4pEy1vrhWQBHR7SiqHHvf\u002Fs1600\u002Fclaude-flaws.jpg","2026-10-07T08:07:38+00:00","2026-10-07T10:00:31.557498+00:00",7,[18,21,23,25,28,31],{"name":19,"type":20},"Claude Opus 5.5","product",{"name":22,"type":20},"Claude Sonnet 5.5",{"name":24,"type":20},"Claude Mythos 5.1",{"name":26,"type":27},"Anthropic","vendor",{"name":29,"type":30},"Project Glasswing","campaign",{"name":32,"type":33},"Artificial Intelligence","technology","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":34,"icon":36,"name":37,"slug":38},null,"Threat Intelligence","threat-intelligence",[40,45,50],{"category":41},{"id":42,"icon":36,"name":43,"slug":44},"02371804-cf6d-4449-98de-f1a2d4d9b266","Tools","tools",{"category":46},{"id":47,"icon":36,"name":48,"slug":49},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":51},{"id":52,"icon":36,"name":53,"slug":54},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",[56,60],{"type":57,"value":58,"context":59},"cve","CVE-2026-26980","SQL injection flaw in Ghost CMS that has been exploited in the wild.",{"type":57,"value":61,"context":62},"CVE-2026-61500","Session forgery flaw in Rejetto HTTP File Server that has been exploited in the wild."]