Anthropic, a prominent player in the artificial intelligence (AI) domain, announced on Tuesday the expansion of its program geared towards cybersecurity professionals. This initiative aims to provide these experts with the opportunity to rigorously test its advanced AI models under fewer restrictions, a move that stems from the outcomes of the company’s Project Glasswing. Between April and July 2026, this project identified a significant number of software vulnerabilities, totaling at least 129,000 verified instances.
Significant Findings from Project Glasswing
Anthropic has further revealed that an additional 5,500 software vulnerabilities were verified from April to October 2026, thanks to open-source scanning efforts. Of the vulnerabilities identified, over 33,000 have been classified as critical or high-severity. However, Anthropic cautions that this figure may be underestimated, as it is based on a subset of data from Glasswing partners. The actual impact may be considerably larger, potentially five times the reported number.
Introducing the Cyber Verification Program
The company’s enhanced initiative, known as the Cyber Verification Program (CVP), introduces a tiered access system. This allows security teams to choose a tier that best fits their operational needs. The tiers provide varying levels of access to Anthropic’s AI models, including Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1, among others. The tiers are: Defense Access for incident response and vulnerability analysis; Red Team Access for penetration testing; and Specialized Access for limited organizations authorized to test safety systems.
Evaluation and Implications of AI in Cybersecurity
In assessments conducted by CyScenarioBench, the safeguards within the Defense Access tier successfully blocked 46 of 50 tasks on Claude Opus 5.5, while the Red Team Access tier completed 34 of 50 tasks without any blocks. These findings bolster Anthropic’s confidence in safely extending advanced cyber capabilities to a wider defensive audience. The tools are designed to help defenders secure systems using advanced capabilities that could otherwise be exploited by malicious entities.
Research by VulnCheck has shown that only a small fraction, specifically 0.67%, of the vulnerabilities discovered by Anthropic or Project Glasswing have been actively exploited. Among these, two significant vulnerabilities include CVE-2026-26980 and CVE-2026-61500. These findings underscore the potential of AI in discovering vulnerabilities, although not all uncovered flaws are readily exploitable or pose immediate threats.
The emergence of AI-generated vulnerability patches introduces new security challenges. Reports from Veracode indicate that approximately 44% of AI-generated code tasks introduced security vulnerabilities. The average security pass rate among models remains static at 56%, highlighting the need for ongoing vigilance as AI-generated code becomes more prevalent.
