Anthropic Opens Claude Access to Red Teams and Verified Cyber Defenders With Reduced Restrictions
Anthropic opened three-tier Cyber Verification access so verified defenders and red teams face fewer Claude restrictions.
On October 6, 2026, Anthropic expanded its Cyber Verification Program, folding Project Glasswing into Defense, Red Team, and Specialized access tiers. Verified users of Claude Opus 5.5, Sonnet 5.5, Mythos 5.1, and future models receive fewer cybersecurity blocks than the public models, which still support only defensive tasks such as code review and patching. In company CyScenarioBench tests of Opus 5.5, public access blocked all 50 attempts, Defense Access blocked 46, and Red Team Access completed 34. Glasswing partners reported at least 129,000 verified vulnerabilities between April and July 2026, though patch disclosures were incomplete.
- Three tiers: Defense, Red Team, and Specialized Access for critical systems.
- Public Claude models keep strict cyber safeguards; verified users get fewer blocks.
- On Opus 5.5, public access blocked all 50 CyScenarioBench attempts; Red Team completed 34.
- Glasswing partners reported at least 129,000 verified vulnerabilities from April to July 2026.
- Available via Claude Platform, Vertex AI, and Microsoft Foundry; Bedrock needs extra eligibility.
Full article593 words · extracted from cybersecuritynews.com · click to collapse
Anthropic has expanded its Cyber Verification Program, giving verified security professionals access to advanced Claude models with fewer cybersecurity restrictions. Announced on October 6, 2026, the update introduces three access tiers covering defensive research, authorized penetration testing, and testing of systems where failures could threaten lives or disrupt markets.
The program includes Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and future models. It brings Project Glasswing and the earlier verification program into one offering, replacing separate access paths with permissions matched to each team’s work.
The change addresses a challenge: tools that help defenders find security flaws can also help attackers exploit them. Anthropic’s public models retain strict cyber safeguards, while verified users receive fewer blocks based on their approved activities. Public access still supports code review, patching, vulnerability discovery in owned source code, and security alert triage.
Three Cybersecurity Access Tiers
Defense Access covers security operations, incident response, malware reverse engineering, and vulnerability analysis. Eligible applicants include company security teams, universities, government bodies, hospitals, utilities, smaller security firms, and open-source maintainers. Individual researchers with a record of reporting vulnerabilities can also qualify. Anthropic aims to respond within a few days.
Red Team Access adds authorized penetration testing and red-teaming. It is limited to organizations, including internal red teams, government teams, and security testing firms. Users must have permission to test their targets. Real-time controls still block ransomware deployment, damage to physical systems, and penetration testing involving high-risk safety systems.

Reviews for this tier may take several weeks. Qualifying applicants receive Defense Access during review, allowing defensive work to begin while Anthropic checks the requirements for broader testing permissions.
Specialized Access has the fewest cyber blocks and serves a limited group authorized to test power grids, flight systems, telecom networks, interbank transfers, and government networks. Anthropic reviews these organizations with the US government. Existing Glasswing members move into this tier without reapproval for current models, building on the earlier Glasswing expansion.
Testing and Vulnerability Findings
Anthropic tested Opus 5.5 using CyScenarioBench, which measures multi-stage cyber operations. Across 50 attempts per access setting, public access blocked every task at the first prompt.
Defense Access blocked 46 attempts, while four succeeded. Red Team Access produced no blocks and completed 34 tasks, close to the 67.6% success rate reported without safeguards. These are company-run benchmark results, not proof that harmful requests cannot bypass controls.
Anthropic also says Glasswing partners found at least 129,000 verified vulnerabilities between April and July 2026. Its open-source scanning identified another 5,500 between April and October, with more than 33,000 findings rated high or critical.
However, the figures draw on partial partner reports, and fewer than half disclosed patch counts. Discovery totals therefore should not be read as completed fixes.
CVP generally requires data retention for misuse monitoring, with temporary exceptions for eligible zero-retention customers. Planned Enterprise Frontier Safeguards will let eligible organizations keep monitoring data in cloud infrastructure they control.
Organizations can apply for CVP with proof of required security controls. Access is available through Claude Platform, Google Cloud Vertex AI, and Microsoft Foundry; Amazon Bedrock access requires EFS eligibility. Existing members retain previous settings and receive automatic evaluation for newer models.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.