Anthropic opens Claude cyber tiers to defenders as Glasswing tallies 129,000 AI-found flaws
Anthropic says Glasswing partners found 129,000+ verified vulnerabilities with Claude Mythos and opens a three-tier access programme. For most IT teams, it means more patches.
Anthropic says partners in its Project Glasswing programme found at least 129,000 verified software vulnerabilities with its Claude Mythos models between April and July 2026, and on October 6, 2026 it opened a three-tier programme that gives vetted defenders access to the same class of models. For most IT teams the practical effect is not the programme itself but what comes with it: a larger, faster stream of patches in the software you already run, which your update process needs to absorb.
What happened, in plain English
Anthropic, the company behind the Claude AI models, runs a programme called Project Glasswing. Selected partner organisations use its most capable models, called Claude Mythos, to look for security bugs (vulnerabilities) in software — much of it open-source code that ends up inside everyday products.
On October 6, 2026, Anthropic published a new tally. Partners found at least 129,000 verified vulnerabilities between April and July 2026, and Anthropic's own scanning of open-source projects found another 5,500 between April and October. More than 33,000 were rated critical or high severity. Anthropic calls these numbers a lower bound and says, based on incomplete partner survey data, that it expects the true impact "to be at least five times higher."
At the same time, Anthropic merged Glasswing with its older Cyber Verification Program (CVP) into one scheme with three tiers. Ordinary, publicly available Claude models deliberately block most hacking-related work. Verified security teams can now apply to have some of those blocks lifted, so they can use the models for defence, authorised penetration testing, or — for a small set of vetted organisations — testing safety-critical systems such as power grids.
An analogy: imagine a building inspector who can suddenly check a thousand buildings a day instead of ten. The buildings did not get worse overnight, but the list of repair notices just got much longer — and someone has to do the repairs.
Independent numbers put this in proportion. VulnCheck researcher Patrick Garrity found that only 2 of roughly 300 vulnerabilities publicly credited to Anthropic or Glasswing — 0.67% — are known to have been exploited in real attacks, according to The Hacker News. One of the two is the Rejetto HFS file-server flaw we covered on October 6.
Are you affected? What to do now
Nobody needs to take emergency action because of this announcement. It matters to you in two ways: as someone who installs patches, and possibly as someone who could apply for access.
If you run or maintain software (almost everyone):
- Expect more security updates, especially in open-source components. Tens of thousands of AI-found bugs are moving through disclosure. Check that your patching cadence for operating systems, libraries, containers and self-hosted apps can absorb a higher volume.
- Know what you run. A software bill of materials (SBOM — a list of the components inside your software) or a dependency scanner tells you which new advisories actually apply to you.
- Prioritise by exploitation, not by headline count. Most AI-found bugs are not being exploited. Use known-exploited lists such as CISA's Known Exploited Vulnerabilities (KEV) catalog and your vendors' advisories to decide what to patch first. The Rejetto HFS and Ghost CMS flaws are examples that did reach attackers.
- Review AI-written fixes like any other code. If your developers use AI to write patches, keep human code review and security testing in place. Veracode research cited in coverage found that roughly 44% of AI code-generation tasks introduced a risky vulnerability in its tests.
If you are on a security team, an open-source maintainer, or a researcher:
- Decide whether Defense Access is useful to you. It covers SOC (security operations centre) work, incident response, malware reverse-engineering and vulnerability analysis. Eligible groups include corporate security teams, non-profits, universities, government bodies, critical-infrastructure operators, smaller security firms, open-source maintainers and individual researchers with a disclosure track record. Anthropic says reviews typically take days.
- Red Team Access is for organisations only — not individuals — and reviews typically take weeks. You may test only systems you are authorised to test; keep written scope and authorisation on file.
- Check the data terms before applying. Anthropic requires data retention so it can monitor for misuse, with limited exceptions. Run this past your privacy or compliance owner, especially if you would paste incident data or customer logs into the model. Anthropic says an option to keep data in customer-controlled cloud storage ("Enterprise Frontier Safeguards") is due this fall.
- Check the platform. The programme runs on Claude Platform, Google Cloud Vertex AI and Microsoft Foundry; on Amazon Bedrock it is limited to Enterprise Frontier Safeguards customers. Applications go through Anthropic's portal (portal.anthropic.com/programs/cvp).
The expert view
What is actually new. AI-assisted bug hunting is not new; Glasswing has been running since April, and Google's threat intelligence team recently reported that about half of AI-found vulnerabilities allow code execution. Two things change here. First, the scale claim: six figures of verified findings in four months. Second, the access model: instead of one invite-only partner list, a vendor is now formalising graduated "dual-use" access — the same capability gated by who you are and what you are authorised to do. Anthropic frames it directly: "the same capabilities that enable a security team to find and fix a vulnerability can also help a malicious actor exploit it."
How the gating works, conceptually. General-availability models refuse most offensive tasks. Verified tiers relax those refusals step by step while keeping real-time blocks on actions such as ransomware deployment or mass disruption. Anthropic reports that on its CyScenarioBench test with Claude Opus 5.5, Defense Access blocked 46 of 50 multi-stage attack scenarios while Red Team Access blocked none. That is the design working as intended — and also a reminder that the Red Team tier is, by construction, a capable offensive tool whose safety rests on identity verification, authorisation checks and monitoring. That is why the data-retention requirement exists.
Read the numbers carefully. "Verified vulnerabilities" is not the same as CVEs (Common Vulnerabilities and Exposures — public, catalogued IDs), and it is not the same as fixed. VulnCheck's September 8 analysis of earlier Glasswing data found that only a small share of findings had reached maintainers or been fixed, and that Claude's severity ratings ran well above maintainers' own (91.5% rated critical/high by the model versus 51.3% by maintainers). In July, VulnCheck also found, as reported by The Register, that AI-found bugs were being exploited at about the same low rate as all other vulnerabilities. The 129,000 figure comes from Anthropic and partner reporting; we found no independent audit of it.
Why it still matters. The bottleneck is shifting from finding bugs to fixing them. Open-source maintainers — often volunteers — receive the reports; downstream vendors must ship updates; IT teams must deploy them. If discovery has accelerated "by months or even years," as some partners told Anthropic, the remediation pipeline is where risk will now accumulate. Low exploitation so far is reassuring, but it measures the past. Attackers with comparable tools — open-weight models included — do not need a verification programme.
What we don't know. How many of the 129,000 have been disclosed, assigned CVEs or patched; how duplicates and low-impact findings were counted; how Anthropic verifies applicants and red-team scope in practice; and how well the real-time blocks hold up against determined misuse. We will update this story if Anthropic or independent researchers publish a reconciliation.
Official sources
- Anthropic — Expanding the Cyber Verification Program (October 6, 2026)
- VulnCheck — Anthropic Glasswing receipts (September 8, 2026)
- Coverage: The Hacker News — Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws
- Coverage: SecurityWeek — Anthropic Introduces 3-Tier Cyber Verification Program for AI Access
- Coverage: The Register — AI-found bugs aren't proving easier to exploit (July 28, 2026)