Anthropic expands Cyber Verification Program and opens Claude Opus 5.5 and Mythos to more security teams
The company merged two restricted-access programs into one, the Cyber Verification Program, giving vetted security teams access to Claude Opus 5.5, Sonnet 5.5, and Mythos 5.1 with fewer safety guardrails.
Anthropic announced on Tuesday, October 6, 2026, an overhaul of its access program for cybersecurity professionals. The new Cyber Verification Program (CVP) merges two initiatives the company had been running separately for the past six months: Project Glasswing, which gave organizations responsible for critical software access to the Claude Mythos family, and the original CVP, which lowered safety guardrails on Claude Opus and Sonnet for vetted teams.
According to Reuters reporting published by the Economic Times, the consolidated program grows out of a concrete result: Glasswing partners found at least 129,000 verified vulnerabilities between April and July 2026, and Anthropic's own scanning of open source projects added another 5,500 findings between April and October.
For those who build software, this carries practical weight: models with reduced "guardrails" mean fewer automatic refusals when a prompt asks for an exploit to be generated, malware to be analyzed, or an end-to-end attack to be simulated. It's exactly the kind of friction that today makes a security team waste time rewriting prompts to get around the model's safety filters, instead of investigating the vulnerability itself.
The numbers behind the decision
Anthropic classifies more than 33,000 of the vulnerabilities found as critical or high severity. The company also admits the count likely underestimates the real problem: since the data comes from a limited sample of partners, its internal estimate is that the true impact is at least five times greater than what was reported.
This backdrop matters because it explains the urgency behind the expansion. Claude Mythos Preview, introduced in April 2026, had raised concern in the security community that an AI capable of automating attacks could be used to exploit software before it was patched. Six months later, Anthropic's narrative is that the same kind of capability, under verification, served to find and report flaws before attackers could.
Three tiers, three different audiences
The revised CVP organizes access into three tiers, each with its own verification criteria and safety controls. All three grant access to the same set of models: Claude Opus 5.5, Sonnet 5.5, Mythos 5.1, and future versions.
| Tier | Who it's for | What it unlocks |
|---|---|---|
| Defense | Security teams, critical infrastructure operators, open source maintainers, and researchers with a track record of reported vulnerabilities | Incident response and malware analysis |
| Red Team | Organizations only (not individuals) | Authorized pentesting and red team exercises |
| Specialized | A small group vetted with the U.S. government | Testing of mission-critical systems: power grid, flight systems, interbank transfer infrastructure |
The Defense tier is the one that matters most to those maintaining an open source project in Brazil: the entry requirement is a track record of reported vulnerabilities, not a corporate affiliation. Specialized, according to Anthropic, is the tier with the fewest restrictions on model use, even though it's the hardest to access: current Glasswing members migrate automatically into this tier, and vetting goes through the U.S. government, which in practice puts this level out of reach for teams outside the U.S., even the most qualified ones.
What changes for those building in Brazil
For architects and AppSec teams that today rely on traditional SAST/DAST tools, the expectation, according to Anthropic itself, is that access to models with fewer guardrails will reduce friction from automatically refused prompts, which could speed up triage of a large list of automated findings.
The point of caution is the same one that has always existed with restricted-access programs for guardrail-free models: the verification queue and the eligibility criteria. So far, Anthropic has not publicly detailed response times for companies outside the United States, nor whether vetting for the Specialized tier makes any exception for Latin American critical infrastructure operators.
For those maintaining an open source library used in production, applying to the Defense tier with a track record of reported CVEs is, today, the most direct path to this access, according to Anthropic's own description. It's worth noting that eligibility based on a "record of reported vulnerabilities" favors those who already practice responsible disclosure, which indirectly pushes the community toward formalizing that process if they want access to the program.
What remains open
Anthropic acknowledges that the 129,000-vulnerability figure is likely a floor, not the real total, and has not publicly detailed what share of Glasswing partners are companies outside the United States. There's also no estimated response time, in the source, for those applying now to the unified CVP, nor technical detail on which "guardrails" specifically are removed in each tier. For security teams in Brazil interested in applying, the practical path now is to follow the eligibility criteria published by Anthropic and start gathering, now, the track record of reported vulnerabilities that the Defense tier requires as a prerequisite.
Translated from the Brazilian Portuguese original · Read the original
Mistral Large 4 arrives in preview with 1 trillion parameters, focus on security and code
Mistral this week opened API access to Large 4, an open-weight 1-trillion-parameter model trained in European data centers, with strong benchmarks in code and cybersecurity.