More than 129,000 verified software vulnerabilities found in four months is a number worth stopping on. That’s the output from Anthropic’s Project Glasswing between April and July, a figure the company says is almost certainly an undercount, with the real impact likely five times higher. And now Anthropic is expanding the program responsible for it.
As reported by Reuters, Anthropic has merged two of its existing cybersecurity access programs into a single restructured framework called the Cyber Verification Program, or CVP. The original CVP gave vetted security teams reduced safeguards on Claude Opus and Sonnet. Glasswing went further, giving organizations working on critical software access to Claude Mythos, Anthropic’s most capable model family for cyber tasks. The new CVP combines both into one tiered structure, and opens access to a broader set of verified professionals.
The timing matters. When Anthropic released Claude Mythos Preview in April, the reaction from parts of the security community was concern, not celebration. A model that capable of analyzing and finding vulnerabilities could, in theory, help attackers move faster than defenders. Anthropic’s approach has been to get ahead of that by putting the tool in defenders’ hands first, under strict vetting, and tracking what actually gets found. The 33,000-plus vulnerabilities rated critical or high severity suggest those defenders are putting it to work.
The new CVP has three tiers with different access levels and verification requirements. All three include access to Claude Opus 5.5, Sonnet 5.5, Mythos 5.1, and future models as they ship:
- Defense tier: Covers incident response and malware analysis. Open to security teams, critical infrastructure operators, open-source maintainers, and researchers with a track record of reported vulnerabilities.
- Red Team tier: Adds authorized penetration testing and red-teaming. Organizations only, not individuals.
- Specialized tier: The fewest restrictions, reserved for a small group authorized to test safety-critical systems like power grids, flight infrastructure, and interbank transfer networks. Vetting is done jointly with the US government. Existing Glasswing members move here automatically.
This is worth watching for a few reasons beyond the vulnerability counts. Anthropic is, in effect, building a credentialed ecosystem around its most capable models, one where access is earned through verification rather than just purchased. That’s a different model from how OpenAI or Google DeepMind have approached security research access, and it positions Anthropic as more embedded in serious defensive security work rather than just adjacent to it.
For security teams evaluating which AI tools to actually use in professional workflows, the CVP’s structure also signals something about where the capability ceiling is. If Anthropic is comfortable giving Mythos access to red teams for authorized penetration testing, that’s a practical endorsement of what the model can do in adversarial contexts. Competitors will need to respond with something comparable, or cede that segment of the market.
The program is still relatively small in terms of partners, which is exactly why Anthropic says the numbers are likely undercounts. Scaling verified access without compromising the vetting process is the real challenge ahead.




