Anthropic Expands Cyber Verification Program to Add Mythos 5.1
Anthropic's revamped Cyber Verification Program merges Project Glasswing into three tiers, opening Claude Mythos 5.1 access to more cyber defenders after partners found 129,000+ vulnerabilities.
Anthropic has merged its two controlled-access cybersecurity programs, Project Glasswing and the original Cyber Verification Program, into a single revamped Cyber Verification Program (CVP) with three access tiers. The top tiers grant vetted security teams reduced-safeguard access to Claude Opus 5.5, Claude Sonnet 5.5 and, for the first time at this scale, Claude Mythos 5.1 — Anthropic's most capable model class, which is otherwise kept out of public release. The company announced the change on October 6, 2026, alongside new figures showing just how much work the program has already found: more than 129,000 verified software vulnerabilities uncovered by partner organizations between April and July, plus another 5,500 found by Anthropic's own scanning through October, with over 33,000 of the combined total rated critical or high severity.
- What's new: Project Glasswing and the Cyber Verification Program are now one program with three access tiers: Defense Access, Red Team Access and Specialized Access.
- Model access: Defense Access and Red Team Access both reach Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, plus future models as they ship.
- Vulnerabilities found: 129,000+ by Glasswing partners (April–July 2026) and 5,500+ by Anthropic's own scanning (April–October 2026); 33,000+ rated critical or high severity.
- How to apply: Through portal.anthropic.com/programs/cvp; Defense Access decisions typically arrive within days, Red Team Access reviews take weeks.
- Where it runs: Claude Platform, Google Cloud Vertex AI and Microsoft Foundry.
What Anthropic announced on October 6
In a post titled "Expanding the Cyber Verification Program," Anthropic said it is folding Project Glasswing — its invite-only program that let security researchers use its most powerful, unreleased model against real-world vulnerabilities — into the Cyber Verification Program, the broader application process Anthropic already used to grant reduced safety restrictions to vetted defenders on Claude Opus and Sonnet. The result is one program, three tiers, and a wider path to the company's top-tier "Mythos-class" models for organizations doing legitimate security work.
The move matters because Anthropic, like other frontier labs, builds classifiers that block offensive cybersecurity capabilities — vulnerability discovery, exploit development, malware analysis at scale — by default, for everyone. The Cyber Verification Program is the mechanism by which an organization proves it is not a malicious actor and gets some of those blocks lifted for its own authorized systems. Folding Glasswing into it means the hundreds of organizations that program had already recruited, plus a much wider pool of defenders who apply going forward, now move through a single, clearer set of rules.
The three new access tiers, explained
Anthropic's announcement lays out three tiers, each granting progressively fewer safety restrictions:
| Tier | Who it's for | Model access | What's allowed |
|---|---|---|---|
| Defense Access | SOC teams, incident responders, malware analysts, vulnerability researchers | Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, plus future models | Defensive work on systems the applicant owns or is authorized to protect |
| Red Team Access | Penetration testers and red teams | Same models as Defense Access | Offensive testing, but only against explicitly authorized systems; real-time blocks on physical-harm or mass-disruption actions remain active |
| Specialized Access | Verified organizations securing safety-critical infrastructure (flight systems, power grids, telecom networks, interbank transfer rails, government administrative networks) | Same models, fewest cyber-specific blocks | The deepest reduction in safeguards; existing Project Glasswing members are moved into this tier automatically |
That last point is the clearest sign of continuity: the roughly 200 organizations that Glasswing had already recruited since its April 2026 launch don't reapply or lose access — they're carried over into Specialized Access, the tier with the fewest restrictions, because they were already vetted at that level of trust.
What Mythos 5.1 access actually means
Claude Mythos is Anthropic's internal name for its top-tier, non-public model class. The company has never released a "Mythos" model to the general public; instead, each Mythos release shares its underlying weights with a public sibling but ships with cybersecurity- and biosecurity-related safeguards largely removed, and it's handed only to organizations that have been through a verification process. Claude Mythos Preview was the first version, unveiled in April 2026 exclusively through Project Glasswing. Claude Fable 5 and Claude Mythos 5 followed on June 9, 2026 as a public/restricted pair built on the same base model, and Claude Fable 5.1 and Claude Mythos 5.1 arrived on September 1, 2026, with an extended knowledge cutoff and stronger coding and multi-step agent performance, per Anthropic's own release notes.
What's new as of October 6 is scale, not the model itself: Mythos 5.1 access is no longer limited to the closed Glasswing cohort. Any organization that clears Defense Access or Red Team Access review — a process Anthropic says can resolve in days for Defense Access — now reaches the same model tier. For a security team, that practically means using a Claude model for tasks that are normally fenced off entirely: reverse-engineering real malware samples, triaging and validating exploitability of newly discovered bugs, or analyzing attack chains without the model refusing or softening its output out of caution. It does not mean unrestricted access to building or running exploits against systems the applicant doesn't control — mass-disruption and physical-harm blocks stay in place at every tier.
The vulnerability numbers behind the expansion
Anthropic used the October 6 announcement to disclose results from the program so far. Between April and July 2026, Glasswing partner organizations found and verified more than 129,000 software vulnerabilities while using Mythos-class access on their own codebases and infrastructure. Anthropic's own open-source scanning effort — a separate initiative running from April through October 2026 — turned up another 5,500 verified vulnerabilities. Combined, over 33,000 of those findings were rated critical or high severity, the categories most likely to translate into an actual breach if left unpatched.
Those figures are the company's stated rationale for widening access rather than keeping it narrow: a controlled-access model that finds tens of thousands of real, exploitable bugs before attackers do is, in Anthropic's framing, a case for recruiting more defenders into the program rather than fewer. The company has not published a breakdown of which partners found which vulnerabilities, or in which products.
The Defender Advantage Fund for open-source maintainers
The October tiering announcement builds on an August move that's worth remembering for context. On August 21, 2026, Anthropic introduced the Defender Advantage Fund, referred to informally as 0xDAF — a $35 million commitment in Claude usage credits earmarked for organizations that help open-source maintainers find and fix vulnerabilities in the software underpinning much of the internet. The fund is aimed squarely at a persistent problem in open-source security: critical libraries are often maintained by small, unpaid teams who don't have the time or tooling to run continuous security scanning, let alone patch what they find. Anthropic's pitch is that Claude credits, channeled through security organizations rather than directly to individual maintainers, can fund the scanning and patching work those projects would otherwise skip.
The Defender Advantage Fund isn't new as of this week, but it's part of the same push: cheaper or free access to Anthropic's most capable models for the specific job of finding and closing security gaps, whether the applicant is a Fortune 500 security operations center or a maintainer of a widely used open-source library.
From a 12-member pilot to a single program
Project Glasswing didn't start as a 200-organization effort. Anthropic launched it on April 7, 2026 with 12 founding partners — including AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, Nvidia and Palo Alto Networks — and pledged up to $100 million in Mythos Preview usage credits across that group and roughly 40 other critical-software maintainers, according to Anthropic's program page. On June 2, 2026, the company added roughly 150 new organizations across more than 15 countries, shifting the program's focus toward critical infrastructure: utilities, hospitals, communications networks and hardware supply chains, with named participants including Okta, Samsung, SK Hynix, SK Telecom, NATO and the EU's cybersecurity agency ENISA.
That expansion is what grew Glasswing into the roughly 200-organization base that now folds into the new CVP's Specialized Access tier. The October 6 change is less about recruiting a fresh batch of partners and more about formalizing how everyone — longtime Glasswing members and brand-new Defense Access applicants alike — gets access to the same underlying models going forward, including whatever comes after Mythos 5.1.
Who can apply, and how
Anthropic is routing all three tiers through one application at portal.anthropic.com/programs/cvp. Defense Access, aimed at defensive security work like SOC operations and vulnerability triage, is the fastest track; Anthropic says applicants can expect a decision within days. Red Team Access, which permits authorized penetration testing and red-teaming in addition to everything Defense Access covers, takes longer to review, on the order of weeks, since Anthropic has to verify both the organization and the specific systems it's authorized to test. Specialized Access isn't a general-application tier at all right now — it's reserved for organizations securing safety-critical systems and is where existing Glasswing partners land automatically.
The program is available wherever Anthropic's models are already sold commercially: directly through the Claude Platform (formerly the Claude API), through Google Cloud's Vertex AI, and through Microsoft Foundry. That matters for larger enterprises that already run Claude through one of those channels for other workloads, since it means CVP access doesn't require standing up a separate billing or deployment relationship with Anthropic.
Why Anthropic is doing this now
Anthropic has been explicit that dual-use cyber capability is one of the areas it treats most cautiously in its own models — the same reasoning that keeps Mythos out of general release. Widening the Cyber Verification Program is the company's answer to a tension it has flagged repeatedly: a model capable enough to meaningfully help defenders find and fix vulnerabilities is, by the same token, capable enough to help an attacker find them first. Anthropic's bet, laid out across the Glasswing and CVP announcements, is that getting that capability into the hands of more verified defenders faster narrows the gap between when a flaw is discoverable and when it's patched — and the 129,000-plus vulnerability count is the evidence it's pointing to.
It's also a competitive marker. Anthropic has leaned on cybersecurity as a flagship use case for its highest-end models since Glasswing's launch, timed closely with the company's broader push into enterprise and government deals. Positioning Opus 5.5 and Sonnet 5.5 — the same models compared head-to-head for coding and reasoning work — alongside Mythos 5.1 inside one security program reinforces the message that Anthropic's commercial model lineup and its most restricted research model are part of a single, coherent access ladder rather than separate product lines.
What's next
Anthropic hasn't given a timeline for when Specialized Access might reopen to new applicants beyond the existing Glasswing base, or for the next model to join the Defense Access and Red Team Access tiers once something succeeds Mythos 5.1. The company has also not said whether the Defender Advantage Fund's $35 million allocation will be topped up as more open-source maintainers apply through it. For now, the practical change for any security team watching this space is straightforward: the application path to reduced-safeguard Claude access, including the Mythos tier, now runs through one program instead of two, and the bar to reach it is a verification review rather than an invitation. Expect Anthropic to publish updated vulnerability-discovery figures the next time it revisits the program, likely alongside whatever model follows Opus 5.5, Sonnet 5.5 and Mythos 5.1 into the lineup.
Frequently asked questions
What is Anthropic's Cyber Verification Program?
It's the application process through which vetted organizations get reduced safety restrictions on Claude models for authorized cybersecurity work, such as vulnerability triage, malware analysis and penetration testing. As of October 6, 2026, it has three tiers: Defense Access, Red Team Access and Specialized Access.
What happened to Project Glasswing?
Project Glasswing, Anthropic's earlier invite-only cybersecurity program, has been merged into the Cyber Verification Program. Its roughly 200 existing partner organizations are moved automatically into the new program's top tier, Specialized Access.
What is Claude Mythos 5.1?
Mythos is Anthropic's internal name for its most capable, non-public model class. Mythos 5.1 shares its underlying model with the publicly available Claude Fable 5.1 but has cybersecurity- and biosecurity-related safeguards largely removed, and it is only available to organizations verified through the Cyber Verification Program.
How do I apply for Cyber Verification Program access?
Organizations apply at portal.anthropic.com/programs/cvp. Defense Access decisions typically come back within days; Red Team Access reviews, which cover authorized penetration testing, take on the order of weeks.
How many vulnerabilities have Anthropic's cybersecurity partners found?
Glasswing partners found more than 129,000 verified vulnerabilities between April and July 2026, and Anthropic's own open-source scanning added another 5,500 through October 2026. Over 33,000 of the combined total were rated critical or high severity.
What is the Defender Advantage Fund (0xDAF)?
Announced August 21, 2026, it's a $35 million commitment in Claude usage credits for organizations that help open-source maintainers find and fix vulnerabilities in widely used software.
Sources
- Anthropic Newsroom: Expanding the Cyber Verification Programanthropic.com
- Anthropic: Project Glasswinganthropic.com
- Anthropic Newsroom: Claude Fable 5 and Claude Mythos 5anthropic.com
- Claude Blog: Bringing the cybersecurity capabilities of Claude Mythos 5 to more defendersclaude.com
- Claude Support: Release Notessupport.claude.com
Theo Park runs the AI desk at Pandromeda. He follows model launches from the frontier labs and the open-weight community, tracks the assistants and developer tools built on them, and explains what each release changes on pricing, capability and safety. His reporting leans on primary sources: model cards, technical reports, API documentation and the companies' own announcements.


