ANTHROPIC has merged Project Glasswing into its Cyber Verification Program (CVP), creating a tiered access system for advanced cyber LLMs including Claude Opus, Claude Sonnet, and Claude Mythos. Glasswing previously granted access to Mythos for more than 40 organisations, but the expansion places all eligible users into three levels of capability with differing safeguards.
The broad Defence Access tier covers defensive work such as SOC and incident response, malware reverse engineering, and vulnerability validation; Red Team Access targets authorised adversarial testing; and Specialized Access, the most restricted tier, reserves testing of systems that could affect lives or critical infrastructure, such as power grids, air traffic systems, and interbank networks.
Existing Glasswing members will transition to the top tier, with new applications undergoing in-depth review, including involvement from the US government. Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1 are cited as the available capabilities across tiers, with access extended to organisations ranging from corporate security teams to government bodies and critical infrastructure operators.
The article notes that between April and July this year, partners using the models uncovered at least 129,000 verified software vulnerabilities, with a further 5,500 verified vulnerabilities found via open-source scanning to October. More than 33,000 of these are rated critical or high severity. Somer Seker, CISO at SOCRadar, warns that acceleration of discovery must be matched by remediation; otherwise, organisations risk building a backlog of exploitable weaknesses. Anthropic stresses that the tiered approach aims to reduce misuse, though cautions that verification of ongoing authorisation remains essential.