Live
Abstract illustration of three nested hexagonal gates around a glowing core, with a dense cloud of small green diamonds on the left and only three blue diamonds passing out the right side
Privacy & Security

Anthropic Widens Mythos Access as Glasswing’s 129,000 Bugs Await Fixes

Ten attack scenarios, five tries each, one model. With no special access, Anthropic says Claude Opus 5.5 was stopped on the very first prompt of all 50 runs. Given a “Red Team Access” pass, the same model hit no blocks at all and finished 34 of them. That result, from Anthropic’s own CyScenarioBench test, is the company’s argument for handing its most capable hacking-adjacent models to a much larger pool of security teams.

On Oct. 6, Anthropic folded Project Glasswing, the invitation-only program that gave critical-software organizations early access to Claude Mythos, into an expanded Cyber Verification Program (CVP) with three tiers. Every tier gets Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, plus future models as they ship. The pitch is blunt: in the company’s words, “defenders also need access to the best tools.”

The harder question sits downstream. AI can now find software flaws faster than anyone can fix them, and the public evidence so far says the fixing is where the system jams.

Cyber Verification Program tiers: who gets what

Anthropic’s generally available models run classifiers that block most offensive security work. That has bitten defenders too: after Opus 5.5 launched on Sept. 22, most security tasks sent to it were routed to the older Opus 4.8, SiliconANGLE reported. The CVP is the exemption process. Here is how the three tiers break down, per Anthropic’s announcement:

  • Defense Access covers security operations, incident response, malware reverse engineering and vulnerability validation. It is open to security teams, critical infrastructure operators, smaller security firms, open-source maintainers and individual researchers with a record of reported vulnerabilities. Anthropic aims to review applications within a few days.
  • Red Team Access adds authorized penetration testing, but only for organizations, not individuals, and only against systems they are permitted to test. Actions that could cause physical harm or mass disruption, such as deploying ransomware, are still blocked in real time. Reviews take a few weeks; applicants sit in Defense Access while they wait.
  • Specialized Access has the fewest blocks and is reserved for verified organizations authorized to test safety-critical systems. SecureWorld lists flight operating systems, power grids, telecom networks and interbank transfer infrastructure as examples. Anthropic reviews each applicant in depth with the U.S. government, and existing Glasswing members move in without reapproval.

There is a price that isn’t money. Enrolled organizations must let Anthropic retain their data so it can monitor for misuse. A way to keep that data in customer-controlled cloud infrastructure arrives with Enterprise Frontier Safeguards “later this fall,” the company says; organizations that already have zero-data-retention access to Claude Fable 5.1 or Mythos 5.1 can join on those terms now. The program runs on the Claude Platform, Google Cloud’s Vertex AI and Microsoft Foundry. On Amazon Bedrock, it is limited to customers eligible for Enterprise Frontier Safeguards.

Red Team Access matched an unrestricted Claude

Back to those 50 runs. In the Defense Access tier, Anthropic says 46 of 50 trials were blocked at some point, which it expected because the scenarios are offensive by design. In the Red Team tier, nothing was blocked and Opus 5.5 completed 34 tasks, which the company says is effectively the same as the model’s 67.6% success rate with no safeguards at all.

Bar chart of Claude Opus 5.5 offensive tasks completed on CyScenarioBench out of 50 runs: 0 with no program access, 4 with Defense Access, 34 with Red Team Access, versus a 67.6% success rate with no safeguards.
Anthropic’s own benchmark shows its Red Team Access tier performing about the same as a model with no safeguards. Source: Anthropic. Graphic: prompt/power

Read that twice. Anthropic is telling customers that its middle tier removes the guardrails for practical purposes, and that the only remaining control is who gets admitted. Our read: that makes the vetting process, not the classifier, the real security boundary, and Anthropic has published little about how it checks a penetration-testing firm beyond a review that “takes a few weeks.”

The Register noted that Anthropic has not explained why it reorganized the programs, and that its own recent warning about Zhipu’s open-weight GLM-5.3 undercuts the idea that Mythos-class hacking is a moat worth gatekeeping. We covered that warning on Oct. 2: Anthropic’s red team said GLM-5.3 nearly matches Mythos at hacking and can have its refusals stripped cheaply. If attackers can download comparable capability, the case for widening defender access gets stronger. So does the case that the gate matters less than Anthropic implies.

The Glasswing numbers, and what they leave out

Anthropic’s headline figure is large. “Through the program, our partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026,” the announcement says, and the company’s own open-source scanning found another 5,500 between April and October. More than 33,000 have been rated critical or high severity.

“This is likely an undercount, as it is based on survey data from only a subset of Glasswing partners.” Anthropic, Oct. 6

The company says the figures come from partial data in 33 partner reports and that it expects the true impact “to be at least five times higher.” It also concedes that fewer than half of partners disclosed how many issues they had patched.

That is the gap critics keep pointing at. Using Anthropic’s own figures, The Register calculated that only 516 of 5,674 true-positive vulnerabilities have been patched. SecureWorld, citing VulnCheck researcher Patrick Garrity, reported that of 26,153 findings Anthropic has reported, 2,736 reached its public disclosure ledger and 202, or 0.8%, are marked fixed. The datasets don’t line up neatly, and SecureWorld says so. The direction is still consistent.

Finding bugs was never the bottleneck

Garrity has been tracking CVEs credited to Anthropic or Glasswing in a public repository. In a Sept. 21 interview with The Register, when his list held 225 CVEs, exactly one was confirmed exploited in the wild: CVE-2026-26980, a critical SQL injection bug in the Ghost publishing platform. By late September the count had reached two of 300, or 0.67%, according to The Hacker News, with a session-forgery flaw in Rejetto HTTP File Server added to the list.

That is not unusual. VulnCheck’s first-half 2026 data, reported by The Next Web, found 14 of 1,061 AI-discovered vulnerabilities confirmed exploited, about 1.3%, close to the 1.4% rate for CVEs overall. Garrity told The Register that “the real gap lies downstream in coordination, triage, remediation, and patch deployment.”

Patching at AI speed brings its own risk. Veracode’s 2026 research found that “roughly 44% of AI code generation tasks introduced a risky security vulnerability in tests,” according to The Hacker News. Maintainers are already drowning: on Oct. 1, Google paused product reports in its open-source bug bounty after a surge of mostly invalid automated submissions.

Outside voices quoted by SecureWorld split on what the numbers prove. “A low exploitation rate shows that finding vulnerabilities was never the real bottleneck,” said Ram Varadarajan, CEO of Acalvio. Diana Kelley, CISO at Noma Security, argued the other side of access: “Powerful cyber capabilities shouldn’t be limited to the biggest organizations.”

What it means for security teams

If you run security for a hospital, a utility, a university or an open-source project, Defense Access is the realistic entry point, and the application is at Anthropic’s CVP portal. Existing CVP members are evaluated automatically for the new models, Help Net Security reported. Read the retention terms before you paste incident data into it. Canadian organizations should note that the one government named in Anthropic’s vetting process is the U.S. government.

And budget for the second half of the job. A model that completes 34 of 50 offensive scenarios will hand your team more findings than it has ever triaged. Somebody still has to ship the 517th patch.

// Columnist, Security & Privacy
Oman Hassan

Oman Hassan covers cybersecurity and privacy for prompt/power: breaches, exploits, surveillance and the policy that follows them. He assumes the password is "password" until proven otherwise.

Latest from prompt/power

  1. AI Safety Hearing: MPs Will Question OpenAI, Anthropic, Google and Meta on 13 OctOct 11
  2. National Medal of Science Goes to Musk, Brin, Huang and Su. Nvidia Pledged US$1BOct 10
  3. TikTok Placebo Safety Test: New York Says Teens Got a Fake Feed ResetOct 10
  4. Waymo Takes Its First Loan, US$5 Billion, as Robotaxis Head OverseasOct 10
  5. Claude Haiku 5.5 Price: 90% Cheaper Until Your Prompt Hits 100K TokensOct 10

Leave a Reply

Your email address will not be published. Required fields are marked *