Anthropic Opens Claude Access to Red Teams and Verified Cyber Defenders With Reduced Restrictions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Anthropic has expanded its Cyber Verification Program, giving verified security professionals access to advanced Claude models with fewer cybersecurity restrictions. Announced on October 6, 2026, the update introduces three access tiers covering defensive research, authorized penetration testing, and testing of systems where failures could threaten lives or disrupt markets.

The program includes Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and future models. It brings Project Glasswing and the earlier verification program into one offering, replacing separate access paths with permissions matched to each team’s work.

The change addresses a challenge: tools that help defenders find security flaws can also help attackers exploit them. Anthropic’s public models retain strict cyber safeguards, while verified users receive fewer blocks based on their approved activities. Public access still supports code review, patching, vulnerability discovery in owned source code, and security alert triage.

Three Cybersecurity Access Tiers

Defense Access covers security operations, incident response, malware reverse engineering, and vulnerability analysis. Eligible applicants include company security teams, universities, government bodies, hospitals, utilities, smaller security firms, and open-source maintainers. Individual researchers with a record of reporting vulnerabilities can also qualify. Anthropic aims to respond within a few days.

Red Team Access adds authorized penetration testing and red-teaming. It is limited to organizations, including internal red teams, government teams, and security testing firms. Users must have permission to test their targets. Real-time controls still block ransomware deployment, damage to physical systems, and penetration testing involving high-risk safety systems.

Reviews for this tier may take several weeks. Qualifying applicants receive Defense Access during review, allowing defensive work to begin while Anthropic checks the requirements for broader testing permissions.

Specialized Access has the fewest cyber blocks and serves a limited group authorized to test power grids, flight systems, telecom networks, interbank transfers, and government networks. Anthropic reviews these organizations with the US government. Existing Glasswing members move into this tier without reapproval for current models, building on the earlier Glasswing expansion.

Testing and Vulnerability Findings

Anthropic tested Opus 5.5 using CyScenarioBench, which measures multi-stage cyber operations. Across 50 attempts per access setting, public access blocked every task at the first prompt.

Defense Access blocked 46 attempts, while four succeeded. Red Team Access produced no blocks and completed 34 tasks, close to the 67.6% success rate reported without safeguards. These are company-run benchmark results, not proof that harmful requests cannot bypass controls.

Anthropic also says Glasswing partners found at least 129,000 verified vulnerabilities between April and July 2026. Its open-source scanning identified another 5,500 between April and October, with more than 33,000 findings rated high or critical.

However, the figures draw on partial partner reports, and fewer than half disclosed patch counts. Discovery totals therefore should not be read as completed fixes.

CVP generally requires data retention for misuse monitoring, with temporary exceptions for eligible zero-retention customers. Planned Enterprise Frontier Safeguards will let eligible organizations keep monitoring data in cloud infrastructure they control.

Organizations can apply for CVP with proof of required security controls. Access is available through Claude Platform, Google Cloud Vertex AI, and Microsoft Foundry; Amazon Bedrock access requires EFS eligibility. Existing members retain previous settings and receive automatic evaluation for newer models.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

The post Anthropic Opens Claude Access to Red Teams and Verified Cyber Defenders With Reduced Restrictions appeared first on Cyber Security News.