IT Home October 7 news: According to Reuters, Anthropic is expanding a program that allows vetted cybersecurity professionals to test its most powerful AI models with fewer safeguards, after the company's "Project Glasswing" helped discover more than 100,000 software vulnerabilities this year.

According to ITHome, Project Glasswing aims to safeguard the security of critical software worldwide. Partners in the program found at least 129000 verified vulnerabilities between months 4 and 7, while Anthropic's own open-source scanning work additionally uncovered 5500 vulnerabilities between months 4 and 10.
So far, more than 33,000 vulnerabilities have been rated as critical or high severity.
Anthropic said these figures likely involve statistical undercounting and that the actual impact is at least five times the current numbers, because the data comes from a survey of a limited number of partners.
The new Cyber Verification Program (CVP) was officially unveiled on Tuesday local time, consolidating the two programs Anthropic has run over the past six months.
The first is Project Glasswing, which opens access to Claude Mythos to organizations responsible for protecting the security of critical software — Anthropic's most capable model series for cybersecurity. The second is the earlier Cyber Verification Program, which offers vetted security teams access to Claude Opus and Claude Sonnet models with reduced protective restrictions.
When the company released Claude Mythos Preview in April, it raised concerns that AI might hack software before it had completed security hardening.
The newly established program is divided into three tiers, each with corresponding vetting requirements and safety controls. All three tiers can use Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and new models released afterward.
The defense tier applies to work such as incident emergency response and malware analysis. Security teams, critical infrastructure operators, open-source project maintainers, and researchers with a track record of vulnerability reporting may all apply.
The red team tier adds, on top of that, authorization for penetration testing and red team exercises, but accepts only applications from organizations.
The specialized tier has the fewest restrictions and is open only to a small group of organizations; these organizations are licensed to conduct testing on security-critical systems such as power grids, aviation flight systems, and bank interbank transfer infrastructure.
Anthropic will vet the qualifications of each participating member together with the U.S. government, and existing members of the original Project Glasswing will be placed into this specialized tier.
