Independent newsroom

Wednesday, October 7, 2026

The File

Every claim traces to a primary source. Uncertainty is labeled. Corrections are public.

Anthropic · Wednesday, October 7, 2026

Anthropic opens its strongest hacking-capable models to many more security teams

The File desk · Oct 7, 2026, 10:47 AM UTC

Status

Confirmed as a company announcement on anthropic.com, dated Oct. 6, 2026, 3:00 p.m. Eastern. Every performance number and vulnerability count below is Anthropic’s. This desk did not independently check them.

  • Confirmed

    Anthropic said it merged earlier programs into one Cyber Verification Program with three access tiers, including invitation-only Claude Mythos 5.1.

  • Confirmed

    The benchmark scores and the vulnerability totals are Anthropic’s own figures, including a company estimate that the true impact is “at least five times higher” than the partial survey.

Anthropic said Tuesday it is giving many more cybersecurity teams access to its strongest models, with fewer safety blocks, including the invitation-only Claude Mythos 5.1. It is folding two earlier programs into one, with three levels. Defense Access covers defensive work such as incident response and malware analysis. Red Team Access adds authorized break-in testing. Specialized Access covers systems such as power grids and flight software, and Anthropic says it reviews each applicant with the U.S. government. Its regular public models still block most hacking work, because the same skills that find flaws can also exploit them.

The post is dated Oct. 6, 2026. Anthropic says each tier includes its most capable models, including Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and new models after those.

Who can apply for Defense Access, in Anthropic’s list: company, nonprofit, university, and government security teams; operators of critical infrastructure of any size, “such as regional hospitals or municipal utilities”; smaller security firms; open-source maintainers; and individual researchers with a track record. Anthropic says it aims to answer within a few days.

Red Team review takes “a few weeks,” and only organizations qualify. Even then, Anthropic says real-time blocks stay on for things such as deploying ransomware or damaging physical systems. Specialized Access is where Project Glasswing members move. Anthropic says it reviews every organization in that tier in depth with the U.S. government. The post does not name which agency.

Members must let Anthropic keep their data so it can watch for misuse, until a planned “Enterprise Frontier Safeguards” option arrives “later this fall.”

Anthropic’s own test of Claude Opus 5.5 on a hacking benchmark it calls CyScenarioBench, 50 trials: with no program access, every task was blocked on the first prompt. In Defense Access, 46 of 50 were blocked at some point. In Red Team Access, none were blocked, and 34 of 50 succeeded. Those figures are Anthropic’s.

Anthropic also says Glasswing partners found “at least 129,000 verified software vulnerabilities” from April to July 2026, and that its own scanning found 5,500 more from April to October. More than 33,000 were rated critical or high severity. Anthropic says this is based on survey data from only some partners, and that the true impact is likely “at least five times higher.” That is a company estimate, not a count this desk checked.

What is still unknown or disputed

Primary sources

Every claim in this story is drawn from the documents below. If a fetch failed, that is recorded on the card.

  1. Source 1

    Expanding the Cyber Verification Program

    Anthropic · October 6, 2026

    The program now consists of three access tiers, which allow security teams to apply for the level of access that best suits their work. Each tier includes access to our most capable models, including Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and new models moving forward.

    https://www.anthropic.com/news/cyber-verification-program