- Anthropic merged two security programs into one three-tier Cyber Verification Program, giving vetted teams Claude models with fewer safeguards, according to iTnews.
- Partners found at least 129,000 verified vulnerabilities between April and July. The reported figures measure discovery, not how many were fixed.
- Leaders should ask how many findings their teams can fix, and who in their supply chain has access to these tools.
Who gets the tool is now a security decision
When finding a flaw takes skilled human effort, people set the pace of discovery. When AI finds flaws in bulk, the limit moves. It becomes a question of who may use the tool, and who can keep up with what it finds.
Anthropic is widening a program for vetted security professionals, iTnews reports. The move follows Project Glasswing, Anthropic's effort to secure critical software, which contributed to a tally of more than 100,000 software vulnerabilities this year. The report does not say those numbers drove the decision.
The timing suggests a pattern. As machines find flaws faster, controlling who holds the tool becomes part of defence. That link is WebPulse's interpretation, not a statement from Anthropic or iTnews.
What Anthropic announced
The revamped Cyber Verification Program folds together two efforts that have run for roughly six months. Under Project Glasswing, groups responsible for protecting critical software could use Claude Mythos. iTnews calls Mythos Anthropic's most cyber-capable model family. The older Cyber Verification Program relaxed some safeguards on Claude Opus and Sonnet for checked security teams.
Every tier covers the same models: Opus 5.5, Sonnet 5.5 and Mythos 5.1, plus later releases. iTnews adds that when Anthropic first showed Mythos Preview in April, some feared AI might break into software before defenders could harden it.
What "fewer safeguards" means
This section is general context, not a claim from the report. AI models usually hold back on requests that could help attackers as much as defenders, such as dissecting malware or probing software for weaknesses. Reduced safeguards let a checked user get help with that work. The same skill serves both sides, which is why access is gated.
Also as context: a model can read code and test it for weaknesses far faster than a person. That shifts the slow step. Finding flaws gets quicker, while confirming, ranking and patching them typically still depend on people.
How the three tiers work
Across the tiers, access narrows as the work gets more sensitive. That is our observation from the tier descriptions, not a stated design rule.
The Defence tier is for defensive jobs such as responding to incidents and studying malware. Operators of critical infrastructure and open-source maintainers can apply. So can security teams, and researchers with a history of disclosed vulnerabilities.
The Red Team tier adds sanctioned attack testing, in which testers probe a system with the owner's consent. Only organisations may apply, not individuals.
Specialised is the least restricted tier. Few organisations qualify. They must be cleared to test systems where failure is dangerous, such as power grids, flight systems and the links that move money between banks. Anthropic checks each member jointly with the US government. Current Glasswing participants shift into this tier.
What the numbers say, and what they leave out
Anthropic's own open-source scanning turned up another 5,500 vulnerabilities between April and October. iTnews reports that over 33,000 of all findings are rated critical or high severity.
Anthropic says the figures come from a survey of a limited number of partners, so it expects the true impact to be at least five times higher.
That is Anthropic's estimate. The report does not show it was independently checked, and it does not explain how the five-times figure was derived. The figures also count findings. As reported, they do not say how many flaws were fixed, or how long fixes took.
The question for leaders
A discovery count is not a risk count. A flaw that has been found but not fixed is still open. For the people who maintain software, a longer list of findings means more work to triage and patch.
The tier structure also shows how access is handled. It runs through verified roles, and the top tier is vetted jointly with the US government.
Four questions are worth putting to your security team and suppliers this quarter:
First, how many verified findings can we fix in a month, and what happens to the rest? Second, do our critical software suppliers take part in programs like this one? Third, who on our side would qualify for the Defence tier, and is anyone applying? Fourth, if we run safety-critical systems, how do we learn what has been found in them?
Faster discovery helps only if fixing keeps pace. The number to watch is not how many flaws were found, but how many were closed.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: iTnews.





