Anthropic Expands Access to Advanced AI Models for Cybersecurity Professionals, Uncovering Over 100,000 Vulnerabilities
Anthropic has announced the expansion of its Cyber Verification Program (CVP), providing vetted cybersecurity professionals with greater access to its cutting-edge AI models, including Claude Opus 5.5, Sonnet 5.5, and Mythos 5.1, with fewer built-in safeguards. This move builds upon the success of Project Glasswing, an earlier initiative that, between April and July of this year, helped uncover over 129,000 verified software vulnerabilities, with an additional 5,500 identified through Anthropic's open-source scanning efforts. More than 33,000 of these were classified as critical or high-severity. The CVP now features three distinct tiers: Defense, Red Team, and Specialized, each with varying levels of access and verification requirements, designed to support activities ranging from incident response to authorized penetration testing of critical infrastructure.
This development is significant for cybersecurity practitioners because it democratizes access to powerful AI tools previously restricted by safety protocols. The sheer volume of vulnerabilities discovered through Project Glasswing underscores the efficacy of AI in rapidly identifying security flaws at a scale impossible for human teams alone. For organizations, this means a potential acceleration in their ability to proactively identify and patch vulnerabilities before they can be exploited by malicious actors who are increasingly leveraging AI themselves. The program's tiered structure is crucial, allowing for tailored access based on the sensitivity of the work and the expertise of the security professionals involved, thereby mitigating risks associated with powerful AI capabilities being misused.
This initiative fits within the broader trend of AI being a double-edged sword in cybersecurity. While AI is undeniably enhancing the capabilities of attackers, enabling them to discover vulnerabilities, generate sophisticated malware, and craft highly personalized phishing campaigns at unprecedented speeds, it is also becoming an indispensable tool for defenders. The industry is witnessing a rapid evolution where AI-powered defenses are becoming essential to match the pace and scale of AI-driven attacks. This includes AI for vulnerability prioritization, correlation of security signals, and accelerated incident response. The expansion of Anthropic's program is a testament to the growing understanding that AI must be used to combat AI, moving beyond traditional, reactive security measures to more proactive and intelligent defense strategies.
In practice, this means that cybersecurity teams should actively explore opportunities to integrate advanced AI tools into their vulnerability management and offensive security operations. Practitioners should consider applying for programs like Anthropic's CVP, particularly if their work involves critical software or infrastructure. Furthermore, organizations need to invest in training their security personnel to effectively utilize these advanced AI capabilities, understanding both their power and their limitations. It also highlights the ongoing need for robust human oversight and ethical considerations, as the ability to uncover vulnerabilities at scale also carries the responsibility of ensuring these findings are used constructively. The focus should be on establishing a continuous, AI-augmented security posture that can adapt to the rapidly changing threat landscape, rather than relying on periodic assessments.
#ai security#vulnerability management#penetration testing#ai models#cybersecurity#threat intelligence
Read original source