Artificial Intelligence & Machine Learning,
Next-Generation Technologies & Secure Development
3 Access Tiers Cover Defense, Red Teaming and Critical Systems

In a notable development within the realm of cybersecurity, Anthropic has announced the opening of applications for its advanced artificial intelligence-powered cyber defense tools. This initiative is now accessible to any organization, marking a significant shift in the landscape of cybersecurity technology. The company’s move, disclosed on a Tuesday, aims to broaden the reach of its capabilities, particularly as open-weight models continue to close the technological gap in AI applications.
The expanded Cyber Verification Program integrates elements from Project Glasswing, which initially granted limited access to prominent users of its Claude Mythos AI model. In conjunction with Anthropic’s existing verification program—which had reduced restrictions on other models like Claude Opus and Sonnet—the new structure presents three distinct tiers of access. This initiative is indicative of the evolving landscape of AI-powered cyber defense, emphasizing the importance of equipping a larger pool of security defenders with the necessary tools to combat rapidly evolving threats.
With the rise of AI capabilities accessible to attackers, the expansion of these advanced resources to a broader audience of defenders is seen as vital. Security professionals widely regard this development as a prudent step towards countering increasingly sophisticated AI-driven attacks. By granting defenders early visibility into system vulnerabilities, organizations can enhance their readiness to respond to threats effectively and decisively.
Aviv Nahum, the co-founder and CEO of Above Security, expressed his concern regarding the limitations placed on defenders, stating, “I’m actually more worried about defenders being artificially held back than I am about capable cyber AI becoming widely available.” He emphasized the inevitability of these advanced capabilities proliferating among various models and providers, advocating for the need to ensure that defenders can arm themselves with equally sophisticated systems for continuous investigation, detection, and response.
Anthropic’s Cyber Verification Program aims to equip security defenders with advanced capabilities while reducing restrictions to facilitate usability. Organizations looking to participate can apply for the access tier that aligns with their specific operational needs. The lowest access tier is designed to support security operations centers, malware analysis, and vulnerability validation for researchers, open-source maintainers, critical infrastructure operators, and bug bounty hunters.
A separate red-teaming tier targets penetration testing teams, providing resources for offensive activities including authorized adversary emulation and the validation of exploits. At the highest tier, formerly known as Project Glasswing, organizations will be permitted to conduct offensive security testing against critical safety systems. These include critical infrastructures such as flight operating systems, power grids, telecommunications networks, interbank transfer systems, and government administrative networks. Anthropic elaborated that, for this top tier, every application is subject to comprehensive review in collaboration with the U.S. government. Existing members of Project Glasswing will seamlessly transition into this new tier without the need for additional approvals.
Despite varying tiers of access, enterprises recognize that the lowest tier may hold the most extensive practical applications. This tier assists security analysts in efficiently triaging and defining methodologies for vulnerability remediation. For security-focused organizations like Above Security, defending against attacks aligns more naturally with their operational strategies. Nahum noted that the organization prioritizes utilizing advanced models to investigate behaviors, analyze vulnerabilities, and understand attacks over relying solely on offensive testing capabilities.
Anthropic’s advanced models have already demonstrated their efficacy in identifying vulnerabilities at scale. The firm reported a staggering 129,000 verified software vulnerabilities identified between April and July, highlighting the potential of AI in driving improved security vigilance. Concurrently, EpochAI’s Common Vulnerabilities and Exposures (CVE) tracker indicated a notable surge in high-severity vulnerabilities stemming from various recognized organizations following the adoption of the Claude Mythos Preview. However, it is crucial to note that while many vulnerabilities were identified, only a small fraction were determined to be actively exploited.
Patrick Garrity, a researcher at the threat intelligence firm VulnCheck, pointed out that only two out of 300 CVEs recognized through Project Glasswing were subsequently exploited. A Google study published in late September highlighted that most AI-discovered vulnerabilities tended to be medium to low risk, indicating that only a mere 3% were classified as high-risk flaws. Nevertheless, experts in the field argue that low exploitation rates should not serve as a definitive measure of a model’s effectiveness in cybersecurity. John Gallagher, the vice president at Viakoo, remarked, “A 1% exploitation rate isn’t a sign of failure; it’s proof that proactive defense is working as intended.”
Experts emphasize that the timeline for recognizing exploitation can vary significantly. Andrew Yoon, the head of research at CivAI, elaborated that an exploit may not be utilized against real targets immediately following its development, creating further delays in its identification and association with a disclosed CVE. It is further noted that a vulnerability’s significance is not solely contingent on its being exploited; hence the imperative to assess the overall security landscape through multiple lenses.
Diana Kelley, the chief information security officer at Noma Security, echoed this sentiment, noting that a thorough understanding of risk extends beyond mere statistical exploitation figures. Validating findings on exposed critical systems carries different implications than those pertaining to environments with robust isolation protocols. Kelley concluded by stating, “The useful measure is not ‘how many bugs eventually got exploited?’ It is how much faster defenders can discover, validate, and understand meaningful weaknesses than they couldn’t before.” As the cybersecurity landscape continues to evolve, the push for broader access to AI-driven defense mechanisms stands as a clear testament to the industry’s evolving priorities aimed at safeguarding digital infrastructures.

