2026-10-11 17:14 UTC

Anthropic's Project Glasswing, now joined by Oxide, will develop into a substantive cross-industry effort establishing practical security infrastructure and standards for AI agents.

state: corroboratedheat: lowuncertainty: mediumconvergesscott: mediumagentic-security agent-harnessesAnthropicOxide

What is this?

Project Glasswing is an Anthropic-led coalition (launched April 2026 alongside Claude Mythos, a frontier vulnerability-finding model Anthropic chose not to release publicly) that gives vetted organizations access to the model for defensive security work — finding and patching flaws in critical software before attackers can. Self-disclosed participants now span Oxide Computer (Mythos 5 pointed at its own firmware-to-network stack), Verizon and AT&T in telecom, TrendAI (Trend Micro), healthcare vendor Epic, and AWS, Apple, Nvidia and Google, with Anthropic committing up to $100M in usage credits and $4M to open-source security organizations; on Oct 6, 2026 Anthropic folded Glasswing members into an expanded three-tier Cyber Verification Program with open applications and reported ≥129K partner-found verified vulnerabilities for Apr–Jul 2026 — self-reported, explicitly unaudited, and met with community skepticism. The snippets are thin and partly conflicting on scope: one low-quality piece (placeholder citations) reframes Glasswing as securing AI datacenter infrastructure itself, while every first-party account consistently describes defensive vulnerability research on participants' own software. None of the supplied material shows the standards-for-securing-AI-agents or independent governance layer the hypothesis predicts — Glasswing is so far substantiated as a scaling, Anthropic-controlled model-access and verification regime, not a standards body.

Why it matters to Scott

Anthropic's Oct 6 tiered CVP operationalizes the evidence-gated access ladder Scott already codified in Earned Autonomy and the Gate Criteria Framework — and hands him dated receipts on its weak points: Glasswing members jump to Specialized Access 'without reapproval' and the 129K-vuln outcomes are producer-reported with no independent audit, exactly the missing rejective mechanism his Verification Loops canon says not to accept. It is also concretely actionable rather than merely illustrative: Defense Access is open to open-source maintainers and individual researchers, and his WordPress.org plugin portfolio plus his manual plugin security-review project are precisely the workload it would accelerate — though the agent-security-standards layer his hypothesis watches for (Provenance Stack / containment territory) still hasn't materialized, so the harness half of his canon stays unborne-on.
ip:concept.earned-autonomyip:framework.gate-criteria-frameworkip:concept.verification-loopsip:source.security-reviewer-method-ebookwork:project.wordpress-orgdev:project.wordpress-security-reviewradar:anthropic-mythos51-cvp-rolloutradar:openai-daybreak-frontline-subsidiesradar:openai-daybreak-cyber-defense-subsidyradar:white-house-gold-eagle-frontier-accessradar:openai-cyber-country-gatingradar:claude-security-plugin-beta
queries asked of Scott's wikis
  • agent harness sandboxing runtime limits untrusted input
  • restricted frontier model access tiers release gating
  • LLM security scanning own codebase workflow
  • agent trust verification standards frameworks
  • open source maintainer security program eligibility funding

Measured heat

now 0 pts/hpeak 162 pts/hcomments 0/hpeers p16momentum: steady3 platformsage 1826h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

10-06 19:00⭐ origin directly observedExpanding the Cyber Verification Program
surprisetalk on hacker news
—
07-27 14:00first on blog (echo) · published · +-1709.0hThe original announcement is Oxide’s own post: “Today we’re joining Anthropic’s Project Glasswing… As part of this collaboration, Oxide is a
Oxide Computer Company
—
07-28 12:39first on hacker news · published · +-1686.3hOxide Joins Anthropic's Project Glasswing
ErenayDev
—
09-28 09:27first on r/LocalLLaMA · published · +-201.5hNVIDIA shipped OpenShell, an open source sandbox that gives local and open agents real runtime limits instead of prompt rules. Over 100 firms joined the safety stack. OpenAI did not.
InternationalGap3698
—
09-28 10:57first on r/singularity · published · +-200.0hNvidia wants to put a watchdog chip next to every AI agent, and Anthropic and SpaceXAI are on board
ross2000
—
07-28 12:39amplified on hacker newshn.story.49082926
ErenayDev
peak 13 · 1 comments · 2% of case engagement
07-28 23:05amplified on hacker newshn.story.49091206
lwhsiao
peak 16 · 4 comments · 2% of case engagement
08-06 14:57amplified on hacker newshn.story.49197627
tosh
peak 4 · 1 comments · 1% of case engagement
09-22 15:22amplified on hacker newshn.story.49802825
gmays
peak 6 · 2 comments · 1% of case engagement
09-28 09:27amplified on r/LocalLLaMA 👑reddit.post.1ws9ydg
InternationalGap3698
peak 810 · 163 comments · 61% of case engagement
09-28 10:57amplified on r/singularityreddit.post.1wsbgsq
ross2000
peak 202 · 85 comments · 18% of case engagement
7 more amplifiers in ainews.case_chain
07-28 13:20our radar first saw it · +-1685.7hdiscovery anchor: hn.story.49082926—

Evidence (14) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnOxide Joins Anthropic's Project GlasswingErenayDev131
🟧 echo.blogThe original announcement is Oxide’s own post: “Today we’re joining Anthropic’s Project Glasswing… As part of this collaboration, Oxide is aOxide Computer Company——
🟧 hnOxide Joins Anthropic's Project Glasswinglwhsiao164
🟧 hnOxide Joins Anthropic's Project Glasswingtosh41
🟧 hnBuilding standards for the next phase of AIgmays62
🟠 redditNVIDIA shipped OpenShell, an open source sandbox that gives local and open agents real runtime limits instead of prompt rules. Over 100 firms joined the safety stack. OpenAI did not.
LocalLLaMA
InternationalGap3698810161
🟠 redditNvidia wants to put a watchdog chip next to every AI agent, and Anthropic and SpaceXAI are on board
singularity
ross200020282
🟠 redditThe Internet Is Safer: Project Glasswing Found 135K Verified Vulnerabilities, With at Least 9,333 Already Patched
singularity
ResultBackground245017918
🟧 hn ⭐Expanding the Cyber Verification Program
Retrieved article excerpt

Open article · Retrieved 2026-10-06T20:42:30.249072+00:00

Announcements

# Expanding the Cyber Verification Program

Oct 6, 2026

Expanding the Cyber Verification Program

We’re launching a new, expanded version of our Cyber Verification Program (CVP), which makes advanced cyber capabilities and reduced blocking classifiers available to qualifying security professionals. The program now consists of three access tiers, which allow security teams to apply for the level of access that best suits their work. Each tier includes access to our most capable models, including Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and new models moving forward. Interested customers can [apply here](https://portal.anthropic.com/programs/cvp).

Cybersecurity is inherently dual use: the same capabilities that enable a security team to find and fix a vulnerability can also help a malicious actor exploit it. For this reason, our generally available models, such as [Claude Opus 5.5](https://www.anthropic.com/claude-opus-5-5), [Claude Fable 5.1](https://www.anthropic.com/claude-fable-and-mythos-5-1), and [Claude Sonnet 5.5](https://www.anthropic.com/claude-sonnet-5-5), have conservative cyber safeguards that block most cyber work. This is intended to limit the harmful activities malicious actors can carry out using our models, while we continue to work to reduce false positives for secure coding.

But defenders also need access to the best tools and most powerful capabilities to secure their systems. For the past six months, we’ve enabled trusted access through two programs: [Project Glasswing](https://www.anthropic.com/glasswing) and the [CVP](https://support.claude.com/en/articles/14604842-real-time-cyber-safeguards-on-claude-opus-and-sonnet). The former gave a group of organizations securing the most critical software access to Claude Mythos; the latter gave vetted security teams access to reduced safeguards on Claude Opus and Claude Sonnet models.

Now, we’re integrating these programs into one expanded offering, designed to give more security organizations access to the capabilities they need to protect their systems.

### New access tiers

The updated access tiers make specific model capabilities available to security professionals based on the scope of their cyber work. Each has different verification requirements and security controls.

**Defense Access** is for defensive work, including security operations center and incident response tasks, reverse-engineering malware, and analyzing and validating vulnerabilities. Examples of qualifying organizations include security teams at companies, nonprofits, universities, and government bodies who are defending systems they own or maintain; operators of critical infrastructure of any size, such as regional hospitals or municipal utilities; smaller security firms; open-source maintainers; and individual researchers with a track record of reported vulnerabilities.

We expect many organizations conducting defensive cybersecurity work to qualify for this tier. We aim to respond to applications within a few days.

**Red Team Access** adds authorized penetration testing and red-teaming to the defensive uses above. Examples of qualifying organizations include in-house red teams, government red teams, and security and penetration testing firms. Organizations in this tier can only perform adversarial testing against systems they are authorized to test, including IT systems in critical industries. Users will still experience real-time blocks on actions that could cause physical harm or mass disruption, such as deploying ransomware, damaging physical systems, or pen testing high-risk safety systems.

Given the increased eligibility requirements and security controls, we expect applications in this tier to take a few weeks to review. Qualifying organizations will be enrolled in the Defense Accesstier while we review their Red Team Access applications. Currently, this tier is for organizations only; individual researchers are not eligible.

**Specialized Access**, which has the fewest cyber blocks, is reserved for a limited set of verified organizations that are authorized to test safety systems that could impact people’s lives or disrupt markets, such as flight operating systems, power grids, telecom networks, interbank transfer infrastructure, and government administrative networks.

For this tier, we currently review every organization in depth in collaboration with the US government. Existing members of Project Glasswing will transition to this tier and do not require reapproval for current models.

Our generally available models can continue to be used for tasks such as code review, patching known issues, vulnerability finding in owned source code, and triage of security alerts.

Data retention is required for organizations enrolled in the program so that we can monitor for cyber misuse. Once [Enterprise Frontier Safeguards](https://www.anthropic.com/news/enterprise-frontier-safeguards) (EFS)—a new solution that combines the privacy of zero data retention with robust safeguards—is available later this fall, eligible organizations will be able to store data in cloud infrastructure they control. Until EFS is available, organizations with access to Claude Fable 5.1 or Claude Mythos 5.1 with zero data retention can also use CVP with zero data retention. To register interest in EFS, [fill out this form](https://claude.com/form/enterprise-frontier-safeguards).

Below, we share an overview of what’s available at each CVP access level, as well as requirements for security and privacy controls:

Overview of the Cyber Verification Program tiers.

### Testing the efficacy of our tiers

To assess the efficacy of our CVP protections, we ran Claude Opus 5.5 through CyScenarioBench—an evaluation that measures whether models can plan and execute multi-stage cyber operations under realistic constraints—with safeguards tuned for our different CVP tiers. Because this evaluation involves complex, interactive offensive scenarios, we would expect Claude to experience significant blocks both on the generally available model and in the Defense Access tier, while experiencing no blocks in the Red Team Access and Specialized Access tiers.

Across five attempts at each of the 10 CyScenarioBench challenges in each access tier, we found that:

- Without CVP access, every task was blocked on the first prompt;
- In the Defense Access tier, 46 of the 50 trials were blocked at some point in the challenge, while the remaining four tasks succeeded; and
- In the Red Team Access tier, no blocks occurred, and Claude Opus 5.5 successfully completed 34 of the 50 tasks—effectively equivalent to the model’s 67.6% success rate on this evaluation with no safeguards applied (representative of Specialized Access).

These evaluations give us confidence that we can make advanced cyber capabilities safely available to a broader set of defenders, expanding the defensive efforts we began with Project Glasswing. We will continue to refine our tier-based classifiers over time.

On CyScenarioBench, our safeguards blocked 46 of 50 tasks on Claude Opus 5.5 in the Defense Access tier, while the Red Team Access tier on Claude Opus 5.5 did not block any tasks, and completed 34 of 50—the same completion rate as when no safeguards are applied.

## Giving defenders the advantage

Through Project Glasswing, we found that Claude Mythos models significantly increased the rate at which organizations were able to identify vulnerabilities in their systems. Through the program, our partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026. And through our own open-source scanning efforts, we found an additional 5,500 verified software vulnerabilities between April and October 2026. Of these verified vulnerabilities, more than 33,000 have so far been rated as critical- or high-severity. This is likely an undercount, as it is based on survey data from only a subset of Glasswing partners. As such, we expect the true impact to be at least five times higher.

When asked how long it would have taken them to find the same number of vulnerabilities without Claude Mythos models, several partners told us that the models had increased their rate of vulnerability finding by months or even years. Read more from our partners at [Booz Allen and Comcast](https://claude.com/blog/how-comcast-booz-allen-use-claude-mythos-to-secure-their-codebases) about their experience.

These results represent a lower bound on the program’s impact on third-party code, as they’re based on partial data from 33 partner reports and Anthropic’s open-source partnerships. Data limitations include that organizations took different approaches to triaging, and fewer than 50% of partners disclosed patched numbers, often because their fixes were still in progress, so the patch rate is significantly undercounted.

The changes we’re making to our Cyber Verification Program today are intended to extend the impact of Project Glasswing to a much larger number of cyber defenders. We’re also continuing our efforts to help secure open-source software and critical infrastructure. In the coming weeks, we’ll share more about this work and what we’ve learned as we continue to work to give defenders a permanent advantage.

## Apply for access

Interested organizations can [apply to CVP here](https://portal.anthropic.com/programs/cvp). As part of the application process, we will verify all applicants and request proof of the required security controls for the relevant access tier. Existing CVP members will keep their current settings for previous models and will be automatically evaluated for access to Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1 through the updated program. Admins will need to assign access to specific workspaces by following [these steps](https://support.claude.com/en/articles/16764810-assign-a-program-to-workspaces-in-claude-console).

CVP is available on the Claude Platform, Google Cloud’s Vertex AI, and Microsoft Foundry. CVP is only available on Amazon Bedrock for customers eligible for [Enterprise Frontier Safeguards](https://www.anthropic.com/news/enterprise-frontier-safeguards).

If you’re blocked on work you think your tier should allow, you can [report it here](https://claude.com/form/cyber-block-false-positive-report-cvp-rejection-appeal). Full details on each tier can be found in our [Help Center](https://support.claude.com/en/articles/14604842-real-time-cyber-safeguards-on-claude-opus-and-sonnet).

## Related content

### Anthropic invests $100 million to train 10,000 engineers and tackle the enterprise AI talent gap

Anthropic is investing $100 million in Claude Frontier Academy to train 10,000 Frontier Deployed Engineers by the end of 2027, with cohorts from Accenture, Bain, CBA, Deloitte, McKinsey, Morgan Stanley and Novo Nordisk already underway.

[Read more](https://www.anthropic.com/news/claude-frontier-academy)

### Barclays scales Claude to upgrade operations and improve client experience

Barclays, the British universal bank, is expanding its strategic collaboration with Anthropic to integrate secure, enterprise-grade AI systems across its global operations.

[Read more](https://www.anthropic.com/news/barclays-scales-claude)

### Claude discovers a novel enzyme system with CRISPR-like repeats

We’re announcing a new life sciences research group and laboratory at Anthropic. This post introduces the team behind this work and shares early results in which Claude discovered a novel enzyme system with properties reminiscent of CRISPR, with only high-level direction from our scientists.

[Read more](https://www.anthropic.com/news/claude-discovers-novel-enzyme-system)
surprisetalk42
🟧 hnExpanding the Cyber Verification Programsoltanov40
🟧 hnThe Anthropic Cyber Missionsurprisetalk60
🟧 hnLaunching an opt-in vulnerability-finding service for open-source softwaredi41
🟧 hnOSS Scanner by Anthropic0natcer31
🟧 hnOSS Scannervinhnx50

Interpretation history

Decision trace