Claude Cyber Verification Program Opens to More Defenders

Claude Cyber Verification Program Opens to More Defenders

Anthropic is widening the circle of people who can use Claude for offensive-style security work. The company's Cyber Verification Program (CVP) is now open to a much broader group of security professionals. Vetted participants get access to Anthropic's most capable models with some of the usual safety filters turned down.

The reason for gating this at all is simple. The skills that help a defender find a flaw are the same skills that help an attacker exploit it.

What the public models refuse, and what they don't

The standard, publicly available Claude models block most of the work security teams care about most: vulnerability research, malware analysis, incident response and penetration testing. A model that can take apart malware or map an attack path for a defender could do the same for someone with worse intentions.

Not everything is locked away. Routine tasks such as reviewing code or patching known flaws still work without any special clearance. The CVP covers the riskier end of the spectrum, where Anthropic wants to know who is asking before it answers.

Three tiers of access

The program sorts participants into three levels, each with a different scope.

1. Defense Access

This is the broadest tier. It is open to corporate security teams, government agencies, universities, critical infrastructure operators, open-source developers and individual researchers. Individual researchers can apply directly, which matters for the many people who do security work outside a large organization.

2. Red Team Access

This tier allows authorized attack simulations, the controlled "break in to find the weak spots" exercises that red teams run against their own or their clients' systems. Only organizations qualify. Individuals cannot apply for this level.

3. Specialized Access

The most restricted tier covers testing of high-stakes systems such as flight controls, power grids and banking infrastructure. Here Anthropic does not vet applicants alone. It reviews every applicant together with the US government.

The structure follows a clear logic: the more damage a misuse could cause, the tighter the checks on who gets in.

The numbers behind the expansion

The CVP builds on an earlier effort called Project Glasswing. According to Anthropic, partners in that program found at least 129,000 confirmed vulnerabilities between April and July 2026. More than 33,000 of them were rated high-severity or critical.

Those figures deserve some context. They come from surveys of only a subset of Glasswing partners, not from a full count. Anthropic says the real-world impact is at least five times higher than the reported numbers. That is the company's own estimate, and it has not been independently verified.

Several partners also said the AI sped up their work by months, and in some cases by years. That is a large claim. If it holds even partly, it explains why Anthropic wants more defenders using these tools.

The Bigger Picture

This move suggests the major labs are settling on a shared answer to the dual-use problem in cybersecurity: keep the public models cautious, then hand stronger capabilities to verified defenders. Google's push into defensive cyber AI points the same way. Anthropic's own government offering shows how closely this work is now tied to public institutions.

The pressure is also rising from outside. Open-weight models are getting close at exploit building, and those come with no verification gate at all. That weakens the case for withholding capability from defenders.

For readers on security teams, this could mean real gains in speed. Several things are worth watching: how strict the vetting turns out to be in practice, whether Anthropic publishes fuller data than partner surveys, and whether any misuse slips through the tiers.