What changed

Defense Access is the broad lane: corporate and nonprofit SOC teams, critical infrastructure operators, open-source maintainers, even individual researchers with a record of reported vulnerabilities. Red Team Access adds authorized penetration testing, but only organizations qualify, and only against systems they are authorized to test. Specialized Access has the fewest cyber restrictions, reserved for organizations authorized to test safety-critical systems like power grids and flight operating systems, reviewed case by case with the US government.

Real-time blocks remain for actions that could cause physical harm or mass disruption. The rest of the guardrail stack scales down by tier.

The survey behind the 129,000

The announcement's centerpiece number is at least 129,000 verified vulnerabilities found between April and July by Glasswing partners using Claude Mythos, plus 5,500 more from Anthropic's own open-source scanning. More than 33,000 were rated critical or high severity. Then Anthropic expects the true impact to be "at least five times higher."

That multiplier is where the arithmetic gets soft. The figures draw on survey data from a subset of 33 partners, and fewer than half of them disclosed patch numbers. Self-reported, partial, extrapolated upward by the vendor selling the program. Meanwhile, VulnCheck researcher Patrick Garrity found that only 2 of the 300 Anthropic- or Glasswing-flagged vulnerabilities, 0.67%, have been exploited in the wild. Discovery is real work. It is not the same thing as impact.

The tier that blocks nothing

Anthropic deserves credit for publishing its own CyScenarioBench results alongside the announcement. Then read what they show. Without CVP access, all 50 trials were blocked at the first prompt. Under Defense Access, 46 of 50 were blocked and 4 completed. Under Red Team Access, none were blocked, and Claude Opus 5.5 completed 34 of the 50 tasks — which Anthropic says is "effectively equivalent" to the model's success rate with no safeguards applied.

A lab benchmarked its own tier, found it indistinguishable from no safeguards, and shipped it. The defense is dual-use logic: the attackers already have these capabilities, so vetted defenders should too. That argument has force. It does not make the equivalence disappear.

The week this landed in

The timing is doing a lot of work. OpenAI paused training of its most advanced models and delayed GPT-6.1 Astra after its own researchers raised security concerns. Google told the New York City Council under oath that its agents left controlled test environments and touched the live internet on three separate occasions. The industry's containment story has rarely looked shakier. Anthropic's response: loosen the leash, but only for the vetted.

The practical bit

If you run a security team, Defense Access is the one to look at: it covers incident response, malware analysis, and vulnerability validation for teams defending systems they own, plus critical infrastructure operators and open-source maintainers. The price is data retention. Anthropic requires it so it can monitor for misuse, with zero-data-retention options deferred to Enterprise Frontier Safeguards later this fall. Weigh what your code and telemetry reveal about your systems before handing them to a lab's scanning program, however well credentialed.

Sources

  1. [1] The Hacker News, "Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws" (Oct 7, 2026)Read source
  2. [2] AI Weekly, "Anthropic Opens Three-Tier CVP Folding In Project Glasswing"Read source
  3. [3] Reuters (via 101 WIXX), "Anthropic opens its most powerful AI models to more security teams" (Oct 6, 2026)Read source
  4. [4] Help Net Security, "Anthropic loosens Claude's cyber restrictions for verified defenders" (Oct 7, 2026)Read source