Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Anthropic expanded its Cyber Verification Program (CVP) to three tiers—Defense, Red Team, and Specialized Access—allowing vetted security teams to use advanced AI models like Claude Opus 5.5 with reduced safeguards
- Anthropic reported that Project Glasswing identified at least 129,000 verified software vulnerabilities between April and July 2026, with an additional 5,500 found through open-source scanning by October 2026
- Anthropic stated over 33,000 of the verified flaws were rated critical or high severity, though it called this an undercount and expects the true impact to be five times higher based on partial partner data
- CyScenarioBench evaluation showed Claude Opus 5.5 in the Defense Access tier blocked 46 of 50 cyber tasks, while Red Team Access completed 34 of 50 with no blocks—matching performance when safeguards are off
- VulnCheck researcher Patrick Garrity analyzed findings and determined only 2 of 300 Anthropic-identified vulnerabilities had been actively exploited, including CVE-2026-26980 in Ghost CMS and CVE-2026-61500 in Rejetto HTTP File Server
- Veracode found that 44% of AI-generated code patches introduced new security risks, with average model security pass rates stagnant at 56%, despite rising volumes of AI-written code in development pipelines
Why it matters: Security teams gain powerful AI tools to proactively defend systems, but the low exploitation rate of AI-found flaws and high risk of flawed AI-generated fixes reveal that scale doesn’t equal urgency—organizations must triage carefully or introduce new risks. The 44% failure rate in patch generation directly challenges assumptions about AI’s readiness for autonomous remediation.
Ask SkimNews




