SecureWorld News

Anthropic Widens Access to Bug-Hunting AI. Remediating Is Still the Hard Part

Written by Drew Todd | Thu | Oct 8, 2026 | 12:27 PM Z

Anthropic wants more defenders to use AI models that have spent the past six months finding software vulnerabilities faster than any human team could. On October 6th, the company announced that it is folding its Cyber Verification Program (CVP) and Project Glasswing into one program with three access tiers. Each tier includes Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and future models, with reduced cyber safeguards for qualifying cybersecurity professionals.

The pitch is built on discovery. Anthropic says Glasswing partners found at least 129,000 verified vulnerabilities in four months. But the data on what happened to those findings tell a different story: few have been fixed, and fewer still have been exploited. For practitioners, the expanded program raises a question the announcement doesn't fully answer: what happens after the AI finds the bug?

What changed

Until now, the two programs served different groups. Project Glasswing gave organizations securing the most critical software access to Claude Mythos, while the CVP gave vetted security teams reduced safeguards on Opus and Sonnet models. The merged program sorts applicants by the kind of work they do.

Defense Access is the broadest tier. It covers SOC and incident response work, malware reverse engineering, and vulnerability analysis and validation. Eligible applicants include critical infrastructure operators of any size, such as regional hospitals and municipal utilities, along with smaller security firms, open-source maintainers, and individual researchers with a record of reported vulnerabilities. Anthropic aims to respond to applications within a few days.

Red Team Access adds authorized penetration testing. Actions that could cause physical harm or mass disruption, such as deploying ransomware or damaging physical systems, are still blocked in real time. The tier is open to organizations only, and reviews take a few weeks.

Specialized Access has the fewest blocks. It is limited to verified organizations authorized to test systems such as flight operating systems, power grids, telecom networks, and interbank transfer infrastructure, and Anthropic will review each applicant in collaboration with the U.S. government. Existing Glasswing members move into this tier.

All enrolled organizations must allow data retention so Anthropic can monitor for misuse, though a zero-retention option through Enterprise Frontier Safeguards is expected later this fall.

Anthropic also published test results to show the tier boundaries hold. On CyScenarioBench, an evaluation of multi-stage offensive cyber operations, the generally available model was blocked on the first prompt every time. Defense Access blocked 46 of 50 trials. Red Team Access blocked none and completed 34 of 50, matching the model's success rate with no safeguards applied.

The numbers behind the pitch

Anthropic's headline figure comes with caveats it acknowledges itself. The company says Glasswing partners found at least 129,000 verified vulnerabilities between April and July 2026, with more than 33,000 rated critical or high. The figure is based on survey data from a subset of partners, and fewer than half of them disclosed how many issues they had patched.

Outside researchers have been tracking a narrower slice of the pipeline. Patrick Garrity, a researcher at vulnerability prioritization vendor VulnCheck, analyzed Anthropic's public disclosure ledger. Of 26,153 total findings Anthropic reported, 2,736 had reached the ledger, and just 202 (0.8%) were marked fixed. The ledger and the partner survey are different datasets, so you can't compare the two figures directly. Still, the gap between "found" and "fixed" is the clearest public signal of where the work piles up.

Exploitation numbers are lower still. In a September analysis, Garrity found that only two of 300 vulnerabilities discovered by Anthropic or Project Glasswing (0.67%) have been exploited in the wild. The two are an SQL injection flaw in Ghost CMS and a session forgery flaw in Rejetto HTTP File Server. That aligns with the broader picture. VulnCheck's H1 2026 report found 14 of 1,061 AI-discovered vulnerabilities confirmed exploited, roughly the same rate as vulnerabilities overall.

Low exploitation doesn't mean the findings were trivial. "Vulnerability discovery and real-world exploitation are two very different things," said Aviv Nahum, Co-Founder and CEO of AI-native insider risk firm Above Security. "Attackers choose bugs based on reachability, economics, access, and operational value—not simply because a vulnerability exists."

Where the bottleneck actually sits

If attackers aren't rushing to use AI-discovered bugs, the more urgent problem is what defenders do with the flood of findings.

Acalvio CEO Ram Varadarajan sees the data as a diagnosis, not a reassurance. "A low exploitation rate shows that finding vulnerabilities was never the real bottleneck," he said. "Knowing which ones matter and stopping the ones that do is, and that's where AI-speed discovery must be paired with architectural defenses rather than treated as a finish line."

Noma Security CISO Diana Kelley rejects both easy readings of the numbers. "We shouldn't have to wait for an attack before a vulnerability is worth fixing," she said. "However, a large CVE count isn't proof of value either." Context decides priority. A valid finding on an exposed critical system, Kelley noted, differs greatly from one behind effective isolation.

Kelley and Nahum, speaking separately, reached nearly the same conclusion about how to measure success. For Kelley, it is how much risk a team can reduce, not how many vulnerabilities the AI finds. For Nahum, "the useful measure is not 'how many bugs eventually got exploited?'" He argued it is how much faster defenders can discover, validate, and understand meaningful weaknesses than they could before.

What this means for security teams

For most organizations, Defense Access is the relevant tier, and its real value may lie in triage rather than discovery. It handles "the SOC triage, malware reverse engineering, and vulnerability validation work that buries people," Varadarajan said, "while leaving judgment and accountability with them."

Amir Boldo, Above Security's Co-Founder and Chief Product and Technology Officer, puts the gain in investigation time. He said the value lies in "compressing the hours an analyst spends reconstructing what happened, why it happened, and whether it's actually risky," with the AI correlating activity and a human making the final call.

The eligibility list matters too. By naming regional hospitals and municipal utilities, Anthropic is reaching organizations that rarely have dedicated vulnerability research staff. "Powerful cyber capabilities shouldn't be limited to the biggest organizations," Kelley said. In OT and IoT environments, where patch cycles run long, Viakoo Vice President John Gallagher argued that early visibility into obscure device flaws gives defenders time to "close doors before threat actors even realize they're unlocked."

None of this works as a permanent advantage. Comparable capability will reach attackers through other models and providers, so Varadarajan's advice is blunt: "We must design defenses that assume an adversary with the same tools."

That makes visibility into how AI is used as important as access. Boldo pointed to Anthropic's mandatory retention and real-time blocks as a start, and argued every enterprise rolling out AI internally needs the same behavioral monitoring: "As these capabilities spread, the control question must move from 'who is allowed to use the model?' to 'what is this identity actually doing with it?'."

Verified access to frontier AI models will help more defenders find what's broken. Deciding what matters, fixing it, and building systems that hold up when attackers have the same tools is still the job.