As reported by The Hacker News, Anthropic has expanded its Cyber Verification Program (CVP), offering vetted cybersecurity professionals tiered access to Claude models with reduced safeguards for defensive and offensive security work. The announcement arrives alongside Project Glasswing's claim of 129,000+ verified vulnerabilities discovered between April and July 2026 — a staggering figure that demands scrutiny not for its magnitude, but for what happens next.

AI Security Alert: As reported by The Hacker News, Anthropic has expanded its Cyber Verification Program (CVP), offering vetted cybersecurity professionals tiered access to Claude models with reduced safeguards for defensive and offensive security work.

The headline number is impressive, but the operational reality is more nuanced. VulnCheck's analysis, cited in the original report, found that only 2 of 300 Glasswing-discovered vulnerabilities — roughly 0.67% — have been exploited in the wild. This is a critical data point that reframes the entire conversation: AI-driven vulnerability discovery is outpacing attacker interest by orders of magnitude. The bottleneck is not detection; it is prioritization and remediation.

The Tiered Access Model Deserves Attention

Anthropic's three-tier structure — Defense, Red Team, and Specialized Access — represents a maturing approach to dual-use AI governance. The CyScenarioBench results are telling: Red Team Access completed 34 of 50 tasks with zero blocks, matching unsafeguarded performance. This means Anthropic has effectively created a controlled channel where offensive capabilities are available without the friction that would otherwise make the tool impractical for authorized testing.

The real question isn't whether AI can find vulnerabilities — it clearly can, at industrial scale. The question is whether defender workflows can absorb, triage, and remediate that volume without drowning in noise.

What This Means for Security Programs

For CISOs and vulnerability management leaders, this development has three immediate implications:

The Tiered Access Model Deserves Attention
Triage capacity becomes the bottleneck. If your team is already struggling to patch known CVEs, an AI firehose of 129,000 findings — even filtered to the 33,000+ rated critical or high — will overwhelm existing workflows. Expect a need for automated prioritization frameworks that incorporate exploitability scoring, asset criticality, and exposure context.
Responsible disclosure pipelines will strain. Anthropic notes the true impact is likely 5x higher than surveyed data suggests. That implies hundreds of thousands of reports potentially flowing to vendors and maintainers. Coordinated vulnerability disclosure (CVD) processes at many organizations are not built for this volume.
The offensive-defensive AI gap is narrowing. If vetted defenders get Claude Opus 5.5 with reduced safeguards, adversaries will seek equivalent capabilities through open models or jailbroken commercial systems. The asymmetric advantage is temporary.

Who Is Most Affected

Open-source maintainers and organizations with large codebases are the primary beneficiaries — and the primary stress points. The 5,500 additional vulnerabilities found through open-source scanning point directly at supply chain risk. Enterprises heavily reliant on third-party and OSS components should expect downstream CVE disclosures to accelerate and plan remediation capacity accordingly.

Shield53 Recommendations

  • Audit your vulnerability intake pipeline now. Map how findings flow from discovery to triage to remediation. If the process is manual or committee-driven, it will break under AI-scale volume. Invest in programmatic prioritization using EPSS, KEV catalog cross-referencing, and business-context weighting.
  • Apply for CVP if your team qualifies. Defense and Red Team tiers offer capabilities that can materially accelerate your own code review, threat modeling, and penetration testing. Evaluate whether Claude-assisted analysis fits your existing security workflows — particularly for malware reverse engineering and vulnerability validation.
  • Brief leadership on remediation capacity gaps. Use the Glasswing numbers as a forcing function to justify budget for vulnerability management tooling and headcount. The problem is no longer finding bugs — it is fixing them at the rate they are being discovered.
  • Monitor the exploitation gap. The 0.67% exploitation rate is reassuring today but will not stay static. Track CISA KEV additions and threat intel feeds for Glasswing-originated CVEs. Build alerting for any discovered vulnerability that crosses into known-exploited status.
  • Review your CVD process for volume readiness. If you are a vendor or open-source maintainer, ensure your security contact and disclosure workflow can handle batch reports. Consider automated intake and acknowledgment systems.

Anthropic deserves credit for building a structured access model rather than simply removing safeguards. But the security community's measure of success for programs like Glasswing should not be vulnerabilities found — it should be vulnerabilities remediated before exploitation occurs. That metric is far harder to move, and no AI model alone can close that gap.