Skip to content
Rush Commerce
Software & Dev3 min read

Anthropic Cyber Verification Program: 3 tiers, ask your MSP

Anthropic's expanded Cyber Verification Program opens Mythos-class security AI to small security firms in three tiers. What it means if you buy security, not sell it.

On October 6, Anthropic folded Project Glasswing into an expanded Cyber Verification Program with three access tiers. The short version: the security AI that was reserved for a few dozen large partners is now open to smaller security firms, critical infrastructure operators "of any size," and open-source maintainers. Defenders get it. Attackers already had their own.

What actually happened

Per Anthropic's announcement:

  • Defense Access. SOC and incident response work, malware reverse-engineering, vulnerability validation. Open to company security teams, smaller security firms, open-source maintainers, critical infrastructure operators like regional hospitals and municipal utilities, and individual researchers with a disclosure record. Anthropic says it responds to applications "within a few days."
  • Red Team Access. Adds authorized penetration testing. Organizations only, no individuals. Review takes a few weeks.
  • Specialized Access. Fewest blocks, for testing safety-critical systems like power grids and interbank transfers. Anthropic reviews each organization with the U.S. government.
  • Models. Each tier covers Claude Opus 5.5, Sonnet 5.5, and Mythos 5.1, on the Claude Platform, Vertex AI, Microsoft Foundry, and Amazon Bedrock (for Enterprise Frontier Safeguards customers).
  • The numbers behind it. Anthropic says Glasswing partners found at least 129,000 verified vulnerabilities from April to July, plus 5,500 more from its own open-source scanning. Over 33,000 were rated critical or high severity.

SiliconANGLE notes that real-time blocking still applies to clearly harmful use like ransomware, even in the higher tiers.

Why it matters for your business

Most small businesses will never apply. You are not a security firm. But the firm that watches your network might be, and that changes what you should ask it.

129,000 found bugs is also 129,000 patches somebody has to ship. The bottleneck has moved from finding flaws to fixing them. Your vendors' patch cadence just became a bigger risk than their bug count.

Three questions for your MSP or security vendor this quarter:

  1. Have you applied for Defense Access? If they do incident response and have not, ask why.
  2. What is your patch window for critical CVEs? Get a number of days, in writing.
  3. Who sees our data? CVP requires data retention on most models. Know where your logs go before they feed an AI triage tool.

If you run your own servers, the same logic applies inside your shop: an inventory of what you run and a patch schedule beat any scanner.

Key takeaways

  • Anthropic merged Glasswing into a three-tier Cyber Verification Program on October 6
  • Defense Access is open to smaller security firms, hospitals, utilities, and maintainers
  • Red Team Access is organizations only; Specialized Access is vetted with the U.S. government
  • Glasswing partners found 129,000+ verified vulnerabilities; fixing them is now the bottleneck
  • Ask your MSP if it applied, its patch window, and where your data goes

A long list of vulnerabilities is not a security plan. We build systems with short dependency lists, automated patching, and an inventory you can read. See how we build or ask us to look at your stack.

Sources: Anthropic, SiliconANGLE.

  • #anthropic
  • #cybersecurity
  • #claude-mythos
  • #msp
  • #vulnerability-management
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.