动察 Beating AI News Flash: Anthropic has expanded its Cyber Verification Program (CVP), merging the previous single-tier access and Project Glasswing into three tiers. Security teams that pass review can receive fewer cybersecurity blocks on Claude Opus 5.5, Sonnet 5.5, and Mythos 5.1. The newly added Red Team Access explicitly permits authorized penetration testing and red team testing.
The three tiers are Defense, Red Team, and Specialized. Defense is aimed at incident response, malware reverse engineering, and vulnerability analysis, and individual security researchers can also apply. Red Team is open only to organizations and allows testing of authorized systems. Specialized has the fewest restrictions and is mainly for rigorously vetted institutions to test critical systems such as power grids, flight systems, telecommunications networks, and bank transfers.
Anthropic ran 50 complex cyberattack tasks with Opus 5.5. The standard version was blocked in all 50 on the first round, and the Defense tier still had 46 blocked midway; at the Red Team tier, none of the 50 triggered a security block, and 34 were ultimately completed, essentially the same success rate as when such security restrictions are fully disabled. However, operations that could cause serious harm, such as ransomware and disrupting physical systems, are still prohibited.
Anthropic previously opened Mythos's advanced cybersecurity capabilities to only a small number of institutions through Project Glasswing. Partners confirmed at least 129,000 software vulnerabilities from April to July, of which more than 33,000 were high-risk or critical. Now Glasswing has been merged into CVP, and existing members directly enter the highest Specialized tier.

