✳ the wire · analysis

Anthropic opens Mythos 5.1 to more security teams with a three-tier Cyber Verification Program

Mythos 5.1confirmedby ArtificialWatch

Get launch alerts like this, free →

Anthropic opens Mythos 5.1 to more security teams with a three-tier Cyber Verification Program
Source imagery · verified against a primary source

Anthropic has expanded its Cyber Verification Program (CVP) into three access tiers that give verified security professionals reduced cyber safeguards on Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, plus new models as they ship. Until now, Mythos access for cyber work ran through Project Glasswing, a small group of organizations securing critical software. Anthropic announced the change on October 6 and says it folds Glasswing and the CVP into one program.

THE THREE TIERS

- Defense Access: defensive work such as incident response, malware reverse-engineering and vulnerability validation. Open to company and government security teams, critical-infrastructure operators of any size, open-source maintainers and individual researchers with a record of reported vulnerabilities. Anthropic aims to answer applications within a few days. - Red Team Access: adds authorized penetration testing and red-teaming. Organizations only, and Anthropic expects reviews to take a few weeks. Real-time blocks stay on actions that could cause physical harm or mass disruption. - Specialized Access: the fewest blocks, for a limited set of organizations authorized to test systems such as power grids, flight systems and interbank transfer infrastructure. Anthropic says it reviews each one with the US government. Glasswing members move into this tier.

Generally available models (Opus 5.5, Fable 5.1, Sonnet 5.5) keep conservative cyber safeguards. Enrolled organizations must allow data retention so Anthropic can monitor for misuse; Anthropic says a zero-retention route arrives later this fall through Enterprise Frontier Safeguards.

ANTHROPIC'S OWN FIGURES

On CyScenarioBench, its test of multi-stage cyber operations, Anthropic says Opus 5.5 was blocked on the first prompt of every task without CVP access, blocked at some point in 46 of 50 trials in the Defense tier, and never blocked in the Red Team tier, where it completed 34 of 50. Anthropic also says Glasswing partners found at least 129,000 verified vulnerabilities between April and July, and that more than 33,000 of the vulnerabilities it counts were rated critical or high.

WHAT WE DO NOT KNOW

How many organizations have been approved so far, and how fast applications clear in practice. The vulnerability counts come from partial partner surveys, and Anthropic itself calls them an undercount.

Source: Anthropic ↗ · Mythos 5.1 tracker · the bench index

sweeping every 60 seconds

Know the minute it drops — not the minute we write it up.

Claude Opus 5 went live at 16:51 UTC. The alert was in subscribers' inboxes at 16:52.

  • Free forever
  • No card
  • Unsubscribe in one click

← back to the wire