Хиймэл оюун ухааны хөгжүүлэгч Anthropic компани өөрийн кибер аюулгүй байдлыг шалгах “Cyber Verification Program” (CVP) болон “Project Glasswing” хөтөлбөрүүдээ нэгтгэж, гурван түвшинт шинэ бүтцийг танилцууллаа.
Anthropic 2026 оны дөрөвдүгээр сард өөрийн Mythos загвартай зэрэгцүүлэн эдгээр хөтөлбөрийг эхлүүлж байсан бөгөөд одоо илүү олон байгууллагад системийн эмзэг байдлыг илрүүлэх боломж олгохоор нэгтгэж байна. Шинэ бүтэц нь хамгаалалтын багуудад зориулсан “Defense Access”, кибер халдлагын туршилт хийх “Red Team Access” болон чухал дэд бүтцийг шалгах “Specialized Access” гэсэн гурван түвшингээс бүрдэнэ.
Компанийн мэдээлснээр, 2026 оны дөрөвдүгээр сараас долдугаар сарын хооронд түншүүд нь 129,000 орчим програм хангамжийн эмзэг байдлыг илрүүлснээс 33,000 гаруй нь өндөр эсвэл нэн ноцтой түвшинд үнэлэгджээ. Гэсэн хэдий ч илрүүлсэн 5,674 ноцтой эмзэг байдлын зөвхөн 516-г нь л зассан байгаа нь аюулгүй байдлын үнэлгээ болон бодит засварын хооронд ихээхэн зөрүү байгааг харуулж байна.
Хөтөлбөрт оролцогчид эхний нэгээс хоёр сарын хугацаанд өгөгдлөө Anthropic-ийн аюулгүй байдлын шаардлагын дагуу хадгалуулах шаардлагатай болно. Удахгүй хэрэгжих “Enterprise Frontier Safeguards” хөтөлбөрийн хүрээнд өгөгдөл хадгалахгүй байх нөхцөлийг нэвтрүүлэхээр төлөвлөж байгаа бөгөөд одоогоор Claude Fable 5.1 болон Mythos 5.1 ашигладаг байгууллагууд энэхүү нөхцөлийг хэдийнэ эдлэх боломжтой байна.
Дэлгэрэнгүйг эх сурвалжаас харах
↓Эх сурвалжийг нээх ↓
Only a week after warning about the perils of competitor Z.ai’s GLM-5.3 model and its advanced cybersecurity capabilities, Anthropic has expanded its Cyber Verification Program (CVP) – or rather, reconfigured it. “For the past six months, we’ve enabled trusted access through two programs: Project Glasswing and the CVP,” the AI biz said. “Now, we’re integrating these programs into one expanded offering, designed to give more security organizations access to the capabilities they need to protect their systems.” Project Glasswing and CVP launched in April 2026 alongside the debut of Mythos, the company’s highly capable and equally hyped frontier model. Project Glasswing gave partners early access to Mythos so they could scour their systems for vulnerabilities before attackers beat them to it. VulnCheck researcher Patrick Garrity was not particularly impressed with CVEs identified by Project Glasswing, noting that fewer than 0.5 percent of the 225 Anthropic-linked vulnerabilities he tracked were being exploited in the wild. And Anthropic’s own warning last month about the risks posed by GLM-5.3 somewhat undermines the idea that there’s anything special about its own Mythos model. Even so, Anthropic says that its security program has allowed its partners to spot at least 129,000 verified software vulnerabilities between April and July 2026. And the biz claims that its own open source scanning efforts revealed an additional 5,500 verified vulnerabilities between April and October. “Of these verified vulnerabilities, more than 33,000 have so far been rated as critical- or high-severity,” Anthropic said. “This is likely an undercount, as it is based on survey data from only a subset of Glasswing partners. As such, we expect the true impact to be at least five times higher.” When these might get patched is unclear. The company’s own figures indicate that of 5,674 true positive vulnerabilities, 3,014 are high severity, and 1,522 are critical severity, yet only 516 have been patched. Given industry boasting about the cybersecurity prowess of AI models, generating a fix, testing it, and deploying it ought to be nearly automatic at this point. But the gap between identification and remediation suggests there’s a lot of slack in the system that needs to be ironed out. Two programs into one with three tiers Now Anthropic’s two programs, one intended for organizations and one for individual security professionals, have been merged and reconfigured into three tiers. The AI biz has not explained why, but its stated intent is to tie model capabilities to specific tasks: Defense Access, Red Team Access, and Specialized Access. Depending on the tier, participants will encounter more or fewer blocks on security-related tasks. As a measure of program participation value, Anthropic said that based on five attempts at 10 CyScenarioBench challenges, those without CVP access got blocked on every attempt. Defense Access is intended for security teams at companies, nonprofits, universities, and government organizations that focus on system defense. In this tier, Claude Opus 5.5 faced refusals in 46 of 50 attempts and succeeded four times. Red Team Access is for penetration testing and offensive cyber evaluation, and participants will still face model refusals for model interactions that would cause physical harm or mass disruption. Specifically, Claude Opus 5.5 completed 34 of the 50 tasks with Red Team Access safeguards enabled, a rate similar to what would be expected from Specialized Access. Specialized Access sounds like a rebranding of Glasswing – it’s “reserved for a limited set of verified organizations that are authorized to test safety systems that could impact people’s lives or disrupt markets, such as flight operating systems, power grids, telecom networks, interbank transfer infrastructure, and government administrative networks.” Those granted admission to this exclusive tier will face the fewest model refusals, not counting anyone using abliterated open-weight models that have had their guardrails suppressed. For the next month or two, program participants will need to allow their data to be retained by Anthropic as part of its AI safety requirements. But soonish, the company’s Enterprise Frontier Safeguards program will offer zero data retention. Organizations already granted zero data retention while using Claude Fable 5.1 or Claude Mythos 5.1 can participate in CVP under those same terms.®

