AI news · October 8, 2026

Anthropic expands cyber access with Project Glasswing partners

cybersecuritysafetyenterpriseagents

Project Glasswing adds three access tiers for advanced cyber work and a partner group spanning cloud, security, hardware, and open-source organizations. Access is for qualifying security professionals.

Cyber Verification access tiers
3
named Project Glasswing partners
11
Made With Models illustration for this story

Anthropic announced Project Glasswing and an expanded Cyber Verification Program on October 6. The program has three access tiers for qualifying security professionals, with advanced cyber capabilities and reduced blocking classifiers available under the relevant review process. Anthropic lists partners from cloud, hardware, security, finance, and open-source groups, including AWS, Apple, Cisco, CrowdStrike, Google, Microsoft, NVIDIA, Palo Alto Networks, and the Linux Foundation. Anthropic also says an unreleased Mythos preview found thousands of high-severity vulnerabilities, which is a company claim.

The important change is controlled access for a high-risk use case. A security team can get more useful model behavior when its identity, purpose, and testing environment are known, but the same capability needs strong audit logs and limits. Builders should separate lab work from production systems, keep secrets out of model context, and report false positives as well as findings. The program is not a general release and should not be treated as one.

What you can do with it

Read the program requirements and use a separate test environment for any cyber evaluation. Define allowed targets, log every tool call, and require human review before a finding changes a production system. Measure useful findings and false alarms instead of counting model outputs.

Our take

Controlled cyber access is a better product shape than broad release when model capability can find real vulnerabilities. Anthropic's partner list and tiered review are meaningful signals, but the strongest performance statement is self-reported. Security teams should judge the program on repeatable findings and safe handling.

Source: Anthropic ↗ — Made With Models writes the brief; the reporting is theirs.