Security News

Anthropic Merges Its Two Security Access Programs, but Fixing Flaws Is Lagging Behind Finding Them

The Register · 7 Oct 2026
Key Takeaway Finding vulnerabilities means little without fixing them, so make sure your business applies software updates promptly, starting with the most serious ones.

Anthropic has merged two programs that gave trusted security organisations access to its AI capabilities: Project Glasswing and the Cyber Verification Program (CVP). Both launched in April 2026 alongside its Mythos model. Glasswing gave partners early access so they could find weaknesses in their own systems before attackers did. Anthropic says the combined offering is designed to give more security organisations the tools they need to protect their systems. The change comes only a week after the company warned about the risks of a competitor's model, Z.ai's GLM-5.3.

Anthropic reports that partners identified at least 129,000 verified software vulnerabilities between April and July 2026, and that its own open source scanning found a further 5,500 between April and October. It says more than 33,000 have been rated critical or high severity, and expects the true figure to be at least five times higher, since it is based on survey data from only some partners. VulnCheck researcher Patrick Garrity was less impressed, noting that fewer than 0.5 percent of the 225 Anthropic-linked vulnerabilities he tracked were being exploited in the wild.

The bigger concern is remediation. Of 5,674 true positive vulnerabilities, Anthropic's figures show 3,014 are high severity and 1,522 are critical, yet only 516 have been patched. Finding flaws is only half the job; the gap between identification and repair suggests the system still has a lot of slack to fix.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Register, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.