News · 2026-10-07
Anthropic expands cyber access through three tiers, including Mythos 5.1
Anthropic expanded its Cyber Verification Program on October 6 into three access tiers and explicitly included Claude Mythos 5.1 among the available models. Qualifying defenders can obtain cyber capabilities with fewer blocking filters, while higher-risk testing requires stronger organizational controls. The change is a controlled-access policy, not a public model-weight release or proof that powerful cyber tools cannot be diverted.
Key facts
- The three tiers are Defense, Red Team, and Specialized Access.
- Anthropic’s test found 34 successful attempts out of 50 for Opus 5.5 under Red Team settings, versus none proceeding past the first prompt without program access.
- Anthropic reports at least 129,000 partner-found vulnerabilities, but does not publish a common verification or deduplication protocol.
- Primary source: Anthropic’s program expansion.
A security professional investigating malware and an attacker preparing intrusion steps can ask superficially similar questions. Public models often handle that ambiguity conservatively. Anthropic describes its program as granting advanced capabilities with “reduced blocking classifiers” to people and organizations whose work and controls it can verify. The policy attempts to move some judgment from the wording of a prompt to the identity and environment of the user.
Defense Access covers security operations, incident response, malware reverse engineering, and vulnerability analysis and validation. Individuals with a vulnerability-reporting track record may apply, provided they have a paid plan. Red Team Access adds authorized adversarial testing and is organization-only. Some real-time blocks remain, including restrictions around ransomware deployment, physical damage, and high-risk safety systems.
Specialized Access has the broadest scope and is limited to a small set of organizations testing systems whose failures could affect lives or disrupt markets. Anthropic names examples such as flight systems, electricity grids, telecommunications, and interbank transfers. It says those organizations undergo deeper review with the United States government. Existing Glasswing members transition into this tier for current models without reapproval.
The program Help Center describes application and eligibility rather than a guaranteed approval process. Work scope, verifiable identity, legal setting, diversion risk, and ultimate customers matter. The announcement’s review estimates differ from the Help Center’s target. Mythos access through cloud providers may also trail approval by about five business days. A Reddit report of a model appearing in one account therefore cannot establish access for every member.
The safety mechanism resembles controlled access to a powerful laboratory instrument. Permission to use the instrument comes with a named operator, recorded activity, a defined experimental scope, and duties when something goes wrong. The tool becomes less restrictive within that scope, while the surrounding institution becomes more accountable. This is distinct from claiming the model itself can always distinguish legitimate testing from abuse.
Anthropic’s security requirements require named security contacts, individual logins, attributable requests, reporting, investigation, and cooperation with remediation. Higher tiers add phishing-resistant authentication, short-lived credentials, and restricted, logged outgoing network access for offensive or agentic work. Specialized Access is ordinarily limited to 25 approved users. Defense users face a December 15 deadline for stronger authentication and removal of long-lived static credentials.
The company’s own CyScenarioBench experiment makes the effect of permissions concrete. It ran ten challenges with five attempts each. All 50 public-setting attempts stopped at the first prompt. Defense settings produced four successes, with 46 attempts blocked somewhere. Red Team settings produced 34 successes and no classifier blocks. This shows that different settings allow the same model to progress differently through simulated operations. It does not estimate success rates for real intrusions or demonstrate that access controls prevent misuse after approval.
The vulnerability totals are larger but less auditable. Anthropic reports 129,000 partner-found vulnerabilities from April through July and another 5,500 from its own open-source scanning through October. More than 33,000 were reportedly rated critical or high. The partner count relies on partial reports from 33 partners using different triage practices; fewer than half reported patch counts. Readers should not translate it into a count of publicly confirmed, unique, repaired vulnerabilities.
Named practitioner accounts are more concrete. In Anthropic’s Comcast and Booz Allen case study, Comcast CISO Noopur Davis distinguishes a finding from a validated, exploitable issue. Comcast describes checking an authentication flaw against a running application and fixing it. Booz Allen describes cross-program analysis and faster review. These are useful first-person accounts, but they appear in vendor-published material rather than an independent audit.
The opened Reddit access report is a community anecdote. The dossier found no independent published assessment of the new tiers’ effectiveness. The strongest counterargument is empirical: verified identities and monitoring can improve accountability without proving resistance to compromised accounts, insider abuse, or diversion.
For security teams, the actionable change is an application route and a set of operational obligations. The existing scoped-credentials lesson explains why named access and credential lifetime matter. The remaining question is whether capability delivery and defensive validation scale together: discovering issues faster helps only when teams can triage and repair them.
Key questions
Can an individual researcher apply for Mythos-related cyber access?
What changes on December 15 for Defense Access?
Are Anthropic’s 129,000 reported vulnerabilities all public, patched defects?
Cite this
APA
Ground Truth. (2026, October 7). Anthropic expands cyber access through three tiers, including Mythos 5.1. Ground Truth. https://groundtruth.day/news/anthropic-cyber-verification-three-tiers-mythos-5-1.html
BibTeX
@misc{groundtruth:anthropic-cyber-verification-three-tiers-mythos-5-1,
title = {Anthropic expands cyber access through three tiers, including Mythos 5.1},
author = {{Ground Truth}},
year = {2026},
month = {oct},
url = {https://groundtruth.day/news/anthropic-cyber-verification-three-tiers-mythos-5-1.html}
}
Comments are replies to this story on Bluesky — reply with any Bluesky account to join in.