Ground Truth.
AI, checked against the source.

News · 2026-10-07

Anthropic expands cyber access through three tiers, including Mythos 5.1

Anthropic expanded its Cyber Verification Program on October 6 into three access tiers and explicitly included Claude Mythos 5.1 among the available models. Qualifying defenders can obtain cyber capabilities with fewer blocking filters, while higher-risk testing requires stronger organizational controls. The change is a controlled-access policy, not a public model-weight release or proof that powerful cyber tools cannot be diverted.

Key facts

A security professional investigating malware and an attacker preparing intrusion steps can ask superficially similar questions. Public models often handle that ambiguity conservatively. Anthropic describes its program as granting advanced capabilities with “reduced blocking classifiers” to people and organizations whose work and controls it can verify. The policy attempts to move some judgment from the wording of a prompt to the identity and environment of the user.

Defense Access covers security operations, incident response, malware reverse engineering, and vulnerability analysis and validation. Individuals with a vulnerability-reporting track record may apply, provided they have a paid plan. Red Team Access adds authorized adversarial testing and is organization-only. Some real-time blocks remain, including restrictions around ransomware deployment, physical damage, and high-risk safety systems.

Specialized Access has the broadest scope and is limited to a small set of organizations testing systems whose failures could affect lives or disrupt markets. Anthropic names examples such as flight systems, electricity grids, telecommunications, and interbank transfers. It says those organizations undergo deeper review with the United States government. Existing Glasswing members transition into this tier for current models without reapproval.

The program Help Center describes application and eligibility rather than a guaranteed approval process. Work scope, verifiable identity, legal setting, diversion risk, and ultimate customers matter. The announcement’s review estimates differ from the Help Center’s target. Mythos access through cloud providers may also trail approval by about five business days. A Reddit report of a model appearing in one account therefore cannot establish access for every member.

The safety mechanism resembles controlled access to a powerful laboratory instrument. Permission to use the instrument comes with a named operator, recorded activity, a defined experimental scope, and duties when something goes wrong. The tool becomes less restrictive within that scope, while the surrounding institution becomes more accountable. This is distinct from claiming the model itself can always distinguish legitimate testing from abuse.

Anthropic’s security requirements require named security contacts, individual logins, attributable requests, reporting, investigation, and cooperation with remediation. Higher tiers add phishing-resistant authentication, short-lived credentials, and restricted, logged outgoing network access for offensive or agentic work. Specialized Access is ordinarily limited to 25 approved users. Defense users face a December 15 deadline for stronger authentication and removal of long-lived static credentials.

The company’s own CyScenarioBench experiment makes the effect of permissions concrete. It ran ten challenges with five attempts each. All 50 public-setting attempts stopped at the first prompt. Defense settings produced four successes, with 46 attempts blocked somewhere. Red Team settings produced 34 successes and no classifier blocks. This shows that different settings allow the same model to progress differently through simulated operations. It does not estimate success rates for real intrusions or demonstrate that access controls prevent misuse after approval.

The vulnerability totals are larger but less auditable. Anthropic reports 129,000 partner-found vulnerabilities from April through July and another 5,500 from its own open-source scanning through October. More than 33,000 were reportedly rated critical or high. The partner count relies on partial reports from 33 partners using different triage practices; fewer than half reported patch counts. Readers should not translate it into a count of publicly confirmed, unique, repaired vulnerabilities.

Named practitioner accounts are more concrete. In Anthropic’s Comcast and Booz Allen case study, Comcast CISO Noopur Davis distinguishes a finding from a validated, exploitable issue. Comcast describes checking an authentication flaw against a running application and fixing it. Booz Allen describes cross-program analysis and faster review. These are useful first-person accounts, but they appear in vendor-published material rather than an independent audit.

The opened Reddit access report is a community anecdote. The dossier found no independent published assessment of the new tiers’ effectiveness. The strongest counterargument is empirical: verified identities and monitoring can improve accountability without proving resistance to compromised accounts, insider abuse, or diversion.

For security teams, the actionable change is an application route and a set of operational obligations. The existing scoped-credentials lesson explains why named access and credential lifetime matter. The remaining question is whether capability delivery and defensive validation scale together: discovering issues faster helps only when teams can triage and repair them.


Primary source, verified: read the paper →

Key questions

Can an individual researcher apply for Mythos-related cyber access?

An individual with qualifying security work can apply for Defense Access on a paid plan. Red Team and Specialized Access are reserved for organizations.

What changes on December 15 for Defense Access?

Anthropic’s requirements call for phishing-resistant multi-factor authentication and an end to long-lived static credentials by December 15, 2026. Interim API keys have storage, assignment, and rotation conditions.

Are Anthropic’s 129,000 reported vulnerabilities all public, patched defects?

No: the announcement does not provide a publicly auditable record of unique, patched, exploitable defects. It aggregates partial partner reports using different triage methods.
Cite this

APA

Ground Truth. (2026, October 7). Anthropic expands cyber access through three tiers, including Mythos 5.1. Ground Truth. https://groundtruth.day/news/anthropic-cyber-verification-three-tiers-mythos-5-1.html

BibTeX

@misc{groundtruth:anthropic-cyber-verification-three-tiers-mythos-5-1,
  title  = {Anthropic expands cyber access through three tiers, including Mythos 5.1},
  author = {{Ground Truth}},
  year   = {2026},
  month  = {oct},
  url    = {https://groundtruth.day/news/anthropic-cyber-verification-three-tiers-mythos-5-1.html}
}

Topics: cybersecurity · ai-security · red-teaming · vulnerabilities · anthropic

Comments are replies to this story on Bluesky — reply with any Bluesky account to join in.