Back to Intelligence

Anthropic Expands Vetted Claude Access as Project Glasswing Finds 129,000 Verified Vulnerabilities — What Defenders Must Do Now

SA
Security Arsenal Team
October 7, 2026
6 min read

Anthropic announced this week that it is expanding access to its frontier Claude models — with reduced safeguards and relaxed blocking classifiers — for vetted cybersecurity professionals. The justification is hard to argue with: the company's Project Glasswing initiative reportedly uncovered at least 129,000 verified software vulnerabilities between April and July 2026, with an additional tranche of findings beyond that figure still being processed.

Let that number sink in. In four months, one initiative using one vendor's models produced a verified vulnerability count that rivals what the entire global CVE ecosystem — every researcher, vendor PSIRT, bug bounty hunter, and automated scanner combined — typically publishes in well over a year. The NVD averages roughly 40,000 CVEs annually in recent years. Glasswing tripled that pace from a single program.

This is not a product announcement to skim past. It is a structural change in the vulnerability landscape, and it has direct consequences for every SOC, vulnerability management team, and product security organization reading this.

What Actually Happened

Two distinct announcements are bundled in this news item, and defenders should separate them:

1. Expanded vetted access to reduced-safeguard models. Anthropic is broadening a program that gives screened cybersecurity professionals access to Claude variants with fewer refusals and blocking classifiers on security-sensitive tasks. In plain terms: the guardrails that normally prevent a model from assisting with exploit development, vulnerability research, and offensive tradecraft are deliberately loosened for verified defenders. This is the same dual-use tension the entire frontier AI industry is wrestling with — the capabilities that make a model useful for red teaming and bug hunting are identical to the capabilities that make it useful to an attacker.

2. Project Glasswing results. Anthropic claims its own initiative used these capabilities to find and verify 129,000+ software vulnerabilities in a four-month window. "Verified" is the operative word — these are not scanner noise or hypothetical findings, but flaws the company asserts were confirmed. Details on disclosure coordination, affected vendors, and severity distribution were not fully enumerated in the announcement, which matters enormously for defenders (more on that below).

Why This Matters to Defenders — The Strategic Picture

I've led IR engagements where the root cause was a vulnerability the client knew about but hadn't triaged yet. The patch gap — the window between disclosure and remediation — is where most breaches live. AI-driven discovery compresses and reshapes that window in three ways:

The discovery asymmetry is collapsing. Historically, finding novel memory corruption bugs, logic flaws, and complex injection chains required scarce human expertise. Frontier models are democratizing that capability. Every capability granted to vetted defenders under controlled access is a capability that will eventually be available — through jailbreaks, leaked weights, open-source equivalents, or less scrupulous providers — to threat actors. If Anthropic's models can find 129,000 flaws in four months, assume adversaries with equivalent tooling are finding their own.

Your attack surface was never fully enumerated. The uncomfortable truth Glasswing exposes: the backlog of latent, undiscovered vulnerabilities in shipping software is vastly larger than the published CVE stream suggested. Defenders have been prioritizing from a queue that represented only the flaws humans had time to find. That queue is about to grow by an order of magnitude.

Disclosure pipelines will be stressed. 129,000 verified findings have to go somewhere — to vendors, CERTs, CNAs, and ultimately into your scanner feeds. Triage teams, PSIRTs, and patch management programs built for ~40K CVEs/year will buckle under AI-scale disclosure volume without process changes.

Technical Considerations for Security Programs

This is not a traditional technical threat with IoCs, but there are concrete operational implications worth understanding:

  • Expect a surge of AI-generated vulnerability reports against your own products if you're a software vendor, and against your third-party stack if you're a consumer. Many will be high-quality; some will be AI-hallucinated noise. Both consume triage hours.
  • Severity inflation risk: AI tools are currently better at finding bugs than assessing exploitability in context. Expect findings that are technically valid but practically low-risk in your deployment — your prioritization logic (CVSS + EPSS + asset criticality + compensating controls) matters more than ever.
  • The exploit-development follow-through: reduced-safeguard models don't just find flaws — they assist in weaponizing them. The time from "vulnerability discovered" to "working exploit" will compress. Assume the patch gap for internet-facing systems just got shorter.
  • Duplicate and colliding reports: with many parties running AI-driven discovery, expect heavy collision on the same findings. Deduplication will be a real operational burden for anyone running a VDP or bug bounty program.

Executive Takeaways

1. Recalibrate your vulnerability management program for volume. If your triage, prioritization, and patching SLAs were sized for historical CVE throughput, they are undersized for what's coming. Automate ingestion, deduplication, and initial severity scoring. Invest in reachability analysis and attack-path context so humans only touch what actually matters in your environment.

2. Shorten patch windows for internet-facing assets — explicitly. Revisit your SLA tiers. If critical findings on edge systems currently allow 14 or 30 days, pressure-test that against a world where AI-assisted exploit generation cuts time-to-weaponization from weeks to days. Compensating controls (WAF virtual patching, segmentation, egress filtering) should be documented before you need them as stopgaps.

3. Prepare your intake pipeline for AI-generated reports. If you run a VDP or bug bounty program, publish clear policy on AI-assisted submissions now. Build triage capacity for higher report volume and higher duplicate rates. Require reproduction artifacts (PoC, affected version, crash logs) to filter hallucinated findings efficiently.

4. Threat-model AI-assisted adversaries in your next tabletop. Update your risk register and IR playbooks to account for adversaries with machine-scale vulnerability discovery and rapid exploit development. The scenarios that used to be "nation-state only" — novel zero-days against your specific stack — need to be treated as a broader threat class.

5. Evaluate governed defensive AI use yourself. The vetted-access model Anthropic is expanding is the shape of things to come: frontier capability under identity verification, contractual controls, and monitoring. If your red team or product security org isn't assessing these tools under controlled conditions, you are ceding the capability advantage to whoever is.

6. Harden what you can't patch. AI-scale discovery means unknown flaws in everything you run — including appliances, firmware, and legacy systems with no patch path. Defense-in-depth stops being a platitude here: strict egress controls, application allowlisting, network segmentation, and robust EDR coverage are what buy you survivability when the unknown-unknowns surface.

The Bottom Line

Project Glasswing's 129,000 verified vulnerabilities are a proof point, not an anomaly. Machine-scale vulnerability discovery is here, it is being productized for defenders under vetted programs, and the same capability trajectory applies to adversaries. The organizations that adapt their vulnerability management economics — automation-heavy triage, aggressive prioritization, compressed patch SLAs, and real compensating controls — will absorb this wave. The ones still running 2019-era patch cadences will drown in it.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.