Back to Explore
NewsVibeFix 编辑部Updated Oct 7, 2026

After 129,000 Vulnerabilities, Anthropic Opens Its Strongest Bug-Hunting Models to More Security Teams

Reuters reported on October 6 that Anthropic is folding Project Glasswing into an expanded Cyber Verification Program: vetted security teams get fewer restrictions on Claude Opus 5.5, Sonnet 5.5, and Mythos 5.1. Glasswing partners found 129,000 verified vulnerabilities in four months, 33,000 of them critical or high severity. For vibe coders, the real signal is this: AI vulnerability discovery has been industrialized, and the window for "ship first, worry later" is closing fast.

A security researcher staring at vulnerability scan reports on screen: Anthropic expands its Cyber Verification Program

What happened

Reuters reported on October 6 that Anthropic is expanding a program that lets vetted cybersecurity professionals test its most powerful AI models with fewer safeguards. The backdrop numbers are striking — partners in Anthropic's Project Glasswing found at least 129,000 verified software vulnerabilities in just the four months from April to July; Anthropic's own open-source scanning found 5,500 more between April and October. Over 33,000 were rated critical or high severity. Anthropic added that the figures are likely an undercount, with the true impact possibly five times higher, since the data comes from a survey of a limited set of partners.

The revamped Cyber Verification Program (CVP) merges two programs Anthropic ran over the past six months: Glasswing — which gave organizations securing critical software access to Claude Mythos (Anthropic's most cyber-capable model family) — and the original CVP, which gave vetted security teams reduced restrictions on Claude Opus and Sonnet models. The new program has three tiers, each with its own vetting requirements and safety controls, but all three include Claude Opus 5.5, Sonnet 5.5, Mythos 5.1, and future models:

  • Defense Access: covers incident response, malware analysis, and similar work. Security teams, critical infrastructure operators, open-source maintainers, and researchers with a vulnerability-reporting record can apply.
  • Red Team Access: adds authorized penetration testing and red-teaming, but only organizations can apply.
  • Specialized Access: the fewest restrictions, reserved for a small group of organizations authorized to test safety-critical systems such as power grids, flight systems, and interbank transfer infrastructure. Anthropic reviews members jointly with the US government, and existing Glasswing members move into this tier.

The hardest numbers in the announcement are actually from a controlled experiment. Anthropic tested each tier's blocking behavior on its own CyScenarioBench (50 cybersecurity scenario tasks): a model without CVP access was blocked on all 50 tasks; Defense Access blocked 46; Red Team Access blocked none, with Claude Opus 5.5 completing 34 — matching the 67.6% success rate with safeguards fully removed. Translation: once vetted, the model flips from "blocked everywhere" to "full firepower." That is the real meaning of the three tiers — same models, with the leash length determined by who you are.

The other side of the numbers is their limitation, which Anthropic states openly: the 129,000 comes from a sample of 33 partner reports, and fewer than half of the partners disclosed patch counts (many fixes were still in progress), so the "patch rate" is significantly undercounted. Booz Allen and Comcast contributed case studies of scanning their own codebases with Claude Mythos — one partner said that without Mythos, the same vulnerabilities would have taken "months or even years" longer to find. Vulnerability discovery now has a measurable "AI acceleration factor."

Two details are worth noting. First, Specialized tier reviews are conducted jointly by Anthropic and the US government — effectively a public-private credentialing system for critical-infrastructure offensive testing, where AI offensive capability now has an issuing authority. Second, organizations entering the Red Team tier accept mandatory data retention, with Anthropic keeping logs to monitor misuse (enterprise cloud storage of those logs will come later). Capability openness and behavior monitoring are two sides of the same coin: loosen the leash, and someone has to hold the other end.

Why vibe coders should care

Don't dismiss this as "big-company security news, nothing to do with me." Think about the project you vibed out last week: the AI installed 40 npm packages in one go, and you probably glanced at package.json once before hitting accept. The reality on the other end: AI vulnerability discovery has been industrialized — 129,000 vulnerabilities in four months is not some lone hacker's trophy, it's a production line's output.

Offense and defense are being accelerated by the same wave of AI. The model you use to write code and the model someone else uses to scan your code are the same generation of technology. That means the window for "ship first, worry later" is shrinking fast: a small project's vulnerability that might once have gone unnoticed for years may now not survive the next automated scan.

For indie developers, the good news is that defensive tooling is being democratized too. The CVP's Defense tier explicitly opens applications to open-source maintainers — if you maintain an open-source project with real users, that's a direct channel to top-tier models for security audits. And even without applying, the mindset transfers: before shipping, let AI red-team your own project. Tools like Codex Security Cloud that automatically scan repos and draft fixes already exist; wiring one into your release flow costs almost nothing.

But first, a bucket of cold water on the 129,000. VulnCheck researcher Patrick Garrity tracked 225 Anthropic-linked CVEs and found fewer than 0.5% were being exploited in the wild. Found does not equal fixed, and fixed does not equal exploited. The 129,000 is a "discovery capability" number, not a "the world is safer" number. The insight for vibe coders hides right there: AI has industrialized finding vulnerabilities, but fixing them, verifying the fixes, and confirming they're not exploited is still labor-intensive — and that's exactly the gap indie developers can fill with AI. Someone scans 1,000 vulnerabilities; your tool helps fix 100 of them. The latter is the business.

Then there's the asymmetry of offense and defense, which stings the most: defenders must apply, get vetted, and retain logs; attackers don't fill out forms. Just last week, Anthropic was publicly warning about the cybersecurity capabilities of competitor Z.ai's GLM-5.3 (we covered it on October 2) — the strongest bug-hunting capabilities were never held only by the "good guys." Every package your vibed project depends on, every endpoint it exposes, sits under this scan density. The "ship first" window isn't just shrinking; it's becoming metered by the hour.

Here's a "pre-ship security triple" indie developers can copy directly: first, stop skipping dependency scans — run npm audit / pip audit; it takes minutes and catches most known vulnerabilities; second, have an agent read through new code looking for three specific problem classes: injection (SQL, command, prompt injection), broken access control, and hardcoded secrets — the three most common defects in AI-generated code; third, if your project handles user data, seriously consider applying for the CVP Defense tier — open-source maintainer status is your ticket in. Also look at scanners built specifically for AI-generated apps, like VibeZero: wiring a scan into your release pipeline costs almost nothing and buys you "get scanned by your own side before shipping."

One more overlooked angle: of the 129,000 vulnerabilities, over 33,000 are critical or high severity — yet fewer than half of the partners disclosed patch counts. That means a huge, unfilled ravine sits between "discovery" and "remediation." Anthropic's own open-source scanning covers only part of the ecosystem; the dependency trees of countless small and mid-size open-source projects are never scanned at all. For indie developers, that's not bad news — it's opportunity: pick an open-source project you use daily, run an AI scan over it, and submit PRs fixing confirmed vulnerabilities. It's community contribution and the strongest line on your résumé at once. Security has never lacked people who can find problems; it lacks people willing to ship fixes upstream. AI has demolished the barrier to the former, which only makes the latter more valuable. Once finding bugs is industrialized, fixing them becomes the next scarce good.

One judgment: the only loser is "ship without checking"

This reads even better next to another early-October story: OpenAI's agent wandered into Australia's Medicare portal, and its CSO ended up apologizing at a parliamentary hearing. AI's "ability to act" is growing, its "ability to break things" is growing, and "ability to govern" is still catching up. Anthropic's move is a statement: rather than letting the strongest bug-hunting capability sit with a few, open it to defenders with controls — get the guns to the good guys first.

The operational takeaway for vibe coders is one sentence: write "AI security scan" into your release checklist, on the same line as "tests pass." Concretely: before every major release, run a dependency vulnerability scan (stop skipping basics like npm audit); have an agent read new code specifically hunting injection, access-control, and hardcoded-secret issues; if the project handles user data, seriously consider applying for the CVP Defense tier. The 129,000 tells you: vulnerabilities aren't a question of "whether they'll be found," but "when."

Connect Anthropic's warning last month with this opening and the logic holds together: warning about models like GLM-5.3 on one hand, opening its own strongest bug-hunting models to defenders on the other. Not a contradiction — two sides of one judgment: capability diffusion is inevitable, so get the guns to the good guys first, and make the licenses real. Vetting, data retention, joint government review — that's the price of the license. Anthropic is betting that controlled openness beats plugging holes in this arms race.

For vibe coders, the real dividing line has moved: it's no longer "do you use AI to write code" — everyone does now — but "do you use AI to review code." The AI that writes code and the AI that reviews it come from the same company, the same generation of technology, the same API shape, at roughly the same cost. Using only half is like buying double insurance at full price and unwrapping just one policy.

One last bit of time math: 129,000 verified vulnerabilities in four months means over 1,000 verified vulnerabilities surface from code every single day. The moment your project ships, it enters that scan density. Vulnerabilities aren't a question of "whether," but "when" — and "scan it yourself before shipping" is the only way to keep that time gap in your own hands.

One practical note: the Defense tier's bar is lower than you'd think — independent researchers with a vulnerability-reporting record can apply; you don't need to be from a big company. If you've ever reported a CVE or submitted a security fix to an open-source project, that's your ticket in. Don't let the word "vetting" scare you off — it screens for motive, not scale.

The AI that writes code and the AI that reviews code are issued by the same company. Don't use only half.

Sources

Browse projectsPublish your project

Related articles

Concept illustration of a robot holding a digital ID card with a shield verification badge, symbolizing AI agent identity
News
AI Agents Get Their Own 'Sign in with Google': AgentMail Launches AgentID

AgentMail launched AgentID on October 6: agents log in to third-party apps using their own email as an OpenID Connect identity. The verification-code step disappears, one authorization lasts 180 days. Identity may be the real watershed between agent toys and agent production.

AI CodingProduct LaunchAuthentication & Access
Multiple AI coding agent sessions running side by side on a dark terminal interface
News
Codex Issues a "28-Day Pledge": One Improvement a Day, or a Usage Reset for Everyone

On October 4, OpenAI's Codex engineering lead Tibo made a public pledge: for 28 days, ship one clear improvement every day for most Codex and ChatGPT Work users — on days the team fails, everyone gets a usage reset. Day 1 brought ~50% faster GPT-6 Astra / 6.1 Sol by default, Day 2 made Auto-review free for ChatGPT sign-ins, Day 3 put GPT-6 in the chat tab. This is an experiment in turning product iteration into a daily series.

AI CodingIndustry TrendsProduct Launch