Anthropic has announced an expansion of a program that gives vetted cybersecurity professionals access to its most capable AI models with relaxed safeguards, while simultaneously reporting that its Project Glasswing initiative identified at least 129,000 verified software vulnerabilities between April and July 2026.

A Wider Door for Defenders

The program, first introduced in a more limited form, allows approved security researchers and incident responders to work with Claude under reduced blocking classifiers. In practice, that means fewer of the guardrails that normally prevent the model from discussing offensive techniques, exploit development, or other dual-use material. Anthropic frames the change as a pragmatic response to a simple problem: defenders need the same depth of technical assistance that attackers can already obtain elsewhere.

Access is not automatic. Organizations and individuals must pass a vetting process before gaining entry, and Anthropic has not disclosed the full criteria used to evaluate applicants. The company has positioned the expansion as a controlled release rather than an open door, emphasizing that reduced safeguards apply only within an approved context.

Project Glasswing by the Numbers

The headline figure from the announcement is the scale of Project Glasswing's output. According to Anthropic, the initiative surfaced at least 129,000 verified software vulnerabilities during a four-month window from April through July 2026. The company said it also found an additional set of issues beyond that total, though the announcement did not provide a precise breakdown of how those extra findings were classified or disclosed.

That volume is striking, but it should be read carefully. "Verified" is doing a lot of work in that sentence. A vulnerability can be real and still be low severity, a duplicate of a known issue, or impractical to exploit in a production environment. Bulk AI-assisted code review tends to produce exactly this kind of long tail: a small number of serious findings surrounded by a much larger body of hardening opportunities and informational alerts. Without per-severity data, the 129,000 figure describes the breadth of scanning activity more than it describes the state of software security overall.

Why Reduced Safeguards Matter

AI models are typically tuned to refuse requests that look like they could enable harm. For a penetration tester or a SOC analyst, those refusals can be a genuine obstacle. Explaining a memory corruption bug, drafting a proof-of-concept, or reasoning about a chained attack path all sit close to the line that general-purpose classifiers are designed to draw.

Relaxing those classifiers for vetted users is a bet that context and accountability reduce risk. It is also a bet that Anthropic's competitors are making in various forms, and it reflects a broader shift in the industry: the same model capability that can be misused is often the capability that makes defensive work tractable at scale.

The counterargument is equally familiar. Any program that grants expanded access depends on the quality of its vetting, and vetting is hard. A single approved account that is later compromised, resold, or misused undermines the entire premise. Anthropic has not published details on monitoring, revocation procedures, or how it would detect abuse after access is granted.

The Disclosure Question

Discovering 129,000 vulnerabilities raises an obvious follow-up: what happened to them? Responsible disclosure at that scale is a logistical problem, not just a technical one. Maintainers of small open-source projects cannot absorb thousands of reports, and triage capacity across the ecosystem is already strained.

Anthropic's summary does not spell out how findings were routed to affected vendors or whether timelines were coordinated with maintainers. For the security community, that process matters as much as the discovery itself. A vulnerability that is found, documented, and then left unaddressed is not much safer than one that was never found.

What to Watch

The expansion of Claude access and the Glasswing results point in the same direction: AI is becoming part of the standard toolkit on both sides of the fight. The questions that remain are operational. How strict is the vetting? What happens when an approved user goes off-script? And how will the flood of AI-generated findings be triaged without drowning the maintainers who have to fix them?

Anthropic has answered the capability question. The governance questions are still open.

Source: The Hacker News