LIVE · cybersecurity feed
Live wire
ASOS Hackers Hijack App Notifications, Claim Snowflake Data BreachKarina Portugal Makes the Case for Know Your AgentAlert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacksCVE-2026-93836 · Ninja Forms plugin flaw exploited to hack WordPress sitesCVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE Publication
security

Anthropic reconfigures its cool kids security program

Anthropic has announced a restructuring of its cybersecurity initiatives, merging its Project Glasswing and Cyber Verification Program (CVP) into a single, tiered offering. This change, effective as of October 2026, aims to provide more security organizations with access to Anthropic's AI capabilities for system protection.

ZeroDay News ·

Source: The Register — Security

Anthropic has announced a restructuring of its cybersecurity initiatives, merging its Project Glasswing and Cyber Verification Program (CVP) into a single, tiered offering. This change, effective as of October 2026, aims to provide more security organizations with access to Anthropic's AI capabilities for system protection.

Project Glasswing and CVP were initially launched in April 2026 alongside the debut of Mythos, Anthropic's frontier AI model. Project Glasswing provided early access to Mythos for partners to identify vulnerabilities within their systems. Anthropic claims that between April and July 2026, its partners identified at least 129,000 verified software vulnerabilities through these programs. Additionally, Anthropic's own open-source scanning efforts reportedly uncovered another 5,500 verified vulnerabilities between April and October.

Of these identified vulnerabilities, Anthropic states that over 33,000 have been rated as critical- or high-severity. The company suggests this is likely an undercount, estimating the true impact to be at least five times higher based on survey data from a subset of Glasswing partners. Despite the identification of 5,674 true positive vulnerabilities, including 3,014 high-severity and 1,522 critical-severity issues, only 516 have been patched according to Anthropic's figures.

The reconfigured program now features three distinct tiers: Defense Access, Red Team Access, and Specialized Access. Anthropic indicates that the purpose of these tiers is to align model capabilities with specific security tasks, with varying levels of restrictions on security-related interactions.

Defense Access is designed for security teams within companies, nonprofits, universities, and government organizations focused on system defense. In this tier, Anthropic's Claude Opus 5.5 model reportedly faced refusals in 46 out of 50 attempts during CyScenarioBench challenges, succeeding only four times.

Red Team Access is tailored for penetration testing and offensive cyber evaluations. Participants in this tier will still encounter model refusals for interactions that could lead to physical harm or widespread disruption. Claude Opus 5.5 completed 34 out of 50 tasks with Red Team Access safeguards enabled, a performance level similar to what is expected from Specialized Access.

Specialized Access is reserved for a limited number of verified organizations authorized to test safety systems that could impact critical infrastructure or markets, such as flight operating systems, power grids, telecom networks, interbank transfer infrastructure, and government administrative networks. This tier offers the fewest model refusals, excluding open-weight models with suppressed guardrails.

For the immediate future, program participants will be required to allow Anthropic to retain their data as part of its AI safety requirements. However, Anthropic's forthcoming Enterprise Frontier Safeguards program is expected to offer zero data retention. Organizations already benefiting from zero data retention with Claude Fable 5.1 or Claude Mythos 5.1 can continue under those terms within the CVP.

ShareXLinkedInWhatsAppFacebook

More News

view all →
data breachhigh

ASOS Hackers Hijack App Notifications, Claim Snowflake Data Breach

ASOS is currently investigating a cybersecurity incident where unauthorized actors leveraged the company's official mobile application to disseminate threatening notifications to its customer base. The messages, sent directly through the app's notification system, asserted that the attackers had successfully breached Snowflake and subsequently gained access to ASOS customer data.

ai securityhigh

Karina Portugal Makes the Case for Know Your Agent

Karina Portugal, a Director at Prove Identity, has reportedly advocated for a new security paradigm termed "Know Your Agent" (KYA). This concept addresses the emerging challenges in verifying autonomous software agents, which traditional "Know Your Customer" (KYC) methodologies are not equipped to handle. The core argument is that existing KYC frameworks primarily focus on human user identity,…

fortinethigh

Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks

The FBI and Secret Service have issued a joint alert regarding "FortiBleed," a credential compromise campaign targeting Fortinet firewalls and VPN gateways. The agencies confirm that the campaign remains active and poses a significant threat, potentially leading to user lockouts and serving as an initial entry point for ransomware attacks.

CVE-2026-93836high

Ninja Forms plugin flaw exploited to hack WordPress sites

Cybersecurity researchers have identified an active exploitation campaign targeting two WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, leveraging stored cross-site scripting (XSS) vulnerabilities to compromise websites. The attacks, first observed on October 4 against WPC Product Bundles for WooCommerce users and then on October 5 against Ninja Forms users, involve the…

clickfix

ClickFix Attacks Evolve to Better Hide Malicious Payloads

Recent reports indicate a significant evolution in ClickFix attack methodologies, with cybercriminals now employing more sophisticated techniques to mask their malicious payloads. The updated tactics reportedly involve the use of DNS TXT records and browser cache pre-fetching, strategies designed to make the early detection of these threats considerably more difficult for security systems and…

patch

Wiretapping change sparks big privacy fight in the Golden State

California Governor Gavin Newsom has signed a bipartisan update to the state's wiretapping law, the California Invasion of Privacy Act (CIPA), which will eliminate the ability for private citizens to sue over certain internet-based surveillance. The amendment, known as SB 690, specifically targets the private right to sue websites and mobile applications for unauthorized use of "pen registers"…