Executive Summary
Anthropic expanded its Cyber Verification Program in October 2026, providing vetted cybersecurity professionals with reduced-safeguard access to advanced AI models including Claude Opus 5.5 and Claude Sonnet 5.5. The company's Project Glasswing initiative discovered 129,000 verified software vulnerabilities between April and July 2026, with over 33,000 rated as critical or high-severity. The program offers three access tiers - Defense Access, Red Team Access, and Specialized Access - each with varying levels of safeguards removal for legitimate security testing and research purposes.
This development highlights the growing intersection of AI capabilities and cybersecurity operations, as organizations increasingly leverage artificial intelligence for both defensive vulnerability discovery and offensive security testing. The dual-use nature of these AI tools underscores the need for careful access controls while democratizing advanced cybersecurity capabilities.
Why This Matters Now
AI-powered vulnerability discovery is accelerating at unprecedented scale, with Anthropic's tools finding 129,000 flaws in just four months. As threat actors gain similar AI capabilities, defenders need immediate access to these same tools to maintain security parity and proactively identify vulnerabilities before exploitation.
Attack Path Analysis
Threat actors leverage AI-generated vulnerability discovery to identify and exploit critical flaws in cloud applications and services. Attackers use automated tools to discover exposed APIs and web applications, then exploit CVEs like SQL injection and session forgery vulnerabilities to gain initial access. They escalate privileges through application-level flaws, move laterally through unprotected east-west traffic, establish command and control channels, and exfiltrate sensitive data through unmonitored egress channels. The attack culminates in data theft or system compromise leveraging the same AI capabilities used by defenders.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploit AI-discovered vulnerabilities such as CVE-2026-26980 (Ghost CMS SQL injection) and CVE-2026-61500 (Rejetto HFS session forgery) to gain initial access to cloud-hosted applications and services
Related CVEs
CVE-2026-26980
CVSS 7.5SQL injection vulnerability in Ghost CMS allows authenticated attackers to execute arbitrary SQL commands and potentially gain unauthorized database access.
Affected Products:
Ghost Foundation Ghost CMS – < 5.82.12
Exploit Status:
exploited in the wildCVE-2026-61500
CVSS 9.8Session forgery vulnerability in Rejetto HTTP File Server allows attackers to bypass authentication and gain unauthorized access to file operations.
Affected Products:
Rejetto HTTP File Server (HFS) – < 2.4.0
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation for Privilege Escalation
Command and Scripting Interpreter
File and Directory Discovery
Exploitation for Client Execution
Valid Accounts
Exploitation of Remote Services
Server Software Component
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Security Framework
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Vulnerability Management
Control ID: 500.08
DORA – Identification
Control ID: Article 8
CISA ZTMM 2.0 – Application Layer Protection
Control ID: Application Security
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
ISO 27001 – Secure Development Policy
Control ID: A.14.2.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
AI vulnerability discovery tools expose software development lifecycles to enhanced threat detection capabilities, requiring immediate security protocol updates and AI-assisted code review processes.
Computer/Network Security
Anthropic's expanded Claude access fundamentally transforms cybersecurity operations through AI-powered vulnerability analysis while introducing dual-use risks requiring specialized governance frameworks and controls.
Information Technology/IT
Mass AI-discovered vulnerabilities across enterprise systems demand accelerated patch management cycles and enhanced monitoring for CVE-2026-26980 and CVE-2026-61500 exploitation attempts.
Financial Services
Critical vulnerability exposure through AI tools threatens PCI DSS compliance requirements while creating regulatory obligations for enhanced AI governance and data protection measures.
Sources
- Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flawshttps://thehackernews.com/2026/10/anthropic-expands-claude-access-for.htmlVerified
- Anthropic Cyber Verification Program Announcementhttps://www.anthropic.com/news/cyber-verification-programVerified
- Claude Mythos AI Finds 10,000 High-Risk Vulnerabilitieshttps://thehackernews.com/2026/05/claude-mythos-ai-finds-10000-high.htmlVerified
- Anthropic Credited CVEs Analysis by Patrick Garrityhttps://github.com/patrickmgarrity/Anthropic-Credited-CVEsVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the attack blast radius by constraining lateral movement between workloads and controlling egress paths used for AI model exfiltration. The segmented architecture could limit attacker reach across cloud environments even after initial application compromise.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The application-level compromise would likely still succeed, but the attacker's ability to pivot beyond the initially compromised workload could be significantly constrained through identity-scoped access controls and workload isolation boundaries.
Control: Zero Trust Segmentation
Mitigation: Privilege escalation attempts would likely encounter segmentation boundaries that constrain access to higher-privileged services and infrastructure components, limiting the scope of accessible resources beyond the initial workload context.
Control: East-West Traffic Security
Mitigation: Lateral movement attempts would likely be constrained by east-west traffic policies that block unauthorized inter-workload communication, significantly reducing the attacker's ability to traverse between cloud services and regions.
Control: Multicloud Visibility & Control
Mitigation: Command and control communications would likely face detection and potential blocking through centralized visibility across multicloud environments, constraining the attacker's ability to maintain persistent and covert communication channels.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely be constrained through controlled egress policies that limit outbound connectivity to authorized destinations, reducing the attacker's ability to transfer AI models and sensitive data to external infrastructure.
While some AI model exposure might occur within the initially compromised workload scope, the overall impact would likely be limited to the segmented environment rather than affecting enterprise-wide AI systems and vulnerability discovery processes.
Impact at a Glance
Affected Business Functions
- AI Model Development and Testing
- Cybersecurity Research and Defense
- Vulnerability Assessment Services
- Software Security Validation
Estimated downtime: N/A
Estimated loss: N/A
No direct data exposure reported. The incident represents a positive development where AI-assisted vulnerability discovery tools identified 129,000+ software vulnerabilities across various systems, with only 2 confirmed as exploited in the wild, demonstrating the proactive nature of AI-assisted security research.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Cloud Native Security Fabric (CNSF) with inline enforcement to detect and block AI-driven exploit attempts at initial compromise
- • Deploy Zero Trust Segmentation with identity-based policies and microsegmentation to prevent lateral movement between workloads and services
- • Establish robust Egress Security & Policy Enforcement with FQDN filtering and data loss prevention to control outbound AI traffic and prevent exfiltration
- • Enable Multicloud Visibility & Control with centralized policy management to detect anomalous AI interactions and suspicious automation patterns
- • Deploy East-West Traffic Security controls to monitor and restrict service-to-service communications and prevent unauthorized lateral movement



