Editor's note: This article is based on a summary of The Hacker News report cited below. The original page was not fully rendered at the time of writing, and Anthropic's announcement has not been independently reviewed. All claims — including the vulnerability count, the programme details and the "further findings" reference — should be read as unverified company statements relayed by the source, pending a full cross-check.

Anthropic said on Tuesday that it is expanding a programme granting vetted cybersecurity professionals access to its advanced Claude models with reduced safeguards and relaxed blocking classifiers — a deliberate loosening of the company's guardrails for a narrow group of offensive security researchers.

Supporting the announcement, the company pointed to Project Glasswing, its own bug-hunting operation, which Anthropic said uncovered at least 129,000 "verified" software vulnerabilities between April and July 2026. The figure is Anthropic's own, and the term "verified" is the company's — the material reviewed does not explain how the vulnerabilities were identified or counted, whether flaws were reproduced independently, confirmed by affected vendors, or triaged and closed. No third-party audit of the figure has been published.

What is unambiguous is the direction of travel. Anthropic is positioning its models as legitimate security tooling and easing the safeguards that, in its reasoning, hold back professional red teams and penetration testers. Those same restrictions exist to stop misuse by general users; the argument here is that they are a drag on vetted research. Access remains gated, but Anthropic has not published the full eligibility criteria alongside the announcement. The company also referred to further findings recorded during the same window, without elaborating on what those findings covered in the material reviewed.

For the open-source community, the discovery number is less consequential than the bottleneck it exposes. If the figure holds, AI systems are now surfacing flaws at a rate far beyond what any conventional bug bounty or audit programme handles in a comparable period — and automated discovery does not automatically produce patched software. Triage, disclosure coordination and remediation remain stubbornly human work, performed disproportionately by volunteers running projects with little or no paid security staff. The realistic outcome is not a more secure ecosystem but an overwhelming one: a flood of unactioned reports competing for scarce maintainer attention.

A second-order question concerns the research toolchain itself. Pentest and red-team organisations already leaning on AI for reconnaissance and code analysis will increasingly be working on Anthropic's models under Anthropic's terms, with Anthropic deciding who qualifies and on what basis. The announcement says nothing about how vetting decisions are made, whether criteria vary for teams outside the United States, or how regional groups fit the definition of "vetted."

For our readership specifically, the practical version of that question is blunt: would a red team based in Hong Kong or Macau, seeking this access, qualify? Nothing in the announcement addresses regional eligibility in either direction, and this desk's question is not answered by any source material reviewed — it is simply unknown. Organisations weighing an application should assume neither eligibility nor exclusion until Anthropic publishes something concrete.

The practical takeaway is narrow but real. Anthropic is betting that frontier models are more valuable to security work than they are risky to expose to a trusted cohort — and is citing its own vulnerability-hunting output as proof the bet is paying off. The 129,000 figure is an impressive number attached to an undefined claim, and the eligibility rules remain unpublished. Both deserve scrutiny before security teams reshape their toolchains around either.

Source: The Hacker News, "Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws," 7 October 2026. The article summary states Anthropic's announcement was made on Tuesday; the source page was not independently rendered at the time of writing.


編按:本文根據下述 The Hacker News 報導的摘要撰寫。撰稿時來源網頁未能完整顯示,Anthropic 的相關公告亦未經獨立查核。文中所有內容——包括漏洞數字、計劃細節,以及「其他發現」的說法——均應視為由來源轉述、尚未經核實的公司說法,待完整查證後再作參考。

Anthropic 於星期二表示,正擴大一項計劃,向經審核的網絡安全專業人員提供其先進 Claude 模型的存取權限,同時降低安全防護並放寬阻擋分類器——這意味著公司刻意為一群進攻性安全研究人員鬆綁其防護措施。

公司在公布時援引 Project Glasswing,即其自行運作的漏洞搜尋計劃。Anthropic 稱該計劃於 2026 年 4 月至 7 月期間發現至少 129,000 個「已驗證」的軟件漏洞。該漏洞數字由 Anthropic 自行公布,「已驗證」一詞亦出自公司本身——在已查閱的材料中,並未說明這些漏洞如何被發現或計算,亦未交代漏洞是否經獨立研究人員重現、獲相關供應商確認,或完成分類與修補。目前未有任何第三方審計報告公開。

方向則相當明確。Anthropic 正把其模型定位為正當的安全工具,並放寬那些在其判斷下妨礙專業滲透測試和紅隊工作的防護措施。這些限制本身是為了防止一般用戶濫用;公司的論點是,它們對經審核的研究工作構成拖累。存取權限仍然設有門檻,但 Anthropic 並未隨公告一併公布完整的申請資格準則。公司又提到在同一時期錄得其他發現,但在已查閱的材料中沒有說明這些發現的內容。

對開源社群而言,漏洞數字本身不如它所暴露的瓶頸重要。假如數字屬實,人工智能系統發現漏洞的速度,已遠超一般漏洞賞金計劃或審計計劃在同等時間內的產出——而自動化發現並不會自動帶來已修補的軟件。分類、披露協調與修補仍然是高度依賴人手的工作,而且相當部分由項目維護者承擔,他們多數是義工,運作的項目往往只有一名甚至沒有專職安全人員。最可能的結果不是更安全的生態,而是一個應接不暇的生態:大量無人跟進的報告,與有限的維護者注意力互相競爭。

另一個次級問題涉及研究工作流程本身。已經借助人工智能進行偵察和程式碼分析的滲透測試及紅隊團隊,日後將在 Anthropic 的模型上、按 Anthropic 的條款工作,由 Anthropic 決定誰有資格、按甚麼條件。公告並未說明審核決策如何作出、準則是否因美國以外的團隊而異,以及地區性團隊應如何界定為「經審核」。

就本刊讀者而言,這個問題的實際版本相當直接:香港或澳門的紅隊如果申請這項存取權限,是否有資格?公告在任何方向上都沒有處理地區資格的問題,而本刊的提問亦未獲任何已查閱的來源材料解答——答案目前仍是未知。考慮申請的機構,在 Anthropic 公布具體內容之前,不應假設自己合資格,也不應假設自己不合資格。

實際的啟示有限但明確。Anthropic 正押注前沿模型對安全工作的價值,高於向受信任群體放寬防護的風險——並以自家漏洞搜尋成果作證,證明這場押注值得。129,000 這個數字十分可觀,但附著在一個未經定義的說法之上;申請資格規則亦未公開。在安全團隊據此重塑其工具鏈之前,兩者都值得審視。

來源:The Hacker News,《Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws》,2026 年 10 月 7 日。來源報導的摘要指出,Anthropic 的公告於星期二發布;撰稿時來源網頁未能獨立顯示。

新聞來源 / Original News Source