Ugrás a tartalomra
Vissza a hírekhez
Anthropic2026. okt. 6. 21:00eszköz

Az Anthropic megnyitotta a Claude modellek kiberbiztonsági kiadásait

Az Anthropic kibővítette kiberbiztonsági programját, így a minősített szakemberek kevesebb korlátozással használhatják a Claude 5.5 modelleket védekezésre.

Expanding the Cyber Verification Program

Az Anthropic kibővítette a Cyber Verification Program (CVP) nevű kezdeményezését, amely lehetővé teszi a biztonsági szakemberek számára, hogy enyhébb korlátozásokkal használják a Claude modelleket. A program keretében a legfejlettebb modellek, köztük a Claude Opus 5.5, a Claude Sonnet 5.5 és a Claude Mythos 5.1 is elérhetők a jóváhagyott partnerek számára.

A rendszer mostantól 3 különböző hozzáférési szintet kínál a védelmi feladatoktól kezdve a tesztelésig. A legszigorúbb, kormányzati szintű ellenőrzést igénylő kategória a kritikus infrastruktúrák, például elektromos hálózatok védelmét szolgálja. A korábbi tesztek során a Claude modellek segítségével a partnerek több mint 129 000 szoftveres sebezhetőséget azonosítottak.

A hozzáférésre a Claude Platform felületén, a Google Cloud Vertex AI-on és a Microsoft Foundry-n keresztül lehet jelentkezni. Az adatok védelme érdekében az Anthropic ősszel bevezeti az ](https://www.anthropic.com)Enterprise Frontier Safeguards megoldást, amely adatmentés nélküli használatot biztosít a felhőben.

Az eredeti szöveg (Anthropic)
We’re launching a new, expanded version of our Cyber Verification Program (CVP), which makes advanced cyber capabilities and reduced blocking classifiers available to qualifying security professionals. The program now consists of three access tiers, which allow security teams to apply for the level of access that best suits their work. Each tier includes access to our most capable models, including Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and new models moving forward. Interested customers can apply here. Cybersecurity is inherently dual use: the same capabilities that enable a security team to find and fix a vulnerability can also help a malicious actor exploit it. For this reason, our generally available models, such as Claude Opus 5.5, Claude Fable 5.1, and Claude Sonnet 5.5, have conservative cyber safeguards that block most cyber work. This is intended to limit the harmful activities malicious actors can carry out using our models, while we continue to work to reduce false positives for secure coding. But defenders also need access to the best tools and most powerful capabilities to secure their systems. For the past six months, we’ve enabled trusted access through two programs: Project Glasswing and the CVP. The former gave a group of organizations securing the most critical software access to Claude Mythos; the latter gave vetted security teams access to reduced safeguards on Claude Opus and Claude Sonnet models. Now, we’re integrating these programs into one expanded offering, designed to give more security organizations access to the capabilities they need to protect their systems. The updated access tiers make specific model capabilities available to security professionals based on the scope of their cyber work. Each has different verification requirements and security controls. Defense Access is for defensive work, including security operations center and incident response tasks, reverse-engineering malware, and analyzing and validating vulnerabilities. Examples of qualifying organizations include security teams at companies, nonprofits, universities, and government bodies who are defending systems they own or maintain; operators of critical infrastructure of any size, such as regional hospitals or municipal utilities; smaller security firms; open-source maintainers; and individual researchers with a track record of reported vulnerabilities. We expect many organizations conducting defensive cybersecurity work to qualify for this tier. We aim to respond to applications within a few days. Red Team Access adds authorized penetration testing and red-teaming to the defensive uses above. Examples of qualifying organizations include in-house red teams, government red teams, and security and penetration testing firms. Organizations in this tier can only perform adversarial testing against systems they are authorized to test, including IT systems in critical industries. Users will still experience real-time blocks on actions that could cause physical harm or mass disruption, such as deploying ransomware, damaging physical systems, or pen testing high-risk safety systems. Given the increased eligibility requirements and security controls, we expect applications in this tier to take a few weeks to review. Qualifying organizations will be enrolled in the Defense Access tier while we review their Red Team Access applications. Currently, this tier is for organizations only; individual researchers are not eligible. Specialized Access, which has the fewest cyber blocks, is reserved for a limited set of verified organizations that are authorized to test safety systems that could impact people’s lives or disrupt markets, such as flight operating systems, power grids, telecom networks, interbank transfer infrastructure, and government administrative networks. For this tier, we currently review every organization in depth in collaboration with the US government. Existing members of Project Glasswing will transit