FR
Live

Claude, the essentials — edition of October 7, 2026

Anthropic widens trusted cyber access as Claude Code tightens its permission rules

By ·

Anthropic merged its two trusted-access programs for security teams into one expanded Cyber Verification Program with three tiers. Claude Code shipped four releases in the same period, several of them about permission and policy enforcement.

Key points

One program for verified defenders

Anthropic announced on October 6 that it is replacing its two earlier trusted-access arrangements with a single, expanded Cyber Verification Program. For the past six months, Project Glasswing gave organizations securing the most critical software access to Claude Mythos. The original CVP gave vetted security teams reduced safeguards on Claude Opus and Claude Sonnet models. The new program has three access tiers, each with its own verification requirements and security controls. Every tier includes Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and new models going forward.

Anthropic explains the design by the dual-use nature of the field: the capabilities that let a team find and fix a vulnerability can also help an attacker exploit it. For that reason, it says, its generally available models, including Claude Opus 5.5, Claude Fable 5.1 and Claude Sonnet 5.5, carry conservative cyber safeguards that block most cyber work. It describes this as a way to limit harmful use, and says it is still working to reduce false positives for secure coding. The company's stated rationale for the program is that defenders also need the most capable tools. One tier, Defense Access, covers defensive work such as security operations center and incident response tasks, malware reverse-engineering, and vulnerability analysis and validation. It is open to security teams defending systems they own or maintain, including at companies, nonprofits, universities and government bodies. Critical-infrastructure operators of any size, such as regional hospitals or municipal utilities, and smaller security firms also qualify. The published text available to us is truncated, so we do not describe the other two tiers.

Sources: Expanding the Cyber Verification Program — Anthropic

Claude Code: permission rules, sub-agents and plugins

Releases 2.1.289 to 2.1.292 of Claude Code cluster around how permissions are enforced. Version 2.1.289 fixes a case where a deny or ask rule on a nested part of a compound shell command did not hold over a user-installed mod's approval on managed machines. It also fixes Read deny rules not applying to files that were @-mentioned, changed or selected in the IDE through a symlink, and a terminal freeze on short code blocks with many unclosed tags or deeply nested ${ substitutions. Version 2.1.290 gives hook authors more context. The tool.check event of plugin hooks now carries an agentId, so a hook can tell a subagent's permission check from the main session's. The question and verdict a mod's tool.check hook reads now include a ceiling field naming the approval an organization requires for a tool. The result of a mod's turn.step hook now includes serverToolUses, the tool calls the API ran itself (the advisor), each with its id, name, input, start and end.

Version 2.1.291 corrects two regressions: cloud sessions dropping answers to permission prompts, introduced in 2.1.290, and the last messages of a session being lost on quit, introduced in 2.1.288. Version 2.1.292 adds an effort parameter to the Agent tool, so Claude runs a sub-agent at the effort level requested. It adds a --marketplace option to claude plugin install, which adds the marketplace if needed under the same policy checks as claude plugin marketplace add, then installs the plugin. It also adds the CLAUDE_CODE_OVERLOADED_RETRY_BASE_DELAY_MS environment variable to set a longer base backoff delay when retrying an overloaded (529) request.

Sources: Claude Code 2.1.292 — Claude Code (GitHub) · Claude Code 2.1.291 — Claude Code (GitHub) · Claude Code 2.1.290 — Claude Code (GitHub) · Claude Code 2.1.289 — Claude Code (GitHub)

Platform: a Models API flag and two resolved incidents

In its October 5 API release notes, Anthropic added capabilities.thinking.types.disabled to the Models API. GET /v1/models and GET /v1/models/{model_id} now report whether each model accepts thinking: {type: "disabled"}, which turns thinking off. Integrators can read this from the API rather than assume which models allow it.

The status page lists two incidents as resolved. On platform.claude.com, many requests to load the Usage page and the Admin API usage report returned errors from 17:00 PT on October 6 (00:00 UTC on October 7) until 18:40 PT (01:40 UTC). The second incident concerned elevated errors on requests to Claude Opus 5.5. The status entry says the cause was identified and a fix was in progress, and it now shows as resolved. The excerpt gives no timing or scope for it.

Sources: Models API: capabilities.thinking.types.disabled (release notes, October 5, 2026) — Anthropic (release notes) · Claude — Elevated errors loading usage data on platform.claude.com — Claude Status · Claude — Elevated errors for Claude Opus 5.5 — Claude Status

Claude Frontier Academy targets the enterprise talent gap

On October 2, Anthropic launched Claude Frontier Academy, backed by a $100 million commitment. It aims to train 10,000 Frontier Deployed Engineers by the end of 2027. The company frames the problem as talent: every enterprise is racing to adopt AI, it says, but the people with the skills to make it work inside a real business are the hardest to find. Anthropic describes the Academy as the first of its kind from an AI company, built on its own work deploying Claude inside large enterprises and the professional services firms that serve them.

The first program, the Frontier Deployed Engineer Residency, follows what Anthropic calls the medical model. Doctors learn from practicing physicians, train on real cases and are assessed before practicing alone, and residency engineers learn from practitioners and practice on realistic cases. Engineers from Accenture, Bain, Capgemini, Commonwealth Bank of Australia, Deloitte, McKinsey, Morgan Stanley and Novo Nordisk are named in the first cohorts. Steve Corfield, Anthropic's Global Head of Business Development and Partnerships, says the aim is for graduates to set the standard for how AI gets built inside a business.

Sources: Claude Frontier Academy: $100M to train 10,000 engineers — Anthropic

This edition is an original synthesis written by Claude from aggregated news — Anthropic's own sources first (release notes, status, newsroom, research, engineering), then the press, Hacker News, Reddit and GitHub, under the editorial supervision of Héra SASU. Every fact links to its article, publisher named. See the live feed →

Claude News is published by Héra SASU. Independent media, not affiliated with Anthropic.