Anthropic released Claude Sonnet 5.5 for coding and knowledge-work use, claiming more than 30% faster responses than Sonnet 5, lower token use and up to 30% lower per-task costs while retaining pricing of $2 per million input tokens and $10 per million output tokens. The company reported major benchmark gains, including a 70.6% Terminal-Bench 4.0 score versus 10.3% for Sonnet 5, while positioning Opus 5.5 as the stronger option for complex, open-ended work requiring sustained judgment. Sonnet 5.5 is available through the Claude Platform, AWS, Google Cloud and Microsoft Azure, with a zero-data-retention option in supported deployments.
Anthropic assessed Sonnet 5.5 as having cybersecurity capabilities comparable to Opus 5.5 and applied a three-stage, Opus-level cyber-safety policy. Routine defensive development work, including bug discovery and remediation, remains permitted, but higher-risk cyber requests may be blocked or routed to the older Sonnet 5; API customers must explicitly enable that fallback. Anthropic cautioned that the fallback model is materially more susceptible to prompt injection, while classifiers may also generate false positives when processing untrusted repository, web, file, memory or connector content. The company is tuning those controls, plans expanded access for verified defenders through its Cyber Verification Program, and added measures intended to prevent model-capability extraction through large-scale fake-account activity.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Anthropic launched Claude Sonnet 5.5 for coding and office-work tasks via the Claude Platform, AWS, Google Cloud, and Microsoft Azure. The release added three-stage cyber-safety classifiers and fallback to Sonnet 5 for certain higher-risk cyber requests, while retaining the prior Sonnet API list price.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcethenewstack.io
Open sourcethenewstack.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.