Anthropic brings Claude Mythos 5 to more cyber defenders

Anthropic brings Claude Mythos 5 to more cyber defenders
News

Anthropic is widening defensive access to Claude Mythos 5, its most capable cybersecurity model. In an announcement published on August 21, the company said Mythos 5 is now powering scans in Claude Security, which is available in public beta to Claude Enterprise customers. Anthropic is also preparing integrations with partners’ security products, launching a $35 million fund for open-source security and planning broader access through its Cyber Verification Program.

Claude Security lets an authorized user select a software repository for analysis. Mythos 5 scans the codebase for vulnerabilities and returns findings with a Common Weakness Enumeration category, confidence and severity ratings, and a suggested fix. The user can then open Claude Code to implement a patch, but every change must be reviewed and approved by a person. Scans use standard token billing under the customer’s existing Enterprise plan; they do not provide direct Mythos access elsewhere.

That boundary is central to Anthropic’s rollout. The company says direct access creates more opportunity to steer a powerful cyber model toward harmful work. Claude Security and forthcoming partner tools instead expose defined defensive outputs, such as vulnerability findings or proposed patches, while keeping the underlying model behind a purpose-built interface. Anthropic says it and its partners will apply abuse-prevention measures, although these are the company’s safeguards and claims rather than an independent guarantee of safety.

The new Defender Advantage Fund, also called 0xDAF, will provide $35 million in Claude credits to organizations that help secure open-source software. Anthropic says grants will focus on fixing live vulnerabilities, making automated scanning and patching reusable across projects, and developing approaches that prevent broader classes of attacks. Initial recipients have not yet been named.

For security teams, this is a practical expansion beyond the small group previously reached through Project Glasswing. For software makers and businesses, it offers stronger automated review without unrestricted model access, but it does not remove the need for conventional testing, authorization and human judgment. The larger market signal is that frontier cyber capabilities may increasingly reach customers through controlled products and verified programs instead of general-purpose model endpoints.

Source claude.com