anthropic

Mythos 5 lands in Claude Security for enterprise beta

Claude News

anthropic

Anthropic has moved Claude Security onto Claude Mythos 5, the model it held back from public release, and opened the scanner in public beta to every Claude Enterprise customer. The company announced the change on X, saying teams can put its most capable security model on a codebase without separate access to the model.

At a glance

  • The scanner points at a GitHub repository and traces data flows across files, reasoning about how components interact, then returns each finding with a CWE category, confidence and severity ratings, and a suggested fix.
  • Scans bill as standard token usage under an existing plan, at $10 per million input and $50 per million output tokens according to The New Stack, and patches open in Claude Code on the web.
  • Alongside the beta, Anthropic's new Defender Advantage Fund puts $35 million in credits toward open-source security, and the company is working with partners to embed Mythos 5 in their products.

Mythos 5 has been the model Anthropic kept away from general access, and the shape of this release reads as an attempt to separate capability from control: defenders receive findings and patches, attackers never touch a prompt. The open question is ownership. Many codebases vendor open-source libraries, and a vulnerability found in a widely deployed dependency inside a company repo is the same vulnerability everywhere that dependency ships.

Mythos 5 runs behind the scan and returns findings only

Anthropic frames the arrangement as a way to widen access to defensive results while keeping direct model access closed. The company says the riskiest behavior occurs when a user has direct access to a model and can steer it toward harmful uses, and that the risk drops sharply when users receive only specific outputs such as a patch for a vulnerability or a security alert.

Claude Security uses Mythos 5 to scan code the customer owns, according to Anthropic, and the company says it and its partners have abuse prevention measures in place to verify the model stays within its intended scope. Admins enable the beta for their users, after which developers and security teams run repository scans.

Mythos 5 previously reached only about 150 partners in Project Glasswing

Mythos 5 is the model Anthropic held back from public release over its performance in high-risk domains. It went instead to roughly 150 partners in the Project Glasswing program, while June brought Fable 5, essentially the same model under very strict guardrails. The New Stack notes that Fable 5 was later banned and then unbanned by the U.S. government.

Claude Security itself launched earlier this year as an enterprise tool for scanning codebases and patching what the scan finds. The Mythos 5 upgrade puts the model at the center of that workflow; patches open in Claude Code on the web, using the models a team already runs.

The Defender Advantage Fund carries $35 million in credits for open-source security

The fund, which Anthropic abbreviates 0xDAF, provides $35 million in credits for finding and patching vulnerabilities in open-source software. The company is also working with security vendors to integrate Mythos 5 into their own products and services. Anthropic describes the fund, the partner work and the program expansion as steps toward bringing frontier capability to more defenders.

Separately, the Cyber Verification Program, which lets vetted defenders run dual-use cybersecurity work on Claude Opus and Claude Sonnet with fewer blocks, expands in the coming weeks. Anthropic says the organizations vetted through that program will also receive safeguarded access to Claude Mythos soon.

When Mythos access widens further

The beta is open to all Claude Enterprise customers as of the announcement. Anthropic has not said when it reaches general availability, when the partner integrations ship, or when Cyber Verification organizations receive their safeguarded Mythos access; the program expansion itself is described only as coming in the following weeks.

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.