Artificial Intelligence

Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund

Claude Security, currently in public beta for Claude Enterprise customers, now runs codebase scans on Mythos 5.

Claude Mythos

Anthropic is broadening access to the cybersecurity capabilities of its advanced AI models through a mix of partner integrations, an updated Claude Security offering, a new open source funding program, and plans to expand its Cyber Verification Program.

The move builds on Project Glasswing, launched in April, which gave a small group of organizations early access to Claude Mythos Preview and its successor, Mythos 5. Anthropic said the goal was to give defenders time to find and fix vulnerabilities before comparable capabilities became widely available or fell into the hands of malicious actors. Claude Fable 5 followed as a broadly available model that keeps dual-use cyber work blocked.

Anthropic said the riskiest scenario is direct, unrestricted access to a model, a risk that drops sharply when users instead receive specific defensive outputs, such as a patch or a security alert. The latest changes are built around this idea, expanding what defenders can get from Mythos-class models while keeping guardrails around direct interaction with them.

On the integration front, Anthropic is working with cybersecurity partners to build Mythos 5 into the security operations, incident response and detection tools already used by teams protecting hospitals, utilities, financial systems, and the software supply chain. 

End users will not interact with Mythos directly. Instead they will work through purpose-built interfaces that run the model in the background and return only a defined output, such as a list of suggested patches, with abuse-prevention checks meant to keep the model within that scope.

Claude Security, currently in public beta for Claude Enterprise customers, now runs its codebase scans on Mythos 5. Scans surface each finding with a CWE category, confidence and severity ratings, and a suggested fix. Any fix still has to be implemented through Claude Code and approved by a human before deployment.

Advertisement. Scroll to continue reading.

“Claude Security uses Mythos 5 to scan code you own, and returns detailed findings rather than raw outputs without exposing the model itself,” Anthropic explained. “This means defenders can access the capabilities of Claude Mythos 5 without the model becoming accessible to those who might misuse it.”

Anthropic also launched the Defender Advantage Fund (0xDAF), putting $35 million in Claude credits toward organizations that help open source maintainers secure their projects. It follows $4 million in direct donations and other support Anthropic provided through Project Glasswing, including coordinated efforts like Akrites and Gold Eagle

Grants will go toward patching live vulnerabilities, building scanning and patching processes other projects can reuse, and pursuing security approaches meant to resist entire classes of attack. Anthropic is starting with a small number of larger pilot grants.

The Cyber Verification Program, which already gives vetted organizations reduced safeguards on Claude Opus and Sonnet for authorized security work, will expand in the coming weeks to cover broader dual-use capabilities on those models, including vulnerability triaging and validation, with Mythos-class access to follow. 

Anthropic is also continuing to expand Mythos access through Project Glasswing alongside US government partners, focused on organizations protecting critical infrastructure that meet strict security control requirements.

The AI giant is encouraging security teams to apply to the Cyber Verification Program now for reduced safeguards on Opus and Sonnet, with further details on the broader rollout expected in the coming weeks.

Related: Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini

Related: AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking

Related: OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses

Related Content

Artificial Intelligence

Researchers say the new ‘Cryptographic Context Injection’ technique conceals malicious instructions until they are decrypted inside a trusted execution environment.

Cybercrime

We all know they’re watching us. But we don’t know who they are, nor why nor how they are doing it.

Artificial Intelligence

Atalanta's Argo product is now being used to prove the resilience of Viasat’s satellite communications network.

Artificial Intelligence

The action taken by OpenAI comes in light of the Hugging Face incident and the discovery of the Astra model’s advanced capabilities. 

Artificial Intelligence

A cybersecurity advisory with technical details and recommendations has been written by the NSA, CISA and other agencies.

Artificial Intelligence

Rapid7 warns that traditional patch cycles cannot keep pace with soaring vulnerability disclosures and faster exploitation, forcing defenders to prioritize exposure over severity scores.

Artificial Intelligence

The AI security testing firm has shared information on a recently disclosed incident involving Anthropic AI models.

Artificial Intelligence

Anthropic has been conducting tests to identify issues in how AI agents interact with each other.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version