Anthropic expands defensive use of Mythos 5 without opening direct access

Claude Security uses Mythos 5 to detect vulnerabilities and suggest fixes, while direct access to the model remains restricted.

Anthropic is expanding access to Claude Mythos 5’s cybersecurity capabilities without making the model directly available to all security professionals. Its strategy is to integrate Mythos 5 into specialized environments that limit possible interactions and provide users only with defensive outputs, such as vulnerability reports or proposed fixes.

This distinction reflects the dual-use nature of advanced cyber capabilities. A model capable of identifying and helping fix a vulnerability can also provide information useful for exploiting it. Anthropic is therefore seeking to broaden access to Mythos 5’s defensive benefits without allowing every user to freely ask it to develop offensive tools.

Claude Mythos 5 remains restricted to a limited group of approved organizations, particularly through Project Glasswing. Claude Fable 5 shares the same foundation but applies stricter safeguards and blocks more dual-use cyber requests, allowing Anthropic to make it more broadly available.

The first concrete expansion involves Claude Security, currently available in public beta to Claude Enterprise customers. Repository scans can now be performed by Mythos 5. An administrator must first enable the service, after which users can select a GitHub repository and initiate a vulnerability scan.

The system examines code in parallel, validates its findings through multiple stages, and returns a report for each issue it retains. Reports include a CWE category, confidence rating, severity assessment, and proposed fix. The service is intended in part to identify issues that can be difficult to detect through static rules, including certain logic errors, injection vulnerabilities, authentication bypasses, and memory corruption flaws.

The findings remain subject to human review. From a report, users can open Claude Code to examine and implement the proposed fix. This second step, however, uses the models their organization normally has access to in Claude Code. A Mythos 5 scan does not unlock the model in the terminal, chat, or Anthropic’s other products.

The same separation applies to the Claude Security plugin available in Claude Code. The plugin uses the models authorized for the company’s account and does not provide access to Mythos 5. To use Mythos 5 for an analysis, the scan must be launched from the Claude Security interface on Claude.ai.

Teams can restrict a scan to a specific directory, schedule recurring scans, and export results in CSV or Markdown formats. Webhooks can also send findings to services such as Slack or Jira. Mythos 5 scans are billed as standard token usage under the existing Enterprise plan, with no separate add-on announced.

Anthropic has not yet published detailed measurements covering false-positive rates, language-specific coverage, or comparisons with specialized security tools. The stated performance is based on the company’s own evaluations and feedback. The documentation also notes that Claude can make mistakes and that every proposed fix should be reviewed before implementation.

The second distribution channel will involve products developed by Anthropic’s partners. The company is working with cybersecurity technology and service providers to integrate Mythos 5 into tools for alert management, incident response, threat intelligence, and vulnerability remediation.

In this setup, customers do not interact directly with the model. An interface designed for a specific task sends the necessary data to Mythos 5 and returns a constrained result. A remediation tool could, for example, provide a list of suggested patches without offering a prompt field through which a user could request the development of an exploit.

Anthropic and its partners plan to add abuse-detection measures and restrict the operations available through these products. The announcement does not yet identify the products involved, their release schedules, or their commercial terms. Companies interested in building services around Mythos 5 can currently only register their interest.

This approach extends Project Glasswing, launched in April 2026 with a small group of technology companies, security organizations, and critical infrastructure operators. The program provided early access to Mythos Preview and later Mythos 5, allowing participants to find and address vulnerabilities before comparable capabilities became more widely available.

Anthropic had committed up to $100 million in model usage credits and $4 million in direct donations to open-source security organizations through Glasswing. The company is now adding another initiative: the Defender Advantage Fund, also known as 0xDAF.

The fund consists of $35 million in Claude credits, rather than an entirely cash-based pool. It is intended to help organizations patch active vulnerabilities in widely used projects, automate repeatable scanning and remediation processes, and experiment with methods designed to eliminate broader classes of security flaws.

The program will begin with a limited number of relatively large pilot grants. Anthropic plans to announce the first recipients in the coming weeks but has not yet published a general application process, grant amounts, or detailed selection criteria.

A third component involves the Cyber Verification Program. This free program already gives vetted professionals fewer interruptions when using Claude Opus or Sonnet for authorized cybersecurity work.

Explicitly prohibited requests, such as creating ransomware or performing large-scale data exfiltration, remain blocked. Certain dual-use operations may nevertheless be permitted for organizations able to demonstrate their legitimacy, identity, and authorization to work on the systems involved.

Enrollment is tied to the organization’s ID and requires data retention to be enabled. Organizations operating under a zero-data-retention policy must use a separate workspace. Anthropic aims to respond to applications within two business days, although acceptance does not guarantee that every