Anthropic is expanding access to Claude Mythos 5 without widely releasing the cybersecurity model. Mythos 5 now powers code scanning in Claude Security and is being integrated into partner products, where users receive findings, patches, or alerts without direct model access.
The expansion builds on Project Glasswing, which gave selected defenders early access to Mythos capabilities.
Anthropic is also committing $35 million in Claude credits to open-source security and expanding verified access for authorized cybersecurity work.
Why It Matters: Anthropic is giving defenders access to Mythos 5’s cybersecurity capabilities without giving them direct access to the model. This could limit misuse while providing stronger security tools. It also creates a new challenge, since AI can uncover vulnerabilities faster than organizations and open-source maintainers can fix them.
- Mythos 5 Is Moving Into Existing Security Workflows: Claude Security, in public beta for Claude Enterprise customers, now uses Mythos 5 to scan codebases. Findings include CWE classifications, severity and confidence ratings, and suggested fixes, with human approval required before implementation through Claude Code. Anthropic is also integrating Mythos 5 into partner tools used for security operations and incident response across critical infrastructure and software supply chains.
- Users Get Defined Results Without Unrestricted Model Access: Anthropic considers direct access to Mythos 5 more susceptible to misuse. Partner products instead run the model in the background and return outputs such as patches or alerts, with controls limiting how the model can be used. The approach extends Project Glasswing, which gave selected defenders early access to Mythos so they could find and repair vulnerabilities before comparable capabilities became widely available. Claude Fable 5 remains the widely available alternative with sensitive dual-use cyber work blocked.
- The $35 Million Defender Advantage Fund Focuses on Open-Source Remediation: Anthropic is providing Claude credits to organizations helping maintainers repair active vulnerabilities and develop reusable security methods. It follows $4 million in donations and other Project Glasswing support, including Akrites and Gold Eagle. The Next Web previously reported that Glasswing models found about 10,000 critical vulnerabilities in one month while patching struggled to keep pace, showing that AI-assisted discovery can create more work than maintainers can absorb. Anthropic will begin the fund with a small number of larger pilot grants.
- Verified Security Organizations Will Gain Access to More Capable Tools: The Cyber Verification Program already gives vetted organizations reduced safeguards on Opus and Sonnet for authorized security work. Planned changes will permit additional vulnerability triage and validation, with Mythos-class access expected later. Project Glasswing is also expanding with U.S. government partners to organizations protecting critical infrastructure that meet strict security requirements.
- Controlled Access Is Becoming One Answer to the Risks of Powerful Cyber AI: OpenAI has pursued a similar vetted-access program for security teams. Anthropic’s caution follows its July disclosure that three models reached real organizations during misconfigured cybersecurity evaluations. Open-source maintainers in Europe also face Cyber Resilience Act vulnerability-reporting requirements beginning September 11, adding pressure to process and remediate security findings. The value of more capable cyber AI may therefore depend as much on access controls and remediation capacity as model performance.
Anthropic will give defenders what its strongest model finds, but not the model itself – TNW


