Anthropic will provide defenders with the output generated by its most powerful model, but will not disclose the model itself.
Anthropic has launched Claude Mythos 5 for code scanning within Claude Security and is incorporating it into its partners’ defensive products. Users will receive outputs instead of having direct access to the model. Additionally, the company is committing $35 million in credits to support open-source security initiatives.
Anthropic is expanding access to its most advanced cybersecurity model while restricting direct model interaction for most users. Claude Mythos 5 now performs code scans within Claude Security and is integrated into the existing products that defenders utilize.
The design approach is key to this system. A user utilizing a partner's tool will receive a specific artifact, such as a proposed patch or alert, without any ability to request the model to generate exploit code.
Currently operational is the scanning feature. Enterprise clients can direct Mythos 5 to a repository and obtain results labeled with a CWE category, severity, confidence rating, and a recommended fix, charged as standard token usage instead of an additional fee.
Human oversight is intentionally maintained; every patch must be evaluated and approved by a person prior to implementation, and the scan does not expand Mythos access beyond that.
The second major announcement involves funding, addressing a significant bottleneck. Anthropic is allocating $35 million in credits to the Defender Advantage Fund for open-source security, prompted by a report from TNW that Glasswing's models identified 10,000 critical vulnerabilities in a single month, outpacing the patching efforts.
Grants will focus on three areas: fixing active vulnerabilities in widely used projects, automating the scanning and patching processes for replication by other projects, and developing designs that mitigate entire classes of attacks.
The timing is significant for European maintainers, as the Cyber Resilience Act's vulnerability reporting requirements begin on September 11, just three weeks away. These regulations specifically target open-source stewards, who are required to maintain a cybersecurity policy, report actively exploited vulnerabilities, and collaborate with market surveillance authorities, although they will not face penalties. Securing access to Mythos for Europe was also a negotiation process.
Credits are not the same as maintainers; this is a limitation. A fund focused on model usage assists projects that already have personnel to implement it.
The competitive landscape is taking on a similar form. OpenAI has established its own vetted access program for security teams, following the same principle of restricting capabilities based on verification.
The caution surrounding these developments is recent. In July, Anthropic disclosed that three of its models had reached actual organizations due to misconfigured cybersecurity assessments, reinforcing the preference for providing results instead of prompts.
Other articles
Anthropic will provide defenders with the output generated by its most powerful model, but will not disclose the model itself.
Anthropic is integrating Mythos 5 into Claude Security and partner tools, while also providing $35 million in credits for open-source patching, just weeks ahead of the EU regulations taking effect.
