Anthropic said on August 21, 2026 that Claude Mythos 5, the cyber-capable model it has limited to vetted defenders since April 2026, is now running vulnerability scans in Claude Security for Enterprise customers. The same announcement lays out plans to bring Mythos 5 into security partners’ products, commits $35 million in credits to a new fund for open-source defense, and previews an expansion of the company’s Cyber Verification Program toward Mythos-class access.
The moves mark the third stage of a rollout Anthropic has deliberately kept slow. The company’s reasoning, laid out in the announcement, is that the danger concentrates where a user has direct access to the model and can try to steer it toward offensive work. When users can only receive “specific outputs, such as a patch for a vulnerability or a security alert,” Anthropic argues, that risk drops considerably, so the expansion widens access to defensive results while keeping guardrails around the model itself.
Four concrete changes make up the announcement. Enterprise customers can now run Claude Security scans on Mythos 5; Anthropic is working with cybersecurity technology and services partners to build the model into tools defenders already run; the new Defender Advantage Fund (0xDAF) will distribute $35 million in Claude credits to organizations securing open-source software; and the Cyber Verification Program, which currently gives vetted organizations reduced safeguards on Claude Opus and Sonnet models, will expand in the coming weeks to cover broader dual-use capabilities on those models, with Mythos-class access to follow.
How Claude Security Delivers Mythos 5 Without Opening the Model
Claude Security is in public beta for Claude Enterprise customers, and Anthropic says scans with Mythos 5 are billed as standard token usage under existing plans, with no separate add-on. Admins enable the feature in the admin console; from claude.ai/security, a user picks a repository, and the model scans the codebase for vulnerabilities. Each finding comes back with a CWE (Common Weakness Enumeration) category, confidence and severity ratings, and a suggested fix. The user then opens Claude Code on the web to implement the patch, and every patch must be reviewed and approved by a human before it lands.
The scoping is the point. The Mythos 5 scan returns detailed findings rather than raw model outputs, and running one does not extend Mythos access to any other surface: interactive patching uses whichever models the organization already has in Claude Code. Partner integrations follow the same pattern. An end user of a partner product never prompts Mythos 5 directly; a purpose-built interface runs the model in the background for a defined task and returns only the intended artifact, such as a list of suggested patches. Anthropic says it and its partners run abuse-prevention measures to keep the model inside that scope, and vendors building security products can register interest in the integration program.
The partner channel builds on an ecosystem Anthropic has been assembling since May 2026, when it reported that firms including Wiz, Palo Alto Networks, CrowdStrike, and Accenture had built cyber products on Claude Opus. The early figures in that post are company-reported rather than independently measured, but they describe the shape of the market: Wiz said its Opus-powered offensive-testing agent runs continuously across more than 150,000 production assets a week, and Accenture said it took security testing coverage from roughly 10% to over 80% across 1,600 applications while cutting scan turnaround from 3–5 days to under an hour. CrowdStrike’s consulting chief Mark Manglicmot, whose firm sells an Opus-based readiness service, put the partner case this way: “Frontier models like Anthropic’s Claude Opus are giving defenders a capability advantage that didn’t exist a year ago, pushing vulnerability management all the way to the left.”
Palo Alto Networks recently enlisted Anthropic, OpenAI, and industrial-control vendors for critical-infrastructure defense, and vendors such as Harness have begun shipping agents that scan, triage, and patch vulnerabilities at machine speed.
From Project Glasswing to a Wider Defender Rollout
Anthropic’s caution with this model class dates to Project Glasswing, launched on April 7, 2026 with a coalition whose members included Amazon Web Services, Microsoft, Google, CrowdStrike, and the Linux Foundation. The project put Claude Mythos Preview into the hands of a small group securing critical software, backed by up to $100 million in usage credits and $4 million in direct donations to open-source security organizations. Anthropic said Mythos Preview had already found thousands of high-severity vulnerabilities, including some in every major operating system and web browser: a 27-year-old remotely triggerable flaw in OpenBSD, a 16-year-old bug in an FFmpeg line that automated testing had hit five million times without catching, and a chained Linux kernel privilege escalation. All three were reported to maintainers and patched before disclosure. The program kept adding participants over the summer, with security firms like Horizon3.ai joining the vulnerability hunt in July 2026.
On June 9, 2026, Anthropic split the model in two for its Fable 5 and Mythos 5 launch. Claude Fable 5 is the same underlying model with safety classifiers that route cyber, biology, and distillation-related queries to Claude Opus 4.8 instead; it went to general availability. Claude Mythos 5, with cyber safeguards lifted for vetted users, went to Glasswing partners at $10 per million input tokens and $50 per million output tokens, less than half the price of Mythos Preview. Anthropic said an external bug bounty produced no universal jailbreaks in over 1,000 hours of testing, and it has kept tuning the classifiers since: earlier in August 2026 it retuned Fable 5’s biology safeguards, cutting blocked queries 85%. Traffic on Mythos-class models carries a 30-day retention requirement, which Anthropic says is used for safety purposes and not training.
Anthropic’s Cyber Defense Push by the Numbers
- $35 million in Claude credits committed to the Defender Advantage Fund (0xDAF), for patching live vulnerabilities in widely used open-source projects, automating scanning and patching in ways other projects can replicate, and approaches that make projects resistant to whole classes of attack
- $100 million in usage credits committed to Project Glasswing in April 2026, plus $4 million in direct donations: $2.5 million to Alpha-Omega and OpenSSF through the Linux Foundation, and $1.5 million to the Apache Software Foundation
- $10 per million input tokens and $50 per million output tokens for Mythos 5, versus $25 and $125 for Mythos Preview
- More than 40 additional organizations maintaining critical software infrastructure given access beyond Glasswing’s 12 launch partners
- 83.1% versus 66.6%: Mythos Preview against Opus 4.6 on CyberGym vulnerability reproduction, as measured and reported by Anthropic itself
The fund extends work Anthropic says Glasswing already started, including support for coordinated vulnerability-fixing efforts like Akrites and the White House’s Gold Eagle initiative. It starts with a small number of larger pilot grants while Anthropic learns what scales.
What Comes Next for Mythos-Class Access
The near-term milestones are all scheduled. Anthropic says that over the coming weeks the Cyber Verification Program will expand: defensive capabilities like vulnerability triaging and validation move to Mythos-class models, and enrolled defenders will see reduced blocks on Opus and Sonnet. Organizations already accepted need take no action; Anthropic says it will reach out with updates. Initial Defender Advantage Fund recipients will be named in the coming weeks as the pilot grants land, and partner integrations carrying Mythos 5 into commercial security products are described as early work the company expects to expand over time. In parallel, Anthropic says it is widening Mythos access through Project Glasswing with U.S. government partners, aimed at operators of critical infrastructure that meet strict security control requirements.
Claude Security remains in public beta for Enterprise customers, with Mythos 5 scans live as of August 21, 2026 and billed as standard token usage under existing plans.
Credit: Source link

























