Claude Security Now Scans Code With Mythos 5

Claude Security hands a single scan card through a vault slit to a tense engineer

Anthropic has wired Claude Security to Mythos 5, the model it has kept away from broad release since April because of what it can do on cyber tasks. Enterprise customers can now run a repository scan on that model without ever touching it directly, billed against the token usage they already pay for.

Key Takeaways

  • Claude Security enters public beta on Mythos 5 for every Enterprise customer, with no paid add-on attached.
  • A scan returns findings sorted by CWE category, each carrying a severity rating, a confidence score and a suggested patch that a human has to approve.
  • Anthropic pairs the launch with a 35 million dollar credit fund for open-source security and a wider verification program for defenders.

A scanner that hands back a patch, never a prompt box

The product is not new, the engine is. Claude Security came out of Project Glasswing and the 10,000 software flaws it surfaced in a single month, at a confirmed accuracy of 90.6%. Until now it ran on models anyone could reach through the catalogue.

Since August 21 it runs on Mythos 5. The switch is open to all Enterprise customers in public beta, with no add-on to buy and no model access to negotiate.

Mechanically it still behaves like a scanner. You connect a GitHub repository, the model traces data flows from one file to the next, then returns what it found under a CWE category, with a severity level, a confidence score and a proposed fix.

The interesting architectural call sits elsewhere. What the user gets back is a scan result, not a text box. Anthropic walked through an interface built to run Mythos in the background against a defined task, which stops anyone from steering the model that just found a flaw into writing the exploit for it.

The next guardrail is human. No patch ships without review, and the company frames that approval step as a condition of the rollout rather than a temporary caution.

It is worth measuring what that framing unlocks. Mythos 5 has been held back from broad availability since April, cleared for vetted defenders one at a time, precisely because its cyber capability runs ahead of the rest of the lineup.

The product walks around that wall without taking it down. The customer receives the model’s output, never the model, and the tradeoff between defender advantage and attacker uplift is settled by the interface instead of a contract clause.

Then there is the billing line, which may be the real unlock. Scans run as standard token usage on the Enterprise plan already in place. A security team has no separate contract to sign and no tooling budget to defend on its own.


Claude Security

Thirty-five million in credits and a wider circle of vetted defenders

The announcement does not stop at the product. Anthropic is launching the Defender Advantage Fund with 35 million dollars in credits aimed at open-source security.

The fund targets three uses: patching vulnerabilities in widely used open-source projects, automating scanning and patching pipelines, and backing experimental work against whole classes of attack. Same logic as the scanner, pointed at maintainers who have neither a budget nor a dedicated team.

The Cyber Verification Program widens alongside it. Verified defenders get lighter safeguards on Opus and Sonnet, broader dual-use capability, and Mythos-class access flagged as coming next.

Security vendors are the third piece. Anthropic said it is preparing to fold Mythos 5 into the products and services that protect hospitals, utilities and banks, without naming a single company. Partners already building on Claude Opus for those tools are expected to move over. Those are also the sectors the company sees targeted, having banned 832 accounts across a year of mapping AI-run cyberattacks.

That footprint extends a deployment that was already wide. The model had been pushed across fifteen countries into 150 organisations including NATO, Samsung and ENISA, hunting zero-day vulnerabilities.

Access policy on this model has never been purely technical either. The rollout was frozen, then reopened by Howard Lutnick for more than a hundred US companies and agencies cleared by Commerce. Shipping a closed product widens usage without reopening that file.


More articles on Horizon


What security teams gain, and what rival labs now have to answer

On the user side the shift is concrete for application teams. Frontier-grade scanning becomes reachable from a plan already paid for, on a perimeter the company picks repository by repository.

The bottleneck moves rather than disappears. A scanner returning hundreds of findings ranked by confidence shifts the load onto triage and approval, work that stays human and needs people able to judge a proposed patch.

On the competitive side, Anthropic just settled a tradeoff its rivals have left open. Instead of exposing a cyber-capable model through an API with a usage policy stapled on, it locks the capability inside a product with a constrained output. That answers the exact objection that had been blocking distribution of this class of model.

Competitors are left with two moves, neither of them cheap. Opening their own offensive-defensive model on an API exposes them to the recklessness charge. Building an equivalent closed product means an engineering layer none of them has demonstrated on this ground yet.

There is a standard-setting effect underneath all this. Once frontier scanning turns into a billing line on an existing plan, the question facing engineering leadership changes shape, and model-assisted security review stops being a project to fund and becomes a box in a pipeline.

The whole bet rests on how tight that layer is. The defender advantage holds only while the product output cannot be run backwards, and that guarantee is an engineering promise rather than a property of the model itself.

The company knows what a containment failure costs. It admitted that three real companies were breached out of a security test that leaked. Public beta now points the same model at a far larger customer base.

Follow the story on Horizon.

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    Your email address will not be published. Required fields are marked *