TLDRocket
Sign in

Anthropic brings Mythos 5 to its Claude Security vulnerability scanner

The New Stack Frederic Lardinois Covered by 2 sources

Anthropic just put its hidden Mythos 5 model into Claude Security for enterprise users. That means more vulnerability scans and patch help, but no direct model access to poke at.

Based on reporting by The New Stack, Frederic Lardinois — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Anthropic has given its Claude Security tool a serious upgrade. The enterprise product, which scans codebases for security holes and suggests fixes, now runs on Mythos 5 for users in public beta on Claude Enterprise.

That’s a notable shift because Mythos 5 was not released openly in the first place. Anthropic kept it back after deciding it was too capable in high-risk settings, then shipped Fable 5 in June as a heavily restricted version. Until now, Mythos 5 had only been available to about 150 partners in Project Glasswing.

Anthropic’s pitch is straightforward: the danger rises when someone can directly steer a model, but drops when the model only returns bounded outputs like alerts or patches. In Claude Security, users are supposed to get those results without direct access to Mythos 5 itself. Anthropic says the service scans code you own and that it and its partners have abuse-prevention checks to keep the model inside its intended scope.

The company is also widening the security push beyond its own product. It’s working with other cybersecurity companies so they can build Mythos 5 into their tools, and it is launching the Defender Advantage Fund, or 0xDAF, with $35 million in credits aimed at finding and patching flaws in open source software. Anthropic says organizations in its Cyber Verification Program, which already lets vetted defenders do dual-use work on Opus and Sonnet with fewer blocks, will get safeguarded access to Claude Mythos soon.

There’s still a practical wrinkle here. Codebases often mix owned code with open source libraries, and copying a widely used library into a repo doesn’t make the underlying bug disappear. If Mythos 5 is good at finding a weakness in one place, it may be good at finding it everywhere. Anthropic’s bet is that control of the harness makes that safe enough. Maybe. The bill, though, is very real: $10 per million input tokens and $50 per million output tokens.

My take — AI-written commentary, not fact-checked reporting

This is the classic Anthropic move: keep the flashy model locked up, then sell the controlled version back as safety. It may be the right call, but it also shows how much the company likes being both the gatekeeper and the referee. That’s very convenient if you enjoy trust exercises with an invoice attached.

Read more about this at: The New Stack

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.