Anthropic Expands Mythos 5 Security Scanning Access
Anthropic expanded access to Claude Mythos 5 for cyber defense on August 21, enabling Claude Enterprise customers to run Claude Security codebase scans on the model. SecurityWeek reports that findings include CWE classifications, confidence and severity ratings, and suggested fixes, while deployment still requires human approval through Claude Code. Anthropic also announced a $35 million credit fund for open-source security work.
Anthropic expanded access to Claude Mythos 5 for defensive cybersecurity work on August 21, making the model available for codebase scans through Claude Security for Claude Enterprise customers. The company also announced partner integrations, a $35 million Defender Advantage Fund for open-source security work, and a broader Cyber Verification Program.
Claude Security is currently in public beta. According to SecurityWeek, its Mythos 5-powered scans return findings with a CWE category, confidence and severity ratings, and suggested fixes. Suggested fixes must still be implemented through Claude Code and approved by a human before deployment.
Controlled access rather than direct model use
Anthropic's announcement distinguishes between access to a model's defensive outputs and direct access to the model. The company wrote that direct access presents the highest misuse risk because a malicious user can attempt to steer the system toward harmful cyber activity. It described scoped outputs, such as vulnerability alerts and patches, as a lower-risk delivery mechanism.
SecurityWeek reports that end users working through partner tools will not interact with Mythos 5 directly. Instead, purpose-built interfaces run the model in the background and return defined results, such as suggested patches, with abuse-prevention checks intended to limit use to that scope.
Anthropic wrote: "Claude Security uses Mythos 5 to scan code you own, and returns detailed findings rather than raw outputs without exposing the model itself." The company described this arrangement as a way to provide defenders with Mythos 5 capabilities without making the model directly accessible to potential abusers.
Enterprise scanning and partner distribution
Anthropic's April program gave a small group of organizations access to Claude Mythos Preview and its successor, Mythos 5, according to the company post. The August update expands that distribution through Claude Security and cybersecurity technology and services partners.
SecurityWeek reports that Anthropic is working to integrate Mythos 5 into security operations, incident response, and detection tools used by organizations protecting hospitals, utilities, financial systems, and software supply chains. Bloomberg Law separately reports that Anthropic is continuing Project Glasswing with US government partners for protectors of critical infrastructure meeting strict security-control requirements.
For application-security teams, the product detail that matters is the workflow boundary: Mythos 5 is being exposed as a scanner that returns structured findings and remediation suggestions, not as an unrestricted assistant. Comparable security-AI deployments commonly use such constrained interfaces to make model output reviewable, connect it to existing ticketing and remediation processes, and retain human accountability for production changes.
Funding and verification expansion
The Defender Advantage Fund, also called 0xDAF, will provide $35 million in Claude credits to organizations working on open-source vulnerability remediation and scanning automation, according to Anthropic. The company post describes the fund as support for efforts to patch vulnerabilities in open-source projects.
Bloomberg Law reports that Anthropic is also expanding its Cyber Verification Program to cover broader dual-use capabilities on Opus and Sonnet, with Mythos-class access intended to follow. The available reports do not specify a date for that later access expansion.
The announcement places automated vulnerability discovery alongside safeguards on model access and mandatory human review. For engineering organizations evaluating AI-assisted AppSec tooling, the reported controls provide concrete evaluation points: whether the system is restricted to authorized code, how findings are scored and traced, whether remediation is reviewable, and which interface limits exposure to dual-use capabilities.
Key Points
- 1Claude Security now uses Mythos 5 for Enterprise codebase scans, adding structured vulnerability findings and suggested remediation to an existing human-approved workflow.
- 2Anthropic's access model restricts direct interaction while delivering defined defensive outputs, a pattern relevant to governing dual-use models in security operations.
- 3The $35 million credit fund directs compute support toward open-source vulnerability remediation, where maintainers often face constrained scanning and patching resources.
Scoring Rationale
The expansion makes a frontier cyber-capable model available in an enterprise vulnerability-scanning workflow, with explicit controls around direct access and human approval. It is particularly relevant to AppSec and security engineering teams assessing AI-assisted code review, although availability is limited to Claude Enterprise and partner channels.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems

