CyberSecurityNews

Claude Mythos 5 Now Available in Claude Security for Vulnerability Scanning


Anthropic has expanded access to its frontier AI cyber-defense capabilities by making Claude Mythos 5 available in Claude Security, enabling enterprise customers to scan codebases for vulnerabilities and receive AI-generated remediation guidance.

The move is designed to give defenders stronger vulnerability discovery and patching support while keeping direct access to the model constrained by purpose-built safeguards.

Claude Security, currently in public beta for Claude Enterprise customers, can scan a selected repository with Claude Mythos 5 and return findings classified by Common Weakness Enumeration (CWE), severity, confidence rating, and suggested fixes.

The results are intended for human review, allowing security teams and developers to assess potential flaws before choosing whether to implement a patch.

Mythos 5 Available in Claude Security

The company said Mythos 5 scans are billed through standard token usage under an organization’s existing Claude Enterprise plan, with no separate add-on for the capability.

Enterprise administrators can enable Claude Security from the administration console, after which authorized users can submit repositories for AI-assisted vulnerability scanning through the Claude Security interface.

Anthropic’s approach reflects a growing effort across the AI industry to deliver advanced offensive-and-defensive cyber capabilities through controlled workflows rather than unrestricted model access.

In Claude Security, the user receives a defined defensive artifact, such as a list of vulnerability findings or proposed patches, rather than the ability to freely prompt Mythos 5 for arbitrary cyber tasks. This design is intended to reduce the risk that a user could redirect the model toward exploit development or other harmful activity.

The company emphasized that the vulnerability scan does not automatically apply code changes. Users can move from the finding into Claude Code on the web to work on remediation, but patching relies on the models already available to their organization.

Every proposed change must still be reviewed and approved by a human before implementation, preserving accountability in the software security lifecycle.

Beyond Claude Security, Anthropic is working with cybersecurity technology and services partners to embed Claude Mythos 5 into existing products used for security operations, incident response, threat intelligence, detection engineering, and software remediation.

The intended model is one where security teams interact with familiar tools while Mythos operates behind the scenes on narrowly defined defensive tasks.

For example, an integrated vulnerability-management product could use Mythos 5 to analyze a flaw and produce candidate patches, while the end user sees only those outputs inside the product interface. According to Anthropic, partner integrations will include scope controls and abuse-prevention mechanisms intended to ensure that the model remains focused on authorized cyber-defense activities.

The announcement also includes a new $35 million Defender Advantage Fund, known as 0xDAF, that will provide Claude credits to organizations improving open-source software security.

Funding will prioritize remediation of live vulnerabilities in widely used projects, scalable automation for code scanning and patching, and security initiatives designed to protect against broad classes of attacks.

Anthropic is also preparing to expand its Cyber Verification Program, which provides vetted organizations with reduced safeguards for legitimate, authorized cybersecurity work with Claude Opus and Sonnet models.

The company said broader dual-use capabilities for those models will be added in coming weeks, while Mythos-class access is expected to follow for qualified defenders.

For enterprise security teams, the Claude Mythos 5 integration positions Claude Security as an AI-assisted vulnerability scanning option that combines code analysis, contextual findings, and human-controlled remediation.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC





Source link