Anthropic is expanding Mythos security access for cybersecurity teams, aiming to help defenders evaluate and improve protection before advanced AI capabilities become widely available. The company’s approach blends integrations with existing security tools, updated model-focused offerings, and a new funding program for open source maintainers.
The key idea is to widen what security teams can do with Mythos-class capabilities while reducing the chance that the model can be directly interacted with in an unrestricted way. Instead of handing users raw model access, Anthropic focuses on producing specific defensive outputs such as patch suggestions and actionable security findings.
Why Anthropic is expanding access carefully
Anthropic points to the riskiest scenario as direct, unrestricted access to a model. In its view, the threat drops sharply when users receive defined defensive results rather than the ability to probe, manipulate, or interact with the model in open-ended ways.
That principle is behind the latest updates. The company wants defenders to gain more value from Mythos-class models, but with guardrails that limit direct interaction and route requests through controlled, security-oriented interfaces.
From early pilots to wider Mythos availability
The new changes build on Project Glasswing, launched in April. At the start, a smaller set of organizations received early access to Claude Mythos Preview and its subsequent release, Mythos 5.
Anthropic described the early-access effort as a way for defenders to identify weaknesses, develop fixes, and strengthen their processes. It also followed up with Claude Fable 5, which remains broadly available while keeping dual-use cyber work blocked.
As the program matures, access is designed to move through channels that return only scoped defensive outputs. End users, Anthropic emphasizes, should not interact with Mythos directly. Instead, they work through purpose-built interfaces that run the model in the background and apply abuse-prevention checks to keep the response within the agreed defensive boundaries.
Integrations with real-world security operations
A major plank of the expansion is practical integration. Anthropic is working with cybersecurity partners to incorporate Mythos 5 into the systems teams already use for protection and response.
According to the company, Mythos 5 is being embedded into areas such as security operations, incident response, and detection tooling. The described end users include organizations defending critical environments—hospitals, utilities, financial systems, and entities tied to the software supply chain.
This matters because defenders often need consistent workflows, not ad-hoc tooling. When advanced capabilities plug into established processes, teams can apply results like vulnerability-related guidance without changing how their operations function day to day.
Claude Security updates: scans with CWE context
Anthropic also upgraded Claude Security for defenders who use Claude Enterprise. The offering is currently in public beta for those customers, and it now runs its codebase scans on Mythos 5.
With these scans, findings are presented with more structured context than raw model output. Anthropic says each finding includes a CWE category along with confidence and severity ratings, plus a suggested fix.
Importantly, Anthropic draws a line between recommendations and deployment. Any fix still has to be carried out through Claude Code, and human approval is required before changes are deployed. That combination keeps control in the hands of defenders and prevents fully automated, unreviewed updates.
Anthropic’s explanation is that Claude Security uses Mythos 5 to scan code the organization owns, returning detailed findings while avoiding exposure of the model itself. The goal is to let defenders access the capability without making the model directly usable by parties who might misuse it.
A new $35M open source Defender Advantage Fund
Beyond tooling and verification, Anthropic is funding work that supports the security ecosystem at the source. The company launched the Defender Advantage Fund (0xDAF), allocating $35 million in Claude credits for organizations that help open source maintainers secure their projects.
This follows earlier support that included $4 million in direct donations and other assistance provided through Project Glasswing. Anthropic points to coordinated efforts as part of that broader support, including work associated with Akrites and Gold Eagle.
The new fund is intended to back grants in areas such as patching live vulnerabilities, building reusable scanning and patching processes, and pursuing security approaches designed to resist entire classes of attack.
Anthropic says it is starting with a limited number of larger pilot grants, with focus areas centered on immediate risk reduction and scalable defensive practices other projects can adopt.
Expanding the Cyber Verification Program
Another route to broader Mythos security access involves expanding Anthropic’s Cyber Verification Program. The program already provides vetted organizations reduced safeguards on Claude Opus and Sonnet for authorized security work.
In the coming weeks, the company says the program will expand to cover broader dual-use capabilities on those models. The described scope includes vulnerability triaging and validation, with Mythos-class access expected to follow after.
Anthropic is encouraging security teams to apply now to the Cyber Verification Program to access reduced safeguards for Opus and Sonnet. Additional information about the broader rollout is expected in the weeks ahead.
Continued Glasswing work with government partners
In parallel, Anthropic continues to expand Mythos access through Project Glasswing with US government partners. The emphasis is on organizations that protect critical infrastructure and meet strict security control requirements.
These efforts reinforce Anthropic’s pattern: wider capability access, but within defined boundaries and under verification-style oversight. The approach aims to help defenders evaluate and strengthen defenses in high-impact settings, rather than simply broadcasting advanced access to any user.
What the shift means for defenders
For cybersecurity teams, the practical outcome is a set of pathways to use Mythos-class capabilities without getting raw model access. Mythos security access is being operationalized through secured interfaces, partner integrations into day-to-day security workflows, and Claude Security scanning that produces structured, reviewable findings.
At the same time, Anthropic is funding the ecosystem through a dedicated open source program. That funding is intended to support patching, reusable defensive processes, and broader resistance strategies—useful not only for individual teams, but for the software landscape they rely on.
Looking ahead
Anthropic’s plan is still unfolding. The company expects more detail on the expanded Cyber Verification Program rollout, and it continues efforts to broaden access through Glasswing alongside government partners.
Overall, the direction is clear: increase defensive capability access while maintaining guardrails that reduce misuse risk. If executed effectively, this can help security teams harden systems faster—especially when vulnerabilities and attacks are evolving quickly.
