Anthropic has announced a significant expansion of access to the cybersecurity capabilities of Mythos 5 , the company’s most advanced security-focused AI model. The move combines integrations with industry partners, an updated version of Claude Security , a new $35 million open source funding program , and an expansion of the Cyber Verification Program . It’s one of Anthropic ’s most ambitious moves to put the power of Mythos 5 in the hands of defenders, without opening the door to malicious users.

The announcement follows Project Glasswing, which began in April 2026 as a tightly controlled access program for select organizations — government agencies, critical infrastructure companies, and cybersecurity researchers. Through Project Glasswing, these organizations gained early access to Claude Mythos Preview and later Mythos 5, with the goal of identifying and fixing vulnerabilities before they became widely known or exploited by malicious actors. According to reports, program participants identified approximately 10,000 critical vulnerabilities in a single month — a number that highlights both the power of automated discovery and the slow pace at which humans can fix them.
Anthropic emphasizes that the most dangerous scenario is immediate, unrestricted access to a powerful AI model. This risk is drastically reduced when users only receive specific defensive results — such as a patch or a security alert — rather than directly accessing the model. This philosophy permeates all new announcements: Mythos 5 remains “behind the curtain,” while defenders gain access to its results through controlled interfaces.
See also: Claude Mythos 5: Tried to introduce malware into open-source project
Mythos 5 at Claude Security: How it works for Enterprise Defenders
Claude Security, which is in public beta for Claude Enterprise, has been upgraded to perform code scans using Mythos 5.Each finding is presented with a CWE, confidence and severity ratings, and a suggested fix. However, each fix must be implemented through Claude Code and approved by a human before deployment — an important safeguard that keeps human control at the heart of the process.

End users do not interact directly with Mythos 5.Instead, they work through specially designed interfaces that run the model in the background and return only a specified result — for example, a list of recommended patches. Abuse prevention checks ensure that the model remains within this scope. Anthropic explained: “Claude Security uses Mythos 5 to scan your code and return detailed findings, without exposing the model itself.” Scans are billed as regular token usage, with no separate subscription fee.
On the integration front, Anthropic is working with cybersecurity partners to integrate Mythos 5 into Security Operations, Incident Response , and threat detection already used by teams protecting hospitals, utilities, financial systems, and the software supply chain. This approach extends the reach of defense capabilities well beyond its own work environment.
Defender Advantage Fund: $35 Million for Open Source Security with Mythos 5
One of the most impressive elements of the announcement is the Defender Advantage Fund (0xDAF) — a $35 million Claude credits for organizations that help open source maintainers secure their projects. This fund comes on top of the $4 million in direct donations and other support that Anthropic has provided through Project Glasswing, including coordinated efforts like Akrites and Gold Eagle.
See also: Claude Fable 5: Anthropic releases first public Mythos-Class model

The grants will be directed in three main directions: fixing vulnerabilities, creating scanning and remediation processes that can be reused by other projects, and developing security approaches that resist entire classes of attacks. Anthropic is starting with a small number of larger pilot grants. The choice to provide Claude credits instead of direct access to the model is deliberate: organizations gain computing power for defensive work, without gaining unlimited access to Mythos 5.
The need for such a fund is understandable when one considers the sheer volume of vulnerabilities that automated scanning can uncover. The 10,000 critical findings in a month from Project Glasswing highlight a fundamental problem: AI-powered vulnerability discovery can far outpace the ability of volunteer maintainers to fix them. 0xDAF attempts to bridge this gap by funding both human labor and automation.
The Cyber Verification Program, which already provides verified organizations with reduced assurances in Claude Opus and Sonnet for authorized security work, will expand in the coming weeks to cover broader dual-use capabilities — including vulnerability classification and validation — with level access Mythos- to follow at a later stage. In parallel, Anthropic continues to expand access to Mythos through Project Glasswing in collaboration with U.S. government partners, focusing on organizations protecting critical infrastructure and meeting stringent security audit requirements.
See also: Anthropic: Mythos may come to Claude Code

For security teams looking to leverage these capabilities, Anthropic recommends: using AI scanning in controlled workflows with human review for all high-severity findings, restricting access through corporate controls and logging, and treating AI-suggested fixes as a starting point rather than a final solution. For open source maintainers, seeking funding or credits that support classification, remediation, and automation is critical, given the scale of findings that can outpace volunteer capacity. According to SecurityWeek, Anthropic is encouraging security teams to apply to the Cyber Verification Program now, with more details on the broader expansion expected in the coming weeks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
