Goblin News
Goblin NewsAI news, distilled.
← Back to feed
7

Anthropic Opens Claude Mythos 5 to Enterprise Security and Launches $35M Defender Fund

Security2 sources·Aug 21

Summary

  • • Claude Mythos 5 enters public beta in Claude Security for all Enterprise plan users today
  • • Anthropic embeds Mythos 5 in partner cyber defense tools via output-restricted interfaces
  • • New $35M Defender Advantage Fund (0xDAF) provides credits for open-source security work
  • • Cyber Verification Program expands to broader dual-use capabilities, with Mythos-class access to follow
Adjust signal

Updates

Aug 24
Stat

Glasswing found 10,000 critical vulnerabilities in one month

TNW reported that Project Glasswing's models identified 10,000 critical vulnerabilities in a single month; patching pace could not keep up, directly motivating the $35M Defender Advantage Fund.

Tech Info

Scan output: CWE category, severity, confidence, fix suggestion

Enterprise repository scans return findings tagged with CWE category, severity rating, and confidence score, plus a suggested fix per vulnerability — billed as ordinary token usage, not a separate add-on.

Policy

EU Cyber Resilience Act obligations begin September 11, 2026

The CRA's vulnerability reporting and cybersecurity policy requirements for open-source stewards start September 11 — three weeks from announcement — creating urgent time pressure for European maintainers to adopt scanning tools.

Security Alert

Anthropic July 2026: models reached real orgs via misconfigured evals

Anthropic disclosed in July 2026 that three of its models reached real organizations during misconfigured cybersecurity evaluations — the specific incident reinforcing the decision to provide outputs rather than direct model access.

Context

OpenAI running a parallel vetted security access program

OpenAI has its own vetted access program for security teams built on the same verification-before-capability logic, indicating industry convergence on a common framework for responsible dual-use AI deployment.

Details

Product Launch

Mythos 5 Now in Enterprise Claude Security Beta

Enterprise plan customers can now run Claude Mythos 5 in Claude Security to scan codebases for vulnerabilities and suggest patches; previously limited to a vetted pilot group under Project Glasswing.

Context

Project Glasswing Background (April 2026)

In April 2026, Anthropic launched Project Glasswing to give a small group of organizations early access to Claude Mythos Preview and Mythos 5 for securing critical software, providing defenders a head start before similar capabilities reached malicious actors.

Strategy

Output-Restricted Interface Safety Model

End users of integrated partner products interact via purpose-built interfaces running Mythos 5 in the background, receiving only specific artifacts — such as vulnerability patches or security alerts — rather than direct model access, substantially reducing dual-use risk.

Partnership

Mythos 5 Integration into Cyber Defense Partner Tools

Anthropic is working with cybersecurity technology and services partners to embed Claude Mythos 5 into existing security operations, incident response, threat intelligence, and detection engineering products — the tools already used to defend hospitals, utilities, and financial systems.

Financials

$35M Defender Advantage Fund (0xDAF) Launched

A new $35 million credit fund supports organizations patching vulnerabilities in open-source projects, automating scanning and patching workflows, and experimenting with new security approaches.

Product Launch

Cyber Verification Program Expansion Coming Soon

The existing Cyber Verification Program — which gives vetted defenders reduced safeguards on Opus and Sonnet models — will expand to include broader dual-use capabilities on those models within weeks, with Mythos-class access planned to follow.

Industry Update

Claude Fable 5 as Safety Architecture Proof of Concept

Claude Fable 5 was the first step: making models broadly available while using safety classifiers to block dual-use cyber work — proving the safeguard architecture before extending it to more capable Mythos-class models.

Insight

Direct Model Access Identified as Primary Dual-Use Risk

Anthropic identifies direct user-model interaction as the highest-risk scenario — where adversaries can steer behavior toward harmful uses. Product-mediated interfaces that return specific outputs drastically reduce this attack surface while preserving full defensive value.

Anthropic blog post (claude.com/blog/bringing-claude-mythos-5-to-more-defenders), August 21, 2026

What This Means

Anthropic is systematically scaling its most capable security-focused model from a closed pilot to broad enterprise and partner availability, using layered access controls to manage dual-use risk. The $35M fund and partner tool integrations signal a move from research-stage deployment to production-grade embedding in the tools that actually defend hospitals, utilities, and financial infrastructure. This marks a significant moment in AI-powered cybersecurity: frontier models are being deployed where security operations happen, not merely offered as standalone APIs. The tiered access architecture Anthropic is pioneering — output-restricted interfaces, identity-verified programs, graduated capability tiers — may become a template for how AI labs responsibly deploy powerful dual-use systems at scale.

Sources

Update history (1)
Aug 24Added five new detail rows from TLDR AI coverage: Glasswing's 10K vulnerabilities/month stat, code scan output format (CWE/severity/confidence), EU Cyber Resilience Act September 11 deadline, Anthropic's July 2026 misconfigured-eval disclosure, and OpenAI's parallel vetted access program.

Similar Events