Claude Security now runs Mythos 5 scans against customer code

Close-up of a person holding a Git sticker, emphasizing software development.

Anthropic integrated its Claude Mythos 5 model into Claude Security, allowing Claude Enterprise customers to run Mythos-class vulnerability scans against code stored in GitHub without receiving direct access to the model itself. As of August 21, 2026, scans connect to a repository, trace data flows across files, and return findings labeled with a Common Weakness Enumeration category, confidence and severity ratings, and suggested fixes that can be routed to Slack or Jira or exported as CSV or Markdown. Dataconomy and GBHackers both describe the rollout as a structured workflow that delivers defensive findings rather than a general-purpose prompt surface. SecurityWeek's article on the same announcement is indexed by IT Security News but did not yield substantive body text in the available evidence, leaving its independent corroboration unverified.

Controlled-output model separates scanning from patching

Claude Security uses Mythos 5 only in the background for analysis, with users receiving structured findings rather than an interactive prompt, an approach Anthropic says is intended to prevent the model from being repurposed for offensive work such as exploit development. Each finding passes through an adversarial verification step in which the model reviews its own output to reduce false positives, and patching is handled separately through Claude Code using models already available to the organization. Every change still requires human review before deployment, and GBHackers notes that no automated fix deployment has been announced.

Defender Advantage Fund directs $35 million in credits to open-source defenders

Alongside the Claude Security expansion, Anthropic launched the Defender Advantage Fund, also referred to as 0xDAF, allocating $35 million in Claude credits to organizations focused on securing open-source software. The fund targets three priorities: patching active vulnerabilities in widely used projects, automating repeatable scanning and patching workflows, and developing security enhancements that reduce exposure to broad classes of attacks. Dataconomy and GBHackers agree on the headline figure and scope, while CryptoBriefing frames the same announcement primarily through the lens of Anthropic's competitive positioning and prediction-market signals rather than the fund's operational details.

Cyber Verification Program set to widen to dual-use capabilities

Anthropic signaled that its Cyber Verification Program, which currently gives vetted defenders reduced safeguards for authorized work using Claude Opus and Sonnet, will be expanded to include additional dual-use cyber capabilities, with future Mythos-class features expected to follow. GBHackers adds that Anthropic is collaborating with cybersecurity technology and services partners to surface Mythos 5 outputs through security operations, threat detection, incident response, and vulnerability remediation tools, rather than through direct model access. The exact timing of the program expansion and partner identities were not specified in the available reporting.

Eligibility and pricing

Claude Security scanning is gated to organizations with a Claude Enterprise agreement whose code resides in GitHub, and Dataconomy reports that startups and mid-market customers on lower-tier plans are not eligible. Administrators must enable the feature through the Claude admin console before users can select a repository and initiate a scan, and scanning is billed as standard token usage under the existing Enterprise plan with no separate Mythos 5 add-on announced.

Share this article

FacebookX

5 sources

Sources