Category [Product announcements](https://claude.com/blog/category/announcements)Product No items found.Date August 21, 2026Reading time 6 minShare [Copy link](https://claude.com/blog/bringing-claude-mythos-5-to-more-defenders#)https://claude.com/blog/bringing-claude-mythos-5-to-more-defenders
我们分享一项进展:我们正努力帮助更多团队将前沿能力用于网络防御。Claude Mythos 5现已在Claude Security中可用,并将很快登陆合作伙伴的网络防御工具。我们还启动了一项 3500 万美元的基金,用于帮助保护开源软件,并分享了扩大我们Cyber Verification Program的计划。
今年 4 月,我们启动了 Project Glasswing,将我们能力最强的前沿模型 Claude Mythos Preview(及其后继版本 Claude Mythos 5)交到一小批组织手中,用于保护全球最关键的软件。这为防御方争取到了一段窗口期,使其能够在具备类似能力的模型广泛可用或落入恶意行为者之手前,发现并修复漏洞。
我们的目标始终是在安全允许的范围内,将 Mythos 级别的防御能力扩展到尽可能多的防御者手中。为此,我们一直在研发安全分类器和防护措施,使我们能够扩大对 Mythos 级模型的访问权限,同时确保其攻击性网络能力不会落入不法之手。Claude Fable 5是第一步:它让该模型得以广泛可用,同时阻止了军民两用性质的网络工作。
今天,我们迈出了下一步。风险最高的行为发生在用户可以直接访问模型时,此时恶意行为者可能试图将其引导至有害用途。但如果用户只能接收特定输出,例如某个漏洞的补丁或一条安全警报,那么风险就会低得多。我们宣布的这些变更,让用户能够更多地获取防御性成果,同时围绕对模型的直接访问维持适当的防护措施:
- 将 Claude Mythos 5 集成到防御者所依赖的工具中。我们正与网络安全技术和服务合作伙伴携手,将 Claude Mythos 5 集成到防御者已在使用、用于保护其软件的产品和服务中。
- Claude Security 扫描现可在 Claude Mythos 5 上运行。使用 Claude Enterprise 套餐的客户现在可以在 Claude Security 中运行我们能力最强的模型,用它扫描其代码库中的安全漏洞并给出补丁建议。
- 为开源安全提供 3500 万美元额度。我们新设立的 Defender Advantage Fund(0xDAF)将提供 3500 万美元额度,用于支持那些致力于修补开源项目漏洞、自动化部分开源软件扫描与修补流程,以及试验全新安全方法的组织。
- 扩展我们的 Cyber Verification Program。该计划已为经过审核的防御者在 Opus 和 Sonnet 模型上提供降低的防护限制。未来几周内,我们将扩展该计划,把 Opus 和 Sonnet 上更广泛的双用途能力纳入其中,随后还将提供 Mythos 级别的访问权限。
我们的目标始终是帮助各类组织适应网络安全的发展节奏与需求,尤其是在 AI 模型日益强大的背景下。我们将继续开发防护措施、准入项目与社区支持,让我们最强大的模型能够安全地提供给广泛的个人与组织使用。
将 Mythos 集成到现有的网络防御工具中
守护医院、公用事业、金融系统和软件供应链的团队,早已依赖一整套产品与服务来开展安全运营、事件响应、威胁情报和检测工程。要让这些防御者最快用上前沿能力,就是把 Mythos 级模型集成到他们已经在使用的工具中。
我们的许多合作伙伴已经基于 Claude Opus 构建了网络安全产品,帮助安全团队更快地分诊告警、识别威胁并修复漏洞。我们目前正与这些合作伙伴及更多伙伴合作,将 Claude Mythos 5 构建进他们的产品与服务中,使他们能够为客户交付 Mythos 级别的防御成效。
当最终用户使用这些产品时,他们并不是直接与 Mythos 交互。相反,他们通过一个专门构建的界面来操作,该界面在后台运行 Mythos 以完成特定任务,用户只会收到该产品预期提供的特定产物。例如,一个用于修复漏洞的工具可能会输出一份建议补丁列表。这份输出由 Mythos 生成,但用户无法通过提示词让模型去做诸如为某个漏洞开发利用程序之类的事情。我们和我们的合作伙伴还部署了滥用防范措施,以确保模型始终在其预期范围内运行。
我们在这项工作上还处于早期阶段,预计它会随着时间推移而扩展。如果你在构建安全产品或服务,并希望将 Claude Mythos 5 带给你的客户,可以在此登记你的意向。
面向企业客户,通过 Claude Mythos 5 提供 Claude Security
从今天起,Claude Security扫描现已运行在 Claude Mythos 5 上。Claude Security 会扫描代码库中的漏洞,并给出补丁建议供人工审查;它目前面向 Claude Enterprise 客户处于公开测试阶段,使用 Mythos 5 的扫描按你现有方案的标准 token 用量计费,无需单独加购。
企业管理员可以在管理控制台中启用 Claude Security。用户可以从claude.ai/security选择一个代码仓库,使用 Claude Mythos 5 进行扫描。随后 Claude 会扫描代码库中的漏洞,并针对每一项发现返回一个CWE(通用缺陷枚举)类别、置信度和严重性评级,以及建议的修复方案。
随后,用户可以在网页端打开 Claude Code 来实施修复。交互式打补丁使用的是你所在组织在 Claude Code 中可访问的模型。Mythos 扫描本身并不会将 Mythos 的访问权限扩展到其他界面。每一个补丁在实施之前都必须经过人工审查和批准。
Claude Security 使用 Mythos 5 扫描你拥有的代码,并返回详细的发现结果,而非原始输出,同时不会暴露模型本身。这意味着防御方可以获取 Claude Mythos 5 的能力,而模型本身不会变得对可能滥用它的人可访问。
如需进一步了解 Claude Security,请参阅我们的入门指南。
推出 Defender Advantage Fund,以保障开源软件安全
世界上一些使用最广泛的程序运行在开源软件之上。然而,这些项目往往由志愿者或非营利基金会维护,他们可能缺乏资源或人员来全面抵御针对其项目的攻击。通过 Project Glasswing,我们向开源安全组织直接捐赠了 400 万美元,为参与该计划的开源安全基金会提供了额度,帮助扫描并修补广泛使用的项目,并支持像 Akrites 和 Gold Eagle 这样的协同漏洞修复工作。
我们新设立的 Defender Advantage Fund(0xDAF)在此基础上更进一步,为那些帮助开源维护者保障其软件安全的组织提供 3500 万美元的 Claude 额度。资助将聚焦三个领域:修补广泛使用项目中的活跃漏洞;以其他项目可复制的方式实现扫描与修补自动化;以及帮助项目采用更雄心勃勃的安全方案,使其能够抵御整类攻击。
我们将从少量规模较大的试点资助开始,以了解哪些做法最有效、最具可扩展性。我们将在未来几周内分享首批受资助方的详细信息。
扩展我们的 Cyber Verification Program
迄今为止,我们的 Cyber Verification Program 已为各组织在使用 Claude Opus 和 Sonnet 模型时提供了获取两用能力的途径。参与该计划的组织会经历更少的防护限制,从而最大程度减少对获准团队在其被授权保护的系统上开展合法网络安全工作的干扰。
在接下来的几周里,我们将对该计划进行演进,以扩大对 Claude Mythos 的受保障访问权限。作为其中的一部分,漏洞分类与验证等防御性能力的访问权限将扩展至 Mythos 级模型,而网络防御人员将看到 Claude Opus 和 Sonnet 级模型上的拦截减少。
此外,我们将继续通过与我们在美国政府中的合作伙伴协作的 Project Glasswing 扩大对 Claude Mythos 的访问,重点关注符合严格安全控制要求的至关重要基础设施的保护者。
我们将在未来几周内分享有关 Cyber Verification Program 扩展的更多细节。与此同时,我们鼓励所有从事合法网络安全工作的安全团队申请该计划,以获得对 Claude Opus 和 Sonnet 模型减少的防护限制。如果您已经注册并获批,则无需采取任何行动;我们会主动联系并提供更新。
下一步
这些举措是我们持续努力的一部分,旨在让更多人和组织能够使用前沿模型的防御能力,并支持开源社区加固其项目以抵御攻击。我们将继续与政府合作伙伴、各类组织、开源维护者以及更广泛的行业合作,共同构建当今高度强大的 AI 模型所要求的具有韧性的网络基础设施。
- 申请 Cyber Verification Program。
- 登记您的意向,使用 Mythos 构建网络产品与服务。
- Claude Security 现面向 Enterprise 客户开放公开测试版。管理员可以在 管理控制台中启用 Claude Security。如需完整操作演示,请参阅我们的入门指南。
Category [Product announcements](https://claude.com/blog/category/announcements)Product No items found.Date August 21, 2026Reading time 6 minShare [Copy link](https://claude.com/blog/bringing-claude-mythos-5-to-more-defenders#)https://claude.com/blog/bringing-claude-mythos-5-to-more-defenders
We're sharing an update on our efforts to help more teams use frontier capabilities for cyber defense.Claude Mythos 5is now available inClaude Security, and coming soon to partners' cyber defense tools. We're also launching a $35M fund to help secure open-source software and sharing plans to expand ourCyber Verification Program.
In April, we launched Project Glasswing to put our most capable frontier model, Claude Mythos Preview (and its successor, Claude Mythos 5), in the hands of a small group of organizations securing the world’s most critical software. This gave defenders a window of time to find and fix vulnerabilities ahead of models with similar capabilities becoming generally available or reaching malicious actors.
Our goal has always been to expand Mythos-level defense to as many defenders as we safely can. To do that, we've been working on safety classifiers and safeguards that let us expand access to Mythos-class models without putting their offensive cyber capabilities in the wrong hands. Claude Fable 5 was the first step: it made the model broadly available while blocking dual-use cyber work.
Today, we’re taking the next steps. The riskiest behavior occurs when a user has direct access to a model, where a malicious actor can try to steer it toward harmful uses. But if users can only receive specific outputs, such as a patch for a vulnerability or a security alert, that risk is much lower. The changes we’re announcing give users greater access to the defensive results, while maintaining appropriate guardrails around direct access to the model:
- Claude Mythos 5 integration into the tools defenders rely on. We’re working with our cybersecurity technology and services partners to integrate Claude Mythos 5 into the products and services defenders already use to secure their software.
- Claude Security scans can now run on Claude Mythos 5. Customers on Claude Enterprise plans can now run our most capable model in Claude Security, using it to scan their codebases for security vulnerabilities and suggest patches.
- $35 million in credits for open-source security. Our new Defender Advantage Fund (0xDAF) will provide $35 million in credits to organizations working to patch vulnerabilities in open-source projects, automate parts of the process of scanning and patching open-source software, and experiment with new security approaches.
- Expanding our Cyber Verification Program. The program already gives vetted defenders reduced safeguards on Opus and Sonnet models. In the coming weeks, we will expand this program to include broader dual-use capabilities on Opus and Sonnet, with Mythos-class access to follow.
Our aim remains to help organizations adapt to the pace and demands of cybersecurity as AI models become increasingly powerful. We will continue to develop safeguards, access programs, and community support to make our most capable models safely available to a wide range of people and organizations.
Integrating Mythos into existing cyberdefensive tools
The teams defending hospitals, utilities, financial systems, and the software supply chain already rely on a suite of products and services for security operations, incident response, threat intelligence, and detection engineering. The fastest way to make frontier capabilities available to those defenders is to integrate Mythos-class models into the tools they already run.
Many of our partners have already built cyber products on Claude Opus that help security teams triage alerts, identify threats, and remediate vulnerabilities faster. We’re now working with these partners and more to build Claude Mythos 5 into their products and services, so they can deliver Mythos-level defensive outcomes to their customers.
When an end user uses one of these products, they’re not interacting with Mythos directly. Instead, they work through a purpose-built interface that runs Mythos in the background for a defined task and only receive the specific artifact the product is intended to provide. For example, a tool to remediate vulnerabilities might provide a list of suggested patches as its output. This output would be generated by Mythos, but the user would not have a way to prompt the model to, say, develop an exploit for a vulnerability. We and our partners also have abuse prevention measures in place to verify the model stays within its intended scope.
We're early in this work and expect it to expand over time. If you build security products or services and want to bring Claude Mythos 5 to your customers, you can register your interest here.
Making Claude Security available with Claude Mythos 5 for Enterprise customers
Starting today, Claude Security scans now run on Claude Mythos 5. Claude Security scans codebases for vulnerabilities and suggests patches for human review; it’s currently in public beta for Claude Enterprise customers, and scans with Mythos 5 are billed as standard token usage under your existing plan, with no separate add-on.
Enterprise admins can enable Claude Security in the admin console. From claude.ai/security, users can select a repository to scan using Claude Mythos 5. Claude then scans the codebase for vulnerabilities, and returns each finding with a CWE (Common Weakness Enumeration) category, confidence and severity ratings, and a suggested fix.
Users can then open Claude Code on the web to implement the fix. Interactive patching uses the models your organization has access to in Claude Code. The Mythos scan itself does not extend Mythos access to other surfaces. Every patch must be reviewed and approved by a human before it can be implemented.
Claude Security uses Mythos 5 to scan code you own, and returns detailed findings rather than raw outputs without exposing the model itself. This means defenders can access the capabilities of Claude Mythos 5 without the model becoming accessible to those who might misuse it.
For more about Claude Security, see our guide to getting started.
Launching the Defender Advantage Fund to secure open-source software
Some of the world’s most widely used programs run on open-source software. Yet these projects are often maintained by volunteers or nonprofit foundations, who may lack the resources or personnel to comprehensively defend their projects against attack. Through Project Glasswing, we made $4M in direct donations to open-source security organizations, provided credits to the open-source security foundations in the program, helped scan and patch widely used projects, and support coordinated vulnerability-fixing efforts like Akrites and Gold Eagle.
Our new Defender Advantage Fund (0xDAF) builds on that work with $35 million in Claude credits for organizations helping open-source maintainers secure their software. Grants will focus on three areas: patching live vulnerabilities in widely used projects, automating scanning and patching in ways other projects can replicate, and helping projects pursue more ambitious security approaches that make them resistant to whole classes of attack.
We're starting with a small number of larger, pilot grants to learn what works and scales best. We will share details on initial recipients in the coming weeks.
Expanding our Cyber Verification Program
To date, our Cyber Verification Program has provided organizations with access to dual-use capabilities when using Claude Opus and Sonnet models. Organizations in the program experience reduced safeguards, minimizing interruptions for accepted teams doing legitimate cybersecurity work on systems they’re authorized to protect.
Over the coming weeks, we are evolving the program to expand safeguarded access to Claude Mythos. As part of this, access to defensive capabilities like vulnerability triaging and validation will expand to Mythos-class models, and cyber defenders will see reduced blocks on Claude Opus and Sonnet-class models. Additionally, we are continuing to expand access to Claude Mythos through Project Glasswing in collaboration with our partners in the U.S. Government, focused on protectors of critically important infrastructure that meet strict security control requirements.
We'll share more details about the Cyber Verification Program expansion in the coming weeks. In the meantime, we encourage all security teams performing legitimate cybersecurity work to apply for the program for reduced safeguards on Claude Opus and Sonnet models. If you are already enrolled and accepted, no action is needed; we’ll reach out with updates.
What’s next
These initiatives are a continuation of our efforts to make the defensive capabilities of frontier models available to more people and organizations, and to support the open-source community in hardening their projects against attack. We will continue to work with government partners, organizations, open-source maintainers, and the broader industry to build the resilient cyber infrastructure today’s highly capable AI models demand.
- Apply for the Cyber Verification Program.
- Register your interest in building cyber products and offerings with Mythos.
- Claude Security is available in public beta for Enterprise customers. Admins can enable Claude Security in the admin console. For a full walkthrough, see our guide to getting started.