Anthropic Broadens AI-Powered Cyber Defense Access and Funds Open Source Security
Anthropic is significantly expanding access to its advanced artificial intelligence (AI) models for cybersecurity defense, aiming to proactively identify and mitigate vulnerabilities across critical sectors. These initiatives, building on the previously launched Project Glasswing, include wider availability of Mythos 5 capabilities, an enhanced Claude Security offering, and the establishment of a $35 million Defender Advantage Fund dedicated to bolstering open-source project security. This strategic move emphasizes controlled access to powerful AI, ensuring defensive applications without enabling misuse by malicious actors, as highlighted by SecurityWeek.
Expanding Anthropic Mythos 5 Security Capabilities
Anthropic’s core strategy revolves around providing defensive outputs from its Mythos-class models rather than direct, unrestricted access, which the company identifies as the riskiest scenario. Following the initial limited access provided through Project Glasswing, the successor, Mythos 5, is now being integrated into existing cybersecurity tools through partnerships. These integrations are designed to support security operations, incident response, and detection in critical sectors such as healthcare, utilities, financial systems, and the software supply chain. End-users will interact with purpose-built interfaces that leverage Mythos 5 in the background, receiving defined outputs like suggested patches while preventing direct model interaction and potential abuse.
The companion model, Claude Fable 5, maintains a broader public availability while specifically blocking dual-use cyber work, ensuring its application remains purely defensive. This dual-model approach aims to strike a balance between empowering defenders and maintaining responsible AI deployment.
Enhanced Claude Security Code Scanning
The Claude Security offering, currently in public beta for Claude Enterprise customers, has been upgraded to run its codebase scans on Mythos 5. This enhancement provides organizations with detailed findings from their proprietary code scans, surfacing each vulnerability with a Common Weakness Enumeration (CWE) category, confidence ratings, and severity assessments. Crucially, Claude Security also suggests fixes. However, any proposed fix must still be implemented via Claude Code and undergo human review and approval before deployment, ensuring a critical layer of human oversight. This approach allows defenders to leverage the capabilities of Claude Mythos 5 for code analysis without direct exposure to the model itself, mitigating misuse risks.
Defender Advantage Fund for Open Source Security
In a significant commitment to broader cybersecurity resilience, Anthropic has launched the Defender Advantage Fund (0xDAF), allocating $35 million in Claude credits. This fund is directed towards organizations that assist open-source maintainers in securing their projects. The grants will support efforts such as patching live vulnerabilities, developing reusable scanning and patching processes, and pursuing security approaches designed to resist entire classes of attacks. This initiative builds on previous support, including $4 million in direct donations, provided through Project Glasswing and collaborative efforts like Akrites and Gold Eagle. Anthropic is initially rolling out a small number of larger pilot grants.
Expanding the Cyber Verification Program
Anthropic is also expanding its Cyber Verification Program. This program currently offers vetted organizations reduced safeguards on Claude Opus and Sonnet for authorized security work. In the coming weeks, the program will broaden its scope to cover dual-use capabilities on these models, including vulnerability triaging and validation. Mythos-class access is slated to follow. Furthermore, Project Glasswing continues to expand Mythos access in collaboration with US government partners, focusing on organizations protecting critical infrastructure that adhere to stringent security control requirements. Security teams are encouraged to apply to the Cyber Verification Program for reduced safeguards on Opus and Sonnet, with further details on the broader rollout anticipated shortly.
Actionable Recommendations for Defenders
Security professionals should consider the following actions to leverage these new Anthropic initiatives:
- Explore Integrations: Organizations using security operations, incident response, or detection tools should investigate whether their vendors are integrating with Anthropic’s Mythos 5 capabilities.
- Apply to Cyber Verification Program: Teams engaged in authorized security work, particularly those protecting critical infrastructure, are encouraged to apply to Anthropic’s Cyber Verification Program for access to reduced safeguards on Claude Opus and Sonnet, with future Mythos-class access.
- Leverage Claude Security: Claude Enterprise customers can utilize the public beta of Claude Security for enhanced code scanning, focusing on suggested fixes and maintaining human review for deployment.
- Support Open Source Initiatives: Organizations involved in securing open-source projects can look into the Defender Advantage Fund for potential Claude credits to bolster their efforts.
These expansions by Anthropic represent a significant effort to shift the balance in favor of defenders by making advanced AI capabilities more accessible for proactive security measures, particularly in safeguarding critical infrastructure and the open-source ecosystem.
Related: Anthropic’s Claude Cowork Mobile: Enterprise Security Implications, LLMs Achieve Novel Cryptanalysis: Implications for Digital Security