Summary
On August 21, 2026, Anthropic began running its restricted cyber-capable model, Claude Mythos 5, inside Claude Security for Enterprise customers. The feature scans customer codebases connected via GitHub, traces data flows, and returns CWE-categorized findings with confidence and severity ratings plus suggested patches, delivering defensive output without granting users direct access to the model.
What changed
Claude Mythos 5, limited to vetted defenders since April 2026, now powers vulnerability scanning in Claude Security (public beta for Claude Enterprise). Scans connect to a GitHub repo, trace cross-file data flows, and produce CWE-tagged findings with severity and confidence plus suggested remediation patches, with no separate model add-on. Anthropic also committed $35M in credits to an open-source defense fund and outlined plans to embed Mythos 5 in partner security products.
Why it matters
It operationalizes a frontier cyber model as a governed defensive product, findings and patches without raw model access, a template for shipping dual-use capabilities safely. For enterprises it folds AI-driven code security into the Claude subscription, pressuring standalone SAST and AI-security vendors.
Evidence excerpt
Claude Mythos 5 "is now running vulnerability scans in Claude Security for Enterprise customers"; scans connect to a GitHub repo, "traces data flows across files," and return findings categorized by CWE with confidence and severity ratings and suggested patches, plus a $35M open-source defense fund.