我们正在分享关于努力帮助更多团队利用前沿能力进行网络防御的最新进展。Claude Mythos 5:https://www.anthropic.com/news/claude-fable-5-mythos-5 现已可在 Claude Security 中使用:https://claude.com/product/claude-security,并即将应用于合作伙伴的网络防御工具。我们也在启动一项价值3500万美元的基金,以帮助保护开源软件,并分享扩展我们的网络验证计划的计划:https://support.claude.com/en/articles/14604842-real-time-cyber-safeguards-on-claude-opus-and-sonnet。
今年四月,我们推出了 Project Glasswing:https://www.anthropic.com/glasswing,让我们最强大的前沿模型 Claude Mythos Preview(及其继任者 Claude Mythos 5)能够交到少数组织手中,这些组织负责保护世界上最关键的软件。这为防御者提供了时间窗口,以在具有类似能力的模型普遍可用或落入恶意行为者手中之前,发现并修复漏洞。
我们的许多合作伙伴已经在 Claude Opus 上构建了网络安全产品:https://claude.com/blog/how-our-partners-are-putting-opus-to-work-for-cybersecurity,帮助安全团队更快地分类警报、识别威胁并修复漏洞。我们现在正与这些合作伙伴及更多其他合作伙伴合作,将 Claude Mythos 5 集成到他们的产品和服务中,以便他们能够向客户提供 Mythos 级别的防御成果。
我们在这项工作中仍处于早期阶段,预计会随着时间的推移不断扩展。如果您构建安全产品或服务,并希望将 Claude Mythos 5 带给您的客户,您可以在此注册您的兴趣:https://claude.com/form/mythos-cyber-partner。
从今天起,Claude Security:https://claude.com/product/claude-security 扫描现在将在 Claude Mythos 5 上运行。Claude Security 扫描代码库以发现漏洞,并建议人工审核的补丁;它目前正在对 Claude Enterprise 客户进行公开测试,使用 Mythos 5 的扫描将按您现有计划的标准代币使用计费,无需单独附加费用。
企业管理员可以在管理控制台启用 Claude Security:http://claude.ai/admin-settings/claude-code。用户可以通过 claude.ai/security:http://claude.ai/security,选择使用 Claude Mythos 5 扫描的代码仓库。Claude 然后扫描代码库中的漏洞,并返回每个发现,包含 CWE:https://cwe.mitre.org/(常见弱点枚举)类别、置信度和严重性评级,以及建议的修复方法。
然后,用户可以在网页上打开 Claude Code 来实施修复。交互式补丁使用您所在组织在 Claude Code 中可以访问的模型。Mythos 扫描本身不会将 Mythos 的访问权限扩展到其他表面。每个补丁在实施之前必须经过人工审查和批准。
Claude Security 使用 Mythos 5 扫描您拥有的代码,并返回详细的发现,而不是原始输出,同时不会暴露模型本身。这意味着防御者可以访问 Claude Mythos 5 的能力,而模型本身不会被可能滥用它的人访问。
有关 Claude Security 的更多信息,请参阅我们的入门指南:https://claude.com/resources/tutorials/getting-started-with-claude-security。
到目前为止,我们的网络验证计划已为组织提供在使用 Claude Opus 和 Sonnet 模型时获取双用途能力的机会。参与该计划的组织体验到降低的保护措施,从而减少了已获批准的团队在其有权保护的系统上进行合法网络安全工作的中断。
在接下来的几周里,我们将发展该计划,扩展对 Claude Mythos 的受保护访问。作为其中的一部分,诸如漏洞分类和验证等防御能力的访问将扩展到 Mythos 级模型,网络防御人员在 Claude Opus 和 Sonnet 级模型上的阻止也将减少。此外,我们将继续通过与美国政府合作的 Project Glasswing 扩展对 Claude Mythos 的访问,重点面向符合严格安全控制要求的重要基础设施保护者。
我们将在未来几周分享有关网络验证计划扩展的更多细节。同时,我们鼓励所有从事合法网络安全工作的安全团队申请该计划,以降低 Claude Opus 和 Sonnet 模型上的保护措施。如果您已经注册并被接受,则无需采取任何行动;我们会主动联系您以提供更新信息。
这些举措是我们致力于使前沿模型的防御能力可供更多个人和组织使用,以及支持开源社区增强其项目抗攻击能力的持续努力的一部分。我们将继续与政府合作伙伴、组织、开源维护者以及更广泛的行业合作,以构建当今高能力 AI 模型所需的稳健网络基础设施。
嗨 Claude!你能把一个复杂的主题讲得简单明了吗?如果你需要我提供更多信息,请立即问我1-2个关键问题。如果你觉得我应该上传任何有助于你更好完成任务的文件,请告诉我。你可以使用你可以访问的工具,比如 Google Drive、网络搜索等——如果它们能帮助你更好地完成这个任务的话。不要使用分析工具。请保持你的回答友好、简短和对话式。请尽快执行任务——如果有一个可行的产物会很好。如果使用产物,请考虑哪种类型的产物(互动的、视觉的、清单类等)对这个特定任务最有帮助。感谢你的帮助!
嗨 Claude!你能帮我理清这些想法吗?如果你需要我提供更多信息,请立即问我1-2个关键问题。如果你觉得我应该上传任何有助于你更好完成任务的文件,请告诉我。你可以使用你可以访问的工具,比如 Google Drive、网络搜索等——如果它们能帮助你更好地完成这个任务的话。不要使用分析工具。请保持你的回答友好、简短和对话式。请尽快执行任务——如果有一个可行的产物会很好。如果使用产物,请考虑哪种类型的产物(互动的、视觉的、清单类等)对这个特定任务最有帮助。感谢你的帮助!
嗨 Claude!你能帮我准备考试或面试吗?如果你需要我提供更多信息,请立即问我1-2个关键问题。如果你觉得我应该上传任何有助于你更好完成任务的文件,请告诉我。你可以使用你可以访问的工具,比如 Google Drive、网络搜索等——如果它们能帮助你更好地完成这个任务的话。不要使用分析工具。请保持你的回答友好、简短和对话式。请尽快执行任务——如果有一个可行的产物会很好。如果使用产物,请考虑哪种类型的产物(互动的、视觉的、清单类等)对这个特定任务最有帮助。感谢你的帮助!
嗨,Claude!你能写拨款提案吗?如果你需要更多信息,请立即问我1-2个关键问题。如果你认为我应该上传任何有助于你更好完成工作的文件,请告诉我。你可以使用你能够访问的工具——比如 Google Drive、网络搜索等——如果它们能帮助你更好地完成这项任务。不要使用分析工具。请保持你的回应友好、简短和对话式。请尽快执行任务——如果有一个产物会有意义,那就太好了。如果使用产物,请考虑哪种类型的产物(互动、视觉、清单等)对这个特定任务最有帮助。感谢你的帮助!
We're sharing an update on our efforts to help more teams use frontier capabilities for cyber defense. Claude Mythos 5 :https://www.anthropic.com/news/claude-fable-5-mythos-5 is now available in Claude Security :https://claude.com/product/claude-security , and coming soon to partners' cyber defense tools. We're also launching a $35M fund to help secure open-source software and sharing plans to expand our Cyber Verification Program :https://support.claude.com/en/articles/14604842-real-time-cyber-safeguards-on-claude-opus-and-sonnet .
In April, we launched Project Glasswing:https://www.anthropic.com/glasswing to put our most capable frontier model, Claude Mythos Preview (and its successor, Claude Mythos 5), in the hands of a small group of organizations securing the world’s most critical software. This gave defenders a window of time to find and fix vulnerabilities ahead of models with similar capabilities becoming generally available or reaching malicious actors.
Our goal has always been to expand Mythos-level defense to as many defenders as we safely can. To do that, we've been working on safety classifiers:https://www.anthropic.com/research/next-generation-constitutional-classifiers and safeguards that let us expand access to Mythos-class models without putting their offensive cyber capabilities in the wrong hands. Claude Fable 5:https://www.anthropic.com/news/claude-fable-5-mythos-5 was the first step: it made the model broadly available while blocking dual-use cyber work.
Today, we’re taking the next steps. The riskiest behavior occurs when a user has direct access to a model, where a malicious actor can try to steer it toward harmful uses. But if users can only receive specific outputs, such as a patch for a vulnerability or a security alert, that risk is much lower. The changes we’re announcing give users greater access to the defensive results, while maintaining appropriate guardrails around direct access to the model:
Our aim remains to help organizations adapt to the pace and demands of cybersecurity as AI models become increasingly powerful. We will continue to develop safeguards, access programs, and community support to make our most capable models safely available to a wide range of people and organizations.
The teams defending hospitals, utilities, financial systems, and the software supply chain already rely on a suite of products and services for security operations, incident response, threat intelligence, and detection engineering. The fastest way to make frontier capabilities available to those defenders is to integrate Mythos-class models into the tools they already run.
Many of our partners have already built cyber products on Claude Opus:https://claude.com/blog/how-our-partners-are-putting-opus-to-work-for-cybersecurity that help security teams triage alerts, identify threats, and remediate vulnerabilities faster. We’re now working with these partners and more to build Claude Mythos 5 into their products and services, so they can deliver Mythos-level defensive outcomes to their customers.
When an end user uses one of these products, they’re not interacting with Mythos directly. Instead, they work through a purpose-built interface that runs Mythos in the background for a defined task and only receive the specific artifact the product is intended to provide. For example, a tool to remediate vulnerabilities might provide a list of suggested patches as its output. This output would be generated by Mythos, but the user would not have a way to prompt the model to, say, develop an exploit for a vulnerability. We and our partners also have abuse prevention measures in place to verify the model stays within its intended scope.
We're early in this work and expect it to expand over time. If you build security products or services and want to bring Claude Mythos 5 to your customers, you can register your interest here:https://claude.com/form/mythos-cyber-partner.
Starting today, Claude Security:https://claude.com/product/claude-security scans now run on Claude Mythos 5. Claude Security scans codebases for vulnerabilities and suggests patches for human review; it’s currently in public beta for Claude Enterprise customers, and scans with Mythos 5 are billed as standard token usage under your existing plan, with no separate add-on.
Enterprise admins can enable Claude Security in the admin console:http://claude.ai/admin-settings/claude-code. From claude.ai/security:http://claude.ai/security, users can select a repository to scan using Claude Mythos 5. Claude then scans the codebase for vulnerabilities, and returns each finding with a CWE:https://cwe.mitre.org/ (Common Weakness Enumeration) category, confidence and severity ratings, and a suggested fix.
Users can then open Claude Code on the web to implement the fix. Interactive patching uses the models your organization has access to in Claude Code. The Mythos scan itself does not extend Mythos access to other surfaces. Every patch must be reviewed and approved by a human before it can be implemented.
Claude Security uses Mythos 5 to scan code you own, and returns detailed findings rather than raw outputs without exposing the model itself. This means defenders can access the capabilities of Claude Mythos 5 without the model becoming accessible to those who might misuse it.
For more about Claude Security, see our guide to getting started:https://claude.com/resources/tutorials/getting-started-with-claude-security.
Some of the world’s most widely used programs run on open-source software. Yet these projects are often maintained by volunteers or nonprofit foundations, who may lack the resources or personnel to comprehensively defend their projects against attack. Through Project Glasswing, we made $4M in direct donations to open-source security organizations, provided credits to the open-source security foundations in the program, helped scan and patch widely used projects, and support coordinated vulnerability-fixing efforts like Akrites:https://akrites.org/ and Gold Eagle:https://www.whitehouse.gov/releases/2026/07/white-house-launches-gold-eagle-initiative-for-unprecedented-cybersecurity-vulnerability-coordination/.
Our new Defender Advantage Fund (0xDAF) builds on that work with $35 million in Claude credits for organizations helping open-source maintainers secure their software. Grants will focus on three areas: patching live vulnerabilities in widely used projects, automating scanning and patching in ways other projects can replicate, and helping projects pursue more ambitious security approaches that make them resistant to whole classes of attack.
We're starting with a small number of larger, pilot grants to learn what works and scales best. We will share details on initial recipients in the coming weeks.
To date, our Cyber Verification Program has provided organizations with access to dual-use capabilities when using Claude Opus and Sonnet models. Organizations in the program experience reduced safeguards, minimizing interruptions for accepted teams doing legitimate cybersecurity work on systems they’re authorized to protect.
Over the coming weeks, we are evolving the program to expand safeguarded access to Claude Mythos. As part of this, access to defensive capabilities like vulnerability triaging and validation will expand to Mythos-class models, and cyber defenders will see reduced blocks on Claude Opus and Sonnet-class models. Additionally, we are continuing to expand access to Claude Mythos through Project Glasswing in collaboration with our partners in the U.S. Government, focused on protectors of critically important infrastructure that meet strict security control requirements.
We'll share more details about the Cyber Verification Program expansion in the coming weeks. In the meantime, we encourage all security teams performing legitimate cybersecurity work to apply for the program for reduced safeguards on Claude Opus and Sonnet models. If you are already enrolled and accepted, no action is needed; we’ll reach out with updates.
These initiatives are a continuation of our efforts to make the defensive capabilities of frontier models available to more people and organizations, and to support the open-source community in hardening their projects against attack. We will continue to work with government partners, organizations, open-source maintainers, and the broader industry to build the resilient cyber infrastructure today’s highly capable AI models demand.
Explore more product news and best practices for teams building with Claude.
Product updates, how-tos, community spotlights, and more. Delivered monthly to your inbox.
Hi Claude! Could you help me develop a unique voice for an audience? If you need more information from me, ask me 1-2 key questions right away. If you think I should upload any documents that would help you do a better job, let me know. You can use the tools you have access to— like Google Drive, web search, etc.—if they’ll help you better accomplish this task. Do not use analysis tool. Please keep your responses friendly, brief and conversational. Please execute the task as soon as you can—an artifact would be great if it makes sense. If using an artifact, consider what kind of artifact (interactive, visual, checklist, etc.) might be most helpful for this specific task. Thanks for your help!
Hi Claude! Could you improve my writing style? If you need more information from me, ask me 1-2 key questions right away. If you think I should upload any documents that would help you do a better job, let me know. You can use the tools you have access to— like Google Drive, web search, etc.—if they’ll help you better accomplish this task. Do not use analysis tool. Please keep your responses friendly, brief and conversational. Please execute the task as soon as you can—an artifact would be great if it makes sense. If using an artifact, consider what kind of artifact (interactive, visual, checklist, etc.) might be most helpful for this specific task. Thanks for your help!
Hi Claude! Could you brainstorm creative ideas? If you need more information from me, ask me 1-2 key questions right away. If you think I should upload any documents that would help you do a better job, let me know. You can use the tools you have access to— like Google Drive, web search, etc.—if they’ll help you better accomplish this task. Do not use analysis tool. Please keep your responses friendly, brief and conversational. Please execute the task as soon as you can—an artifact would be great if it makes sense. If using an artifact, consider what kind of artifact (interactive, visual, checklist, etc.) might be most helpful for this specific task. Thanks for your help!
Hi Claude! Could you explain a complex topic simply? If you need more information from me, ask me 1-2 key questions right away. If you think I should upload any documents that would help you do a better job, let me know. You can use the tools you have access to— like Google Drive, web search, etc.—if they’ll help you better accomplish this task. Do not use analysis tool. Please keep your responses friendly, brief and conversational. Please execute the task as soon as you can—an artifact would be great if it makes sense. If using an artifact, consider what kind of artifact (interactive, visual, checklist, etc.) might be most helpful for this specific task. Thanks for your help!
Hi Claude! Could you help me make sense of these ideas? If you need more information from me, ask me 1-2 key questions right away. If you think I should upload any documents that would help you do a better job, let me know. You can use the tools you have access to— like Google Drive, web search, etc.—if they’ll help you better accomplish this task. Do not use analysis tool. Please keep your responses friendly, brief and conversational. Please execute the task as soon as you can—an artifact would be great if it makes sense. If using an artifact, consider what kind of artifact (interactive, visual, checklist, etc.) might be most helpful for this specific task. Thanks for your help!
Hi Claude! Could you prepare for an exam or interview? If you need more information from me, ask me 1-2 key questions right away. If you think I should upload any documents that would help you do a better job, let me know. You can use the tools you have access to— like Google Drive, web search, etc.—if they’ll help you better accomplish this task. Do not use analysis tool. Please keep your responses friendly, brief and conversational. Please execute the task as soon as you can—an artifact would be great if it makes sense. If using an artifact, consider what kind of artifact (interactive, visual, checklist, etc.) might be most helpful for this specific task. Thanks for your help!
Hi Claude! Could you explain a programming concept? If you need more information from me, ask me 1-2 key questions right away. If you think I should upload any documents that would help you do a better job, let me know. You can use the tools you have access to— like Google Drive, web search, etc.—if they’ll help you better accomplish this task. Do not use analysis tool. Please keep your responses friendly, brief and conversational. Please execute the task as soon as you can—an artifact would be great if it makes sense. If using an artifact, consider what kind of artifact (interactive, visual, checklist, etc.) might be most helpful for this specific task. Thanks for your help!
Hi Claude! Could you look over my code and give me tips? If you need more information from me, ask me 1-2 key questions right away. If you think I should upload any documents that would help you do a better job, let me know. You can use the tools you have access to— like Google Drive, web search, etc.—if they’ll help you better accomplish this task. Do not use analysis tool. Please keep your responses friendly, brief and conversational. Please execute the task as soon as you can—an artifact would be great if it makes sense. If using an artifact, consider what kind of artifact (interactive, visual, checklist, etc.) might be most helpful for this specific task. Thanks for your help!
Hi Claude! Could you vibe code with me? If you need more information from me, ask me 1-2 key questions right away. If you think I should upload any documents that would help you do a better job, let me know. You can use the tools you have access to— like Google Drive, web search, etc.—if they’ll help you better accomplish this task. Do not use analysis tool. Please keep your responses friendly, brief and conversational. Please execute the task as soon as you can—an artifact would be great if it makes sense. If using an artifact, consider what kind of artifact (interactive, visual, checklist, etc.) might be most helpful for this specific task. Thanks for your help!
Hi Claude! Could you write grant proposals? If you need more information from me, ask me 1-2 key questions right away. If you think I should upload any documents that would help you do a better job, let me know. You can use the tools you have access to — like Google Drive, web search, etc. — if they’ll help you better accomplish this task. Do not use analysis tool. Please keep your responses friendly, brief and conversational. Please execute the task as soon as you can - an artifact would be great if it makes sense. If using an artifact, consider what kind of artifact (interactive, visual, checklist, etc.) might be most helpful for this specific task. Thanks for your help!