AI Security AI安全 2h ago Updated 1h ago 更新于 1小时前 46

Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund Anthropic扩大Mythos 5防御者访问权限,推出3500万美元开源基金

Anthropic is expanding access to its advanced cybersecurity AI models (Mythos 5) through partner integrations, updated Claude Security tools, and a new $35 million open-source funding program The company is adopting a "defensive outputs only" model, where users receive specific security findings (patches, alerts) rather than direct, unrestricted access to powerful AI models Project Glasswing and the Cyber Verification Program are expanding to give vetted organizations and critical infrastructure Anthropic通过合作伙伴集成、更新的Claude Security、3500万美元开源资助计划和扩大Cyber Verification Program,系统性扩展Mythos 5等高级模型的网络安全能力访问 采用"输出而非模型访问"的安全架构:终端用户通过专门构建的界面获取补丁建议、安全警报等防御性输出,而非直接交互模型,大幅降低滥用风险 Project Glasswing计划向受信任组织提供Mythos 5早期访问,Claude Security现已集成Mythos 5进行代码库扫描,提供CWE分类、置信度和严重性评级 Defender Advantage Fund投入3500万美元

68
Hot 热度
65
Quality 质量
62
Impact 影响力

Analysis 深度分析

TL;DR

  • Anthropic is expanding access to its advanced cybersecurity AI models (Mythos 5) through partner integrations, updated Claude Security tools, and a new $35 million open-source funding program
  • The company is adopting a "defensive outputs only" model, where users receive specific security findings (patches, alerts) rather than direct, unrestricted access to powerful AI models
  • Project Glasswing and the Cyber Verification Program are expanding to give vetted organizations and critical infrastructure protectors earlier access to dual-use cybersecurity capabilities
  • Claude Security now runs codebase scans on Mythos 5, providing CWE categories, confidence/severity ratings, and suggested fixes while keeping the model itself inaccessible
  • The Defender Advantage Fund (0xDAF) will support open-source maintainers in patching vulnerabilities and building reusable security scanning processes

Why It Matters

Anthropic is strategically positioning itself at the intersection of advanced AI and cybersecurity defense, recognizing that powerful models like Mythos 5 could be weaponized if widely accessible. By channeling capabilities through controlled interfaces and partner tools rather than direct model access, they're attempting to solve the dual-use dilemma that plagues the entire AI safety community. This approach could become an industry standard for how AI companies responsibly distribute cybersecurity capabilities.

Technical Details

  • Mythos 5 Architecture: Anthropic's advanced cybersecurity model, initially released through Project Glasswing in April as a preview, now powers Claude Security's codebase scanning capabilities with detailed vulnerability classification
  • Claude Security Integration: Public beta for Claude Enterprise customers; scans codebases and returns structured findings including CWE categories, confidence scores, severity ratings, and suggested fixes—all processed through purpose-built interfaces with abuse-prevention checks
  • Defensive Output Design: The system is engineered to return only defined outputs (patches, security alerts) rather than raw model interactions, with all fixes requiring human approval through Claude Code before deployment
  • Cyber Verification Program: Provides vetted organizations reduced safeguards on Claude Opus and Sonnet for authorized security work, expanding to include vulnerability triaging and validation, with Mythos-class access planned for future rollout
  • Defender Advantage Fund (0xDAF): $35 million in Claude credits allocated to organizations helping open-source maintainers secure projects, building on $4 million in direct donations from Project Glasswing efforts like Akrites and Gold Eagle

Industry Insight

  • The "controlled access through defensive outputs" model represents a pragmatic middle ground between unrestricted AI capability and overly restrictive guardrails—companies should evaluate similar architectures for their own security tooling rather than pursuing direct model access
  • Anthropic's partnership strategy with cybersecurity tool providers (integrating Mythos 5 into existing SOC, incident response, and detection platforms) suggests the future of AI security is embedded infrastructure rather than standalone tools; security teams should prioritize vendors adopting this integration approach
  • The expansion of the Cyber Verification Program signals that dual-use AI capabilities will increasingly require formal vetting processes; organizations should begin preparing compliance documentation and security control requirements now to qualify for early access as these programs scale

TL;DR

  • Anthropic通过合作伙伴集成、更新的Claude Security、3500万美元开源资助计划和扩大Cyber Verification Program,系统性扩展Mythos 5等高级模型的网络安全能力访问
  • 采用"输出而非模型访问"的安全架构:终端用户通过专门构建的界面获取补丁建议、安全警报等防御性输出,而非直接交互模型,大幅降低滥用风险
  • Project Glasswing计划向受信任组织提供Mythos 5早期访问,Claude Security现已集成Mythos 5进行代码库扫描,提供CWE分类、置信度和严重性评级
  • Defender Advantage Fund投入3500万美元Claude积分资助开源项目安全,Cyber Verification Program将扩展至漏洞分类、验证等更广泛的双重用途能力

为什么值得看

Anthropic在AI安全与能力开放之间提出了可落地的平衡方案,为行业树立了"防御性AI能力分发"的新范式。其分层访问策略(Mythos 5早期访问→Claude Fable 5广泛可用→Claude Security输出模式)展示了如何在防止恶意滥用的同时最大化AI的防御价值。

技术解析

  • 分层模型架构:Mythos 5(早期访问版)→ Claude Fable 5(广泛可用版,阻止双重用途网络工作)→ Claude Security(集成Mythos 5的扫描工具),形成从研究到生产的完整链条
  • 输出隔离机制:终端用户不直接与Mythos交互,而是通过专门构建的接口获取定义明确的输出(如补丁列表),内置滥用预防检查确保模型保持在限定范围内
  • Claude Security扫描流程:基于Mythos 5的代码库扫描提供CWE分类、置信度、严重性评级和修复建议,但修复需通过Claude Code实施并经人工审批后方可部署
  • 资金与验证体系:Defender Advantage Fund提供3500万美元Claude积分支持开源漏洞修复和扫描工具建设;Cyber Verification Program为经过审核的组织提供降低安全限制的Opus/Sonnet访问,后续扩展至Mythos级能力

行业启示

  • AI安全分发模式转型:从"开放模型访问"转向"开放防御输出",行业需重新思考高能力AI的安全分发机制,Anthropic的方案可能成为后续标准
  • 开源生态安全投资加速:3500万美元专项基金表明头部AI公司正系统性投资开源安全,安全团队应关注此类资助机会并加强与开源维护者的协作
  • 合规与验证门槛提升:Cyber Verification Program的扩展意味着高级AI安全能力将越来越依赖组织资质审核,企业需提前建立安全控制体系以获取访问权限

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Claude Claude Security 安全 Open Source 开源 LLM 大模型 Product Launch 产品发布