메뉴
HN
Hacker News • 35일 전

클로드 미토스 5의 사이버보안 기능, 더 많은 방어자에게 확대

IMP
7/10
핵심 요약

Anthropic이 최고 성능 프론티어 모델인 Claude Mythos 5를 Claude Security와 파트너사의 사이버 방어 도구에 통합한다고 발표했습니다. 또한 오픈소스 보안 강화를 위한 3,500만 달러 규모의 'Defender Advantage Fund(0xDAF)' 크레딧 펀드를 출시하고, 검증된 방어자들에게 모델 안전장치를 완화해주는 사이버 검증 프로그램(Cyber Verification Program)을 Opus·Sonnet의 광범위한 듀얼유즈 기능까지 확대할 예정입니다. 공격적 사이버 능력의 악용을 막으면서도 방어 목적의 결과물(패치, 보안 경고 등)에는 폭넓은 접근을 허용하는 것이 핵심 전략입니다.

번역된 본문

클로드 미토스 5의 사이버보안 기능을 더 많은 방어자에게 제공하기

카테고리: 제품 발표 | 날짜: 2026년 8월 21일 | 읽는 시간: 5분

저희는 더 많은 팀이 사이버 방어에 프론티어(최첨단) 기능을 활용할 수 있도록 지원하는 노력에 대한 업데이트를 공유합니다. Claude Mythos 5가 이제 Claude Security에서 이용 가능하며, 곧 파트너사들의 사이버 방어 도구에도 제공될 예정입니다. 또한 오픈소스 소프트웨어를 보호하기 위한 3,500만 달러 규모의 펀드를 출시하고, 사이버 검증 프로그램(Cyber Verification Program)을 확장할 계획을 발표합니다.

4월, 저희는 세계에서 가장 중요한 소프트웨어를 보호하는 소수의 기관들에게 가장 강력한 프론티어 모델인 Claude Mythos Preview(및 후속 모델인 Claude Mythos 5)를 제공하는 '프로젝트 글래스윙(Project Glasswing)'을 시작했습니다. 이를 통해 방어자들은 유사한 수준의 능력을 갖춘 모델이 일반에 공개되거나 악의적인 행위자에게 도달하기 전에 취약점을 발견하고 수정할 수 있는 시간을 확보했습니다.

저희의 목표는 항상 미토스(Mythos) 수준의 방어 능력을 안전하게 가능한 한 많은 방어자에게 확대하는 것이었습니다. 이를 위해 저희는 공격적 사이버 능력이 잘못된 손에 들어가지 않도록 하면서 미토스급 모델에 대한 접근을 확장할 수 있는 안전 분류기(safety classifier)와 안전장치를 개발해 왔습니다. Claude Fable 5가 그 첫걸음이었습니다. 이 모델은 듀얼유즈(이중 용도) 사이버 작업을 차단하면서도 폭넓게 이용할 수 있게 했습니다. 오늘 저희는 다음 단계를 밟습니다.

가장 위험한 상황은 사용자가 모델에 직접 접근할 때 발생합니다. 악의적인 행위자가 모델을 유해한 용도로 유도하려고 시도할 수 있기 때문입니다. 하지만 사용자가 취약점 패치나 보안 경고 같은 특정 결과물만 받을 수 있다면 그 위험은 훨씬 낮아집니다. 오늘 발표하는 변화는 모델에 대한 직접 접근에는 적절한 안전장치를 유지하면서, 방어적 결과물에 대한 접근을 확대하는 것입니다:

  • 방어자들이 사용하는 도구에 Claude Mythos 5 통합: 저희는 사이버보안 기술 및 서비스 파트너들과 협력하여, 방어자들이 소프트웨어를 보호하기 위해 이미 사용 중인 제품과 서비스에 Claude Mythos 5를 통합하고 있습니다.

  • Claude Security 스캔에서 Claude Mythos 5 실행 가능: Claude Enterprise 플랜 고객은 이제 가장 강력한 모델을 Claude Security에서 실행하여 코드베이스의 보안 취약점을 스캔하고 패치를 제안받을 수 있습니다.

  • 오픈소스 보안을 위한 3,500만 달러 크레딧: 새로운 '디펜더 어드밴티지 펀드(Defender Advantage Fund, 0xDAF)'는 오픈소스 프로젝트의 취약점을 패치하고, 오픈소스 소프트웨어의 스캔 및 패치 과정을 자동화하며, 새로운 보안 접근 방식을 실험하는 기관들에 3,500만 달러 상당의 크레딧을 제공합니다.

  • 사이버 검증 프로그램 확대: 이 프로그램은 이미 검증된 방어자들에게 Opus 및 Sonnet 모델에 대한 완화된 안전장치를 제공하고 있습니다. 향후 몇 주 내에 Opus와 Sonnet에 대한 더 폭넓은 듀얼유즈 기능을 포함하도록 확장하고, 이어서 미토스급 접근도 제공할 예정입니다.

AI 모델이 점점 더 강력해짐에 따라 조직들이 사이버보안의 속도와 요구에 적응할 수 있도록 돕는 것이 저희의 목표입니다. 저희는 계속해서 안전장치, 접근 프로그램, 커뮤니티 지원을 개발하여 가장 강력한 모델을 다양한 사람과 조직에게 안전하게 제공할 것입니다.

기존 사이버 방어 도구에 미토스 통합하기

병원, 공공시설, 금융 시스템, 소프트웨어 공급망을 방어하는 팀들은 이미 보안 운영, 사고 대응, 위협 인텔리전스, 탐지 엔지니어링을 위한 일련의 제품과 서비스에 의존하고 있습니다. 이러한 방어자들에게 프론티어 기능을 가장 빠르게 제공하는 방법은 이미 사용 중인 도구에 미토스급 모델을 통합하는 것입니다. 많은 파트너사는 이미 Claude Opus 기반의 사이버 제품을 구축하여 보안 팀이 경고를 분류하고, 위협을 식별하고, 취약점을 더 빠르게 수정하도록 돕고 있습니다. 저희는 이러한 파트너사들 및 더 많은 기업들과 협력하여 Claude Mythos 5를 그들의 제품과 서비스에 탑재함으로써, 고객에게 미토스 수준의 방어 성과를 전달할 수 있도록 하고 있습니다.

원문 보기
원문 보기 (영어)
Bringing the cybersecurity capabilities of Claude Mythos 5 to more defenders Category Product announcements Product No items found. Date August 21, 2026 Reading time 5 min Share Copy link https://claude.com/blog/bringing-claude-mythos-5-to-more-defenders We're sharing an update on our efforts to help more teams use frontier capabilities for cyber defense. Claude Mythos 5 is now available in Claude Security , and coming soon to partners' cyber defense tools. We're also launching a $35M fund to help secure open-source software and sharing plans to expand our Cyber Verification Program . In April, we launched Project Glasswing to put our most capable frontier model, Claude Mythos Preview (and its successor, Claude Mythos 5), in the hands of a small group of organizations securing the world’s most critical software. This gave defenders a window of time to find and fix vulnerabilities ahead of models with similar capabilities becoming generally available or reaching malicious actors. Our goal has always been to expand Mythos-level defense to as many defenders as we safely can. To do that, we've been working on safety classifiers and safeguards that let us expand access to Mythos-class models without putting their offensive cyber capabilities in the wrong hands. Claude Fable 5 was the first step: it made the model broadly available while blocking dual-use cyber work. Today, we’re taking the next steps. The riskiest behavior occurs when a user has direct access to a model, where a malicious actor can try to steer it toward harmful uses. But if users can only receive specific outputs, such as a patch for a vulnerability or a security alert, that risk is much lower. The changes we’re announcing give users greater access to the defensive results, while maintaining appropriate guardrails around direct access to the model: Claude Mythos 5 integration into the tools defenders rely on. We’re working with our cybersecurity technology and services partners to integrate Claude Mythos 5 into the products and services defenders already use to secure their software. Claude Security scans can now run on Claude Mythos 5. Customers on Claude Enterprise plans can now run our most capable model in Claude Security, using it to scan their codebases for security vulnerabilities and suggest patches. $35 million in credits for open-source security. Our new Defender Advantage Fund (0xDAF) will provide $35 million in credits to organizations working to patch vulnerabilities in open-source projects, automate parts of the process of scanning and patching open-source software, and experiment with new security approaches. Expanding our Cyber Verification Program. The program already gives vetted defenders reduced safeguards on Opus and Sonnet models. In the coming weeks, we will expand this program to include broader dual-use capabilities on Opus and Sonnet, with Mythos-class access to follow. Our aim remains to help organizations adapt to the pace and demands of cybersecurity as AI models become increasingly powerful. We will continue to develop safeguards, access programs, and community support to make our most capable models safely available to a wide range of people and organizations. Integrating Mythos into existing cyberdefensive tools The teams defending hospitals, utilities, financial systems, and the software supply chain already rely on a suite of products and services for security operations, incident response, threat intelligence, and detection engineering. The fastest way to make frontier capabilities available to those defenders is to integrate Mythos-class models into the tools they already run. Many of our partners have already built cyber products on Claude Opus that help security teams triage alerts, identify threats, and remediate vulnerabilities faster. We’re now working with these partners and more to build Claude Mythos 5 into their products and services, so they can deliver Mythos-level defensive outcomes to their customers. When an end user uses one of these products, they’re not interacting with Mythos directly. Instead, they work through a purpose-built interface that runs Mythos in the background for a defined task and only receive the specific artifact the product is intended to provide. For example, a tool to remediate vulnerabilities might provide a list of suggested patches as its output. This output would be generated by Mythos, but the user would not have a way to prompt the model to, say, develop an exploit for a vulnerability. We and our partners also have abuse prevention measures in place to verify the model stays within its intended scope. We're early in this work and expect it to expand over time. If you build security products or services and want to bring Claude Mythos 5 to your customers, you can register your interest here . Making Claude Security available with Claude Mythos 5 for Enterprise customers Starting today, Claude Security scans now run on Claude Mythos 5. Claude Security scans codebases for vulnerabilities and suggests patches for human review; it’s currently in public beta for Claude Enterprise customers, and scans with Mythos 5 are billed as standard token usage under your existing plan, with no separate add-on. Enterprise admins can enable Claude Security in the admin console . From claude.ai/security , users can select a repository to scan using Claude Mythos 5. Claude then scans the codebase for vulnerabilities, and returns each finding with a CWE (Common Weakness Enumeration) category, confidence and severity ratings, and a suggested fix. Users can then open Claude Code on the web to implement the fix. Interactive patching uses the models your organization has access to in Claude Code. The Mythos scan itself does not extend Mythos access to other surfaces. Every patch must be reviewed and approved by a human before it can be implemented. Claude Security uses Mythos 5 to scan code you own, and returns detailed findings rather than raw outputs without exposing the model itself. This means defenders can access the capabilities of Claude Mythos 5 without the model becoming accessible to those who might misuse it. For more about Claude Security, see our guide to getting started . Launching the Defender Advantage Fund to secure open-source software Some of the world’s most widely used programs run on open-source software. Yet these projects are often maintained by volunteers or nonprofit foundations, who may lack the resources or personnel to comprehensively defend their projects against attack. Through Project Glasswing, we made $4M in direct donations to open-source security organizations, provided credits to the open-source security foundations in the program, helped scan and patch widely used projects, and support coordinated vulnerability-fixing efforts like Akrites and Gold Eagle . Our new Defender Advantage Fund (0xDAF) builds on that work with $35 million in Claude credits for organizations helping open-source maintainers secure their software. Grants will focus on three areas: patching live vulnerabilities in widely used projects, automating scanning and patching in ways other projects can replicate, and helping projects pursue more ambitious security approaches that make them resistant to whole classes of attack. We're starting with a small number of larger, pilot grants to learn what works and scales best. We will share details on initial recipients in the coming weeks. Expanding our Cyber Verification Program To date, our Cyber Verification Program has provided organizations with access to dual-use capabilities when using Claude Opus and Sonnet models. Organizations in the program experience reduced safeguards, minimizing interruptions for accepted teams doing legitimate cybersecurity work on systems they’re authorized to protect. Over the coming weeks, we are evolving the program to expand safeguarded access to Claude Mythos. As part of this, access to defensive capabilities like vulnera