Anthropic、サイバー防御向け Claude Mythos 5 を提供開始
本文の状態
日本語全文を表示中
詳細モードで約11分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
Claude Blog
Anthropic は Claude Security への Claude Mythos 5 の統合を開始し、今後パートナーのサイバー防御ツールにも展開する予定である。
AI深層分析を開く2026年8月22日 22:19
AI深層分析
キーポイント
Claude Mythos 5 の防御機能拡大
Anthropic は Claude Security への Claude Mythos 5 の統合を開始し、今後パートナーのサイバー防御ツールにも展開する予定である。
リスク管理に基づくアクセス制御
モデルへの直接アクセスを制限しつつ、パッチやセキュリティアラートといった具体的な防御結果のみを提供することで、悪用リスクを低減する仕組みを導入した。
オープンソースセキュリティ基金の創設
「Defender Advantage Fund (0xDAF)」として 3500 万ドル相当のクレジットを提供し、オープンソースプロジェクトの脆弱性修正やスキャン自動化を支援する。
サイバー検証プログラムの拡充
Anthropic は既存の Cyber Verification Program の拡大計画を発表し、モデルの安全性と防御能力の強化を図る方針を示した。
既存のセキュリティツールへのClaude Mythos 5の統合
防御者が既に利用している製品やサービスにClaude Mythos 5を統合し、直接モデルにアクセスするのではなく、目的に特化したインターフェースを通じて防御結果を提供する。
重要な引用
We're sharing an update on our efforts to help more teams use frontier capabilities for cyber defense.
The riskiest behavior occurs when a user has direct access to a model, where a malicious actor can try to steer it toward harmful uses.
Our new Defender Advantage Fund (0xDAF) will provide $35 million in credits to organizations working to patch vulnerabilities in open-source projects, automate parts of the process of scanning and patching open-source software, and experiment with new security approaches.
When an end user uses one of these products, they're not interacting with Mythos directly. Instead, they work through a purpose-built interface that runs Mythos in the background for a defined task and only receive the specific artifact the product is intended to provide.
編集コメントを表示
編集コメント
この発表は、高度な AI モデルをセキュリティリスクの増大を防ぎながら実社会に統合する、極めて現実的なアプローチを示している。特に、モデルへの直接アクセスを制限して防御結果のみを提供する仕組みは、AI の悪用懸念に対する重要な解決策の一つと言える。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
より多くのセキュリティチームが最先端の防御能力を活用できるよう、私たちの取り組みに関する最新情報を共有します。
「Claude Mythos 5」は現在、「Claude Security」で利用可能となり、近い将来にはパートナー企業のサイバー防御ツールでも提供開始されます。また、オープンソースソフトウェアの保護を支援するための 3,500 万ドル規模の基金を創設し、「Cyber Verification Program」の拡大計画についても発表します。
今年 4 月、私たちは「Project Glasswing」を開始しました。これは、世界で最も重要なソフトウェアを守る少数の組織に対し、当社の最上位モデルである Claude Mythos Preview(およびその後継機である Claude Mythos 5)を早期に提供するためのプロジェクトです。これにより、同様の能力を持つモデルが一般公開される前や悪意あるアクターに渡る前に、セキュリティ担当者たちが脆弱性を発見し修正する時間を確保することが可能になりました。
私たちの目標は、安全に可能な限り多くの防御者に対して Mythos レベルの防御能力を拡大することです。そのために、私たちは 安全性分類器 やセーフガードの開発を進めており、これにより、モデルの攻撃的なサイバー機能を誤った手に渡すことなく、Mythos クラスのモデルへのアクセスを拡大することが可能になります。Claude Fable 5 はその第一歩でした。これはモデルを広く利用可能にする一方で、デュアルユース(民生・軍事両用)となるサイバー作業へのアクセスをブロックするものです。
今日、私たちは次の一歩を踏み出します。最もリスクが高いのは、ユーザーがモデルに直接アクセスできる場合です。この状況では、悪意のあるアクターが有害な用途へとモデルを誘導しようとする可能性があります。しかし、ユーザーが特定の出力(例えば脆弱性に対するパッチやセキュリティアラート)のみを受け取る場合、そのリスクは大幅に低下します。
今回発表する変更により、ユーザーは防御結果に対してより広いアクセス権を得ることができますが、モデルへの直接アクセスについては適切なガードレールを維持します。
防御者が信頼するツールへの Claude Mythos 5 の統合
セキュリティ対策に携わる方々が日常的に利用している製品やサービスへ、Claude Mythos 5 を組み込む取り組みを進めています。当社はサイバーセキュリティ技術およびサービスのパートナー企業と協力し、ソフトウェアの保護に活用されている既存のエコシステムへの統合を推進しています。
Claude Security スキャンが Claude Mythos 5 で実行可能に
Claude Enterprise プランをご利用のお客様は、現在、最も高性能なモデルである Claude Mythos 5 を「Claude Security」で利用できるようになりました。これにより、コードベース内のセキュリティ脆弱性をスキャンし、修正パッチの提案を行うことが可能です。
オープンソースセキュリティのための 3,500 万ドル相当のクレジット提供
新たに設立した「Defender Advantage Fund (0xDAF)」を通じて、オープンソースプロジェクトの脆弱性修正に取り組む組織に対し、総額 3,500 万ドル相当のクレジットを提供します。この資金は、スキャンやパッチ適用プロセスの一部を自動化する取り組みや、新たなセキュリティアプローチの実験に活用されます。
サイバー検証プログラムの拡大
同プログラムでは現在、審査を通過した防御者に対し、Opus および Sonnet モデルでの制限緩和措置が講じられています。今後数週間で、このプログラムは Opus と Sonnt のより広範なデュアルユース機能に対応するよう拡大され、その後に Mythos クラスのアクセス権限が付与される予定です。
今後の取り組み
AI モデルがますます強力になる中で、組織がサイバーセキュリティのスピードと要求に適応できるよう支援するという目的は変わりません。当社は引き続き、安全対策の強化、アクセスプログラムの整備、コミュニティサポートの拡充に取り組むことで、高性能なモデルをより多くの人々や組織が安全に利用できるようにしていきます。
既存のサイバー防御ツールへのミソス統合
病院、インフラ、金融システム、ソフトウェアサプライチェーンを守護するチームは、すでにセキュリティ運用、インシデント対応、脅威インテリジェンス、検知エンジニアリングのために一連のプロダクトとサービスを活用しています。最先端の能力をこれらの防御者へいち早く届ける最善の方法は、彼らが既に使用しているツールにミソス(Mythos)クラスのモデルを組み込むことです。
多くのパートナー企業はすでに、セキュリティチームがアラートをトリアージし、脅威を特定し、脆弱性への対応を迅速化するためのサイバープロダクトを Claude Opus 上で構築しています。現在、私たちはこれらのパートナーおよびさらに多くの企業と連携し、Claude Mythos 5 を彼らのプロダクトやサービスに組み込む取り組みを進めています。これにより、顧客に対してミソスレベルの防御成果を提供することが可能になります。
エンドユーザーがこれらの製品を利用する際、直接「Mythos」と対話しているわけではありません。代わりに、特定のタスクのためにバックグラウンドで Mythos を実行する専用インターフェースを通じて作業を行い、その製品が提供することを意図した特定の成果物のみを受け取ります。
例えば、脆弱性対策ツールであれば、推奨されるパッチのリストを出力として返すことになります。この出力は Mythos によって生成されますが、ユーザーがモデルに対して「ある脆弱性のためのエクスプロイトを開発してほしい」といったプロンプトを与える手段はありません。また、私どもとパートナー企業も、モデルが意図された範囲内で動作しているかを確認するための不正利用防止対策を講じています。
この取り組みはまだ初期段階にあり、将来的にはさらに拡大していく見込みです。セキュリティ製品やサービスを開発中で、Claude Mythos 5 を自社の顧客に提供したいとお考えの場合は、こちらから関心をお寄せください。
Claude Enterprise ユーザー向け「Claude Security」の Claude Mythos 5 対応開始
本日より、Claude Security のスキャンが Claude Mythos 5 をベースに実行されるようになりました。Claude Security はコードベースから脆弱性を検出し、人間によるレビューを前提としたパッチを提案します。現在は Claude Enterprise ユーザー向けに公開ベータ版として提供されており、Mythos 5 を利用したスキャンは既存プランの標準トークン使用量として課金されます。別途アドオンを購入する必要はありません。
エンタープライズ管理者は、管理コンソール で Claude Security を有効化できます。claude.ai/security から、Claude Mythos 5 を使用してスキャンするリポジトリを選択可能です。Claude はコードベース内の脆弱性をスキャンし、各発見事項について CWE(Common Weakness Enumeration)カテゴリ、信頼性および深刻度の評価、そして推奨される修正策を提示します。
その後、ユーザーはウェブ上の Claude Code を開いて修正を実装できます。インタラクティブなパッチ適用には、組織が Claude Code で利用可能なモデルが使用されます。ただし、Mythos によるスキャン自体が、他の領域への Mythos アクセス権限を拡張するわけではありません。すべてのパッチは、実装前に人間によるレビューと承認が必要です。
Claude Security は、ユーザーが所有するコードを Mythos 5 でスキャンし、モデルそのものを公開することなく詳細な発見事項を返します。これにより、防御担当者は Claude Mythos 5 の能力を利用できますが、悪用されるリスクのある人物が直接モデルにアクセスすることは防げます。
Claude Security に関する詳細は、スタートガイド をご覧ください。
オープンソースソフトウェアを守る「Defender Advantage Fund」の発足
世界で最も広く利用されているプログラムの多くは、オープンソースソフトウェア上で動作しています。しかし、これらのプロジェクトを維持しているのはボランティアや非営利財団であることが多く、攻撃からプロジェクトを包括的に守るためのリソースや人員が不足しているケースも少なくありません。
「Project Glasswing」を通じて、私たちはオープンソースのセキュリティ団体に対して直接 400 万ドルの寄付を行い、プログラムに参加する基盤組織にクレジットを提供しました。また、広く利用されているプロジェクトのスキャンとパッチ適用を支援し、Akrites や Gold Eagle のような協調的な脆弱性修正活動も後押ししました。
新たに発足した「Defender Advantage Fund (0xDAF)」は、これらの取り組みをさらに発展させるものです。オープンソースのメンテナがソフトウェアを守る活動を支援する組織に対し、Claude クレジット 3500 万ドル相当を提供します。助成金は主に以下の 3 つの領域に焦点を当てます。
- 広く利用されているプロジェクトにおけるライブな脆弱性の修正
- 他のプロジェクトでも再現可能な形でスキャンとパッチ適用を自動化する手法の開発
- 攻撃の特定のカテゴリ全体に対して耐性を持つ、より野心的なセキュリティアプローチへの挑戦支援
まずは少数の大規模なパイロット助成金から開始し、何が効果的でどのように拡大可能かを検証していきます。最初の採択者に関する詳細は、今後数週間で発表予定です。
サイバー検証プログラムの拡大
これまで、当社のサイバー検証プログラムは、Claude Opus および Sonnet モデルを利用する際に、組織が二重用途の機能へのアクセスを得られるよう支援してきました。このプログラムに参加している組織では、安全対策が緩和され、承認されたチームが保護対象システムの正当なサイバーセキュリティ作業を行う際の中断を最小限に抑えることができます。
今後数週間で、当社はプログラムを進化させ、Claude Mythos に対する安全対策付きのアクセス範囲を広げます。これに伴い、脆弱性の選別や検証といった防御機能へのアクセスが Mythos クラスのモデルにも拡大され、サイバー防衛担当者は Claude Opus や Sonnet クラスのモデルにおけるブロック制限が緩和されることになります。さらに、米国政府とのパートナーシップに基づく「Project Glasswing」を通じて、厳格なセキュリティ制御要件を満たす重要インフラの保護者に対し、Claude Mythos へのアクセス拡大を継続して行います。
サイバー検証プログラムの拡大に関する詳細は、今後数週間で発表いたします。それまでの間、正当なサイバーセキュリティ作業を行うすべてのセキュリティチームには、Claude Opus および Sonnet モデルでの安全対策緩和のために本プログラムへの申請をご検討いただくようお勧めします。すでに登録・承認されている場合は、特別な手続きは不要です。更新情報は別途ご連絡いたします。
今後の展望
これらの取り組みは、最先端モデルの防御機能をより多くの人や組織に提供し、オープンソースコミュニティが攻撃からプロジェクトを堅牢にするための支援を継続するものです。政府パートナー、組織、オープンソースのメンテナ、そして業界全体と連携し、高度な AI モデルが求める強靭なサイバーインフラの構築に取り組んでいきます。
- Cyber Verification Program への応募
- Mythos を活用したサイバー製品やサービスの開発 に関心がある方は登録してください。
- Claude Security は Enterprise ユーザー向けにパブリックベータ版として提供されています。管理者は 管理コンソール で Claude Security を有効化できます。詳細な手順については、スタートガイド をご覧ください。
原文を表示
*We're sharing an update on our efforts to help more teams use frontier capabilities for cyber defense. *Claude Mythos 5* is now available in *Claude Security*, and coming soon to partners' cyber defense tools. We're also launching a $35M fund to help secure open-source software and sharing plans to expand our *Cyber Verification Program*.*
In April, we launched Project Glasswing to put our most capable frontier model, Claude Mythos Preview (and its successor, Claude Mythos 5), in the hands of a small group of organizations securing the world’s most critical software. This gave defenders a window of time to find and fix vulnerabilities ahead of models with similar capabilities becoming generally available or reaching malicious actors.
Our goal has always been to expand Mythos-level defense to as many defenders as we safely can. To do that, we've been working on safety classifiers and safeguards that let us expand access to Mythos-class models without putting their offensive cyber capabilities in the wrong hands. Claude Fable 5 was the first step: it made the model broadly available while blocking dual-use cyber work.
Today, we’re taking the next steps. The riskiest behavior occurs when a user has direct access to a model, where a malicious actor can try to steer it toward harmful uses. But if users can only receive specific outputs, such as a patch for a vulnerability or a security alert, that risk is much lower. The changes we’re announcing give users greater access to the defensive results, while maintaining appropriate guardrails around direct access to the model:
- Claude Mythos 5 integration into the tools defenders rely on. We’re working with our cybersecurity technology and services partners to integrate Claude Mythos 5 into the products and services defenders already use to secure their software.
- Claude Security scans can now run on Claude Mythos 5. Customers on Claude Enterprise plans can now run our most capable model in Claude Security, using it to scan their codebases for security vulnerabilities and suggest patches.
- $35 million in credits for open-source security. Our new Defender Advantage Fund (0xDAF) will provide $35 million in credits to organizations working to patch vulnerabilities in open-source projects, automate parts of the process of scanning and patching open-source software, and experiment with new security approaches.
- Expanding our Cyber Verification Program. The program already gives vetted defenders reduced safeguards on Opus and Sonnet models. In the coming weeks, we will expand this program to include broader dual-use capabilities on Opus and Sonnet, with Mythos-class access to follow.
Our aim remains to help organizations adapt to the pace and demands of cybersecurity as AI models become increasingly powerful. We will continue to develop safeguards, access programs, and community support to make our most capable models safely available to a wide range of people and organizations.
Integrating Mythos into existing cyberdefensive tools
The teams defending hospitals, utilities, financial systems, and the software supply chain already rely on a suite of products and services for security operations, incident response, threat intelligence, and detection engineering. The fastest way to make frontier capabilities available to those defenders is to integrate Mythos-class models into the tools they already run.
Many of our partners have already built cyber products on Claude Opus that help security teams triage alerts, identify threats, and remediate vulnerabilities faster. We’re now working with these partners and more to build Claude Mythos 5 into their products and services, so they can deliver Mythos-level defensive outcomes to their customers.
When an end user uses one of these products, they’re not interacting with Mythos directly. Instead, they work through a purpose-built interface that runs Mythos in the background for a defined task and only receive the specific artifact the product is intended to provide. For example, a tool to remediate vulnerabilities might provide a list of suggested patches as its output. This output would be generated by Mythos, but the user would not have a way to prompt the model to, say, develop an exploit for a vulnerability. We and our partners also have abuse prevention measures in place to verify the model stays within its intended scope.
We're early in this work and expect it to expand over time. If you build security products or services and want to bring Claude Mythos 5 to your customers, you can register your interest here.
Making Claude Security available with Claude Mythos 5 for Enterprise customers
Starting today, Claude Security scans now run on Claude Mythos 5. Claude Security scans codebases for vulnerabilities and suggests patches for human review; it’s currently in public beta for Claude Enterprise customers, and scans with Mythos 5 are billed as standard token usage under your existing plan, with no separate add-on.
Enterprise admins can enable Claude Security in the admin console. From claude.ai/security, users can select a repository to scan using Claude Mythos 5. Claude then scans the codebase for vulnerabilities, and returns each finding with a CWE (Common Weakness Enumeration) category, confidence and severity ratings, and a suggested fix.
Users can then open Claude Code on the web to implement the fix. Interactive patching uses the models your organization has access to in Claude Code. The Mythos scan itself does not extend Mythos access to other surfaces. Every patch must be reviewed and approved by a human before it can be implemented.
Claude Security uses Mythos 5 to scan code you own, and returns detailed findings rather than raw outputs without exposing the model itself. This means defenders can access the capabilities of Claude Mythos 5 without the model becoming accessible to those who might misuse it.
For more about Claude Security, see our guide to getting started.
Launching the Defender Advantage Fund to secure open-source software
Some of the world’s most widely used programs run on open-source software. Yet these projects are often maintained by volunteers or nonprofit foundations, who may lack the resources or personnel to comprehensively defend their projects against attack. Through Project Glasswing, we made $4M in direct donations to open-source security organizations, provided credits to the open-source security foundations in the program, helped scan and patch widely used projects, and support coordinated vulnerability-fixing efforts like Akrites and Gold Eagle.
Our new Defender Advantage Fund (0xDAF) builds on that work with $35 million in Claude credits for organizations helping open-source maintainers secure their software. Grants will focus on three areas: patching live vulnerabilities in widely used projects, automating scanning and patching in ways other projects can replicate, and helping projects pursue more ambitious security approaches that make them resistant to whole classes of attack.
We're starting with a small number of larger, pilot grants to learn what works and scales best. We will share details on initial recipients in the coming weeks.
Expanding our Cyber Verification Program
To date, our Cyber Verification Program has provided organizations with access to dual-use capabilities when using Claude Opus and Sonnet models. Organizations in the program experience reduced safeguards, minimizing interruptions for accepted teams doing legitimate cybersecurity work on systems they’re authorized to protect.
Over the coming weeks, we are evolving the program to expand safeguarded access to Claude Mythos. As part of this, access to defensive capabilities like vulnerability triaging and validation will expand to Mythos-class models, and cyber defenders will see reduced blocks on Claude Opus and Sonnet-class models. Additionally, we are continuing to expand access to Claude Mythos through Project Glasswing in collaboration with our partners in the U.S. Government, focused on protectors of critically important infrastructure that meet strict security control requirements.
We'll share more details about the Cyber Verification Program expansion in the coming weeks. In the meantime, we encourage all security teams performing legitimate cybersecurity work to apply for the program for reduced safeguards on Claude Opus and Sonnet models. If you are already enrolled and accepted, no action is needed; we’ll reach out with updates.
What’s next
These initiatives are a continuation of our efforts to make the defensive capabilities of frontier models available to more people and organizations, and to support the open-source community in hardening their projects against attack. We will continue to work with government partners, organizations, open-source maintainers, and the broader industry to build the resilient cyber infrastructure today’s highly capable AI models demand.
- Apply for the Cyber Verification Program.
- Register your interest in building cyber products and offerings with Mythos.
- Claude Security is available in public beta for Enterprise customers. Admins can enable Claude Security in the admin console. For a full walkthrough, see our guide to getting started.
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み