Anthropic、Claude Security スキャナに Mythos 5 モデルを導入
本文の状態
日本語全文を表示中
詳細モードで約4分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
The New Stack AI
Anthropic がセキュリティ脆弱性スキャナ「Claude Security」に、以前は非公開だった高性能モデル「Mythos 5」を導入し、企業向けに公開ベータを開始した。
AI深層分析を開く2026年8月22日 04:35
AI深層分析
キーポイント
Mythos 5 の Claude Security への統合
Anthropic は開発チームのコードベースから脆弱性を特定・修正するツール「Claude Security」に、以前は限定的なパートナーのみが利用できた高性能モデル「Mythos 5」を適用した。
リスク低減のための設計変更
ユーザーがモデルに直接アクセスして悪意ある指示を与えるリスクを避けるため、特定の出力(パッチやアラート)のみを受け取る形とし、モデルへの直接的な介入を防ぐガードレールを維持している。
オープンソース脆弱性対策基金の創設
同社は「Defender Advantage Fund (0xDAF)」を立ち上げ、オープンソースソフトウェアの脆弱性発見と修正に充てるための 3500 万ドル相当のクレジットを提供すると発表した。
Cyber Verification Program の拡大
審査済みの防衛チームが Opus や Sonnet でデュアルユースのセキュリティ作業を行うプログラムを強化し、近い将来「Claude Mythos」への安全なアクセス権も付与する予定である。
Claude Enterprise ユーザー向け公開ベータ
Mythos 5 は Claude Security を利用したいすべての Claude Enterprise ユーザー向けに公開ベータとして利用可能となった。管理者が有効化すると、開発者やセキュリティチームは Mythos 5 を用いてリポジトリのスキャンと問題発生時の修正提案が可能になる。
重要な引用
"The riskiest behavior occurs when a user has direct access to a model, where a malicious actor can try to steer it toward harmful uses."
"But if users can only receive specific outputs, such as a patch for a vulnerability or a security alert, that risk is much lower."
"Anthropic says Claude Security 'uses Mythos 5 to scan code you own.'"
Admins can enable it for their users and then developers and security teams can use it to scan their repositories with Mythos 5 at the helm and suggesting fixes when it finds an issue.
編集コメントを表示
編集コメント
Mythos 5 のような高性能モデルを、直接アクセスを制限する形での実装は、AI セキュリティ領域における重要なマイルストーンとなる。企業にとって、高度な防御能力を維持しつつリスクを最小化する運用モデルの参考事例として注目される。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。

今年初、Anthropic は開発チームがコードベースからセキュリティ上の脆弱性を特定し、修正するためのエンタープライズ向けツール「Claude Security」をリリースしました。そして金曜日、同社はこのサービスに Claude Mythos 5 モデルを搭載する大規模なアップデートを実施したと発表しました。
さらに Anthropic は、他のサイバーセキュリティ企業とも連携し、自社の製品へ Mythos 5 を統合する支援を進めています。同時に、「Defender Advantage Fund (0xDAF)」という新たな基金も立ち上げます。この基金はオープンソースソフトウェアの脆弱性発見と修正に向けた活動に対し、3,500 万ドル相当のクレジットを提供します。
Anthropic は以前より「Cyber Verification Program」を運営しており、審査済みのセキュリティ専門家に対して、Opus や Sonnet モデルを用いたデュアルユース(二重利用)のサイバーセキュリティ作業を、制限を緩和して実行できる環境を提供しています。同社によると、これらの組織には間もなく Claude Mythos 5 への安全なアクセス権も付与される予定です。
Mythos 5 の背景:公開には至らなかった理由
Mythos 5 は、ハイリスク領域におけるタスク処理能力が極めて高かったため、Anthropic が一般公開を見送ったモデルです。代わりに同社は今年 6 月、「Fable 5」をリリースしました。これは実質的に Mythos 5 をベースにしていますが、非常に厳格なガードレール(安全装置)が設けられています。
当時、Mythos 5 は Anthropic の「Project Glasswing」プログラムに参加する約 150 社のパートナー企業のみが利用可能でした。なお、Fable 5 が米政府によって一時禁止され、その後解禁された経緯についても言及されています。
Claude Security における Mythos 5
では、なぜ Anthropic は今、Claude Security に Mythos 5 を追加することに安心感を持っているのでしょうか。
同社は発表の中で、「最もリスクが高いのは、ユーザーがモデルに直接アクセスできる場合です。この状況では悪意のあるアクターが、有害な用途へとモデルを誘導しようとする可能性があります」と述べています。「しかし、ユーザーが受け取れるのが脆弱性に対するパッチやセキュリティアラートといった特定の出力のみであれば、そのリスクは大幅に低下します。今回発表する変更により、ユーザーは防御結果へのアクセス権限を拡大できますが、モデルへの直接アクセスについては適切なガードレールを維持します」
安全対策
本質的に、Anthropic がこのプロセスを統括しており、すべてが同社のツールやハーンネス内で実行されるため、同社は現在、すべての企業に Mythos 5 を提供しても安全だと主張しています。ユーザーはモデルへの直接アクセスではなく、検出結果とパッチを受け取ることになります。Anthropic は「Claude Security は、あなたが所有するコードをスキャンするために Mythos 5 を使用します」と説明しています。
また、「当社およびパートナー企業には、モデルが意図された範囲内に留まることを確認するための悪用防止措置が講じられています」とも付け加えています。
多くのコードベースにオープンソースライブラリが含まれているため、所有権の概念は少し曖昧になりがちです。さらに、開発者が広く展開されているライブラリをクローンして自社のリポジトリに取り込み、Mythos 5 にスキャンさせるとすれば、攻撃者が探しているのと同じ検出結果が得られることになります。結局のところ、その脆弱性は、そのライブラリが配布されるすべての場所に存在するからです。この状況がどう展開するかは、今後の動向に注目する必要があります。
実務的には、これにより Mythos 5 は、Claude Security を利用したいすべての Claude Enterprise ユーザー向けにパブリックベータ版として提供されるようになりました。管理者はユーザーに対してこの機能を有効化でき、その後、開発者やセキュリティチームが Mythos 5 を中核に据えてリポジトリのスキャンを開始し、問題が見つかった際には修正提案を行えるようになります。
ただし、Mythos 5 のトークン使用にはコストがかかります。Anthropic は入力トークン 100 万あたり 10 ドル、出力トークン 100 万あたり 50 ドルを請求しています。
原文を表示

Earlier this year, Anthropic launched Claude Security, an enterprise tool that helps development teams scan their codebase for security vulnerabilities and patch them. On Friday, the company gave Claude Security a major upgrade by bringing its Claude Mythos 5 model to the service.
In addition, Anthropic is also working with other cybersecurity companies to help them integrate Mythos 5 into their products, and it is launching a new Defender Advantage Fund (0xDAF) that will provide $35 million in credits to find and patch vulnerabilities in open source software.
Anthropic previously also launched its Cyber Verification Program, which lets vetted defenders run dual-use cybersecurity work on Opus and Sonnet with fewer blocks. Those organizations will also get safeguarded access to Claude Mythos soon, Anthropic says.
The Mythos 5 story: too good to launch
Mythos 5, of course, is the model that was so good in performing tasks in high-risk domains that Anthropic didn’t give it a public release. Instead, in June, it launched Fable 5, which is essentially Mythos 5 but with very strict guardrails.
Mythos 5, at the time, was only available to about 150 partners in Anthropic’s Project Glasswing program (and there’s the whole sidestory of Fable 5 getting banned and unbanned by the U.S. government).
Mythos 5 in Claude Security
So why does the company feel comfortable adding Mythos 5 to Claude Security now?
“The riskiest behavior occurs when a user has direct access to a model, where a malicious actor can try to steer it toward harmful uses,” Anthropic writes in the announcement. “But if users can only receive specific outputs, such as a patch for a vulnerability or a security alert, that risk is much lower. The changes we’re announcing give users greater access to the defensive results, while maintaining appropriate guardrails around direct access to the model.”
Safeguards
Essentially, since Anthropic is in charge here and all of this runs inside of its tools and harnesses, the company argues it can safely give Mythos 5 to all enterprises now. Users get findings and patches instead of direct model access, and Anthropic says Claude Security “uses Mythos 5 to scan code you own.”
It also adds that it and its partners “have abuse prevention measures in place to verify the model stays within its intended scope.”
Since many codebases include open source libraries, ownership becomes a bit of a slippery category. Also, a developer who clones a widely deployed library into a company repo and then points Mythos 5 at it would get the same findings an attacker would be looking for. That vulnerability, after all, would exist everywhere that library ships. We’ll have to see how this plays out.
In practice, this means Mythos 5 is now in public beta for all Claude Enterprise users who want to use Claude Security. Admins can enable it for their users and then developers and security teams can use it to scan their repositories with Mythos 5 at the helm and suggesting fixes when it finds an issue.
Mythos 5 tokens aren’t cheap, though. Anthropic charges $10 per million input and $50 per million output tokens.
The post Anthropic brings Mythos 5 to its Claude Security vulnerability scanner appeared first on The New Stack.
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み