news.mlab.sh
Back to the feed
threat-intel

Anthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploits

Medium
Summary

Anthropic’s Opus 5 AI model excels at finding software vulnerabilities, nearly matching Mythos 5’s capabilities, but it cannot automatically generate exploits. Anthropic deliberately limits Opus 5’s exploit generation abilities to prioritize safety and avoid misuse, while Mythos 5 remains unavailable for general use. The company is leveraging Mythos 5 for government software vulnerability scanning.

Anthropic recently released Claude Opus 5, a new AI model designed as a more affordable alternative to its top-tier Fable 5. While Opus 5 demonstrates impressive vulnerability detection skills, approaching Mythos 5’s performance, it lacks the ability to automatically develop working exploits. Anthropic has intentionally designed Opus 5 to avoid direct training on offensive cyber tasks, resulting in a significantly lower exploit-generation score compared to Mythos 5.

This deliberate limitation stems from Anthropic’s focus on safety and preventing misuse of the AI model. Opus 5’s safety classifiers are less restrictive than those of Fable 5, leading to fewer interventions from human operators. However, Opus 5 is permitted to search for vulnerabilities directly within source code.

Requests that trigger these safety classifiers are automatically routed back to the older Opus 4.8 model within Claude.ai, Claude Code, and Claude Cowork. Anthropic’s Cyber Verification Program offers a version of Opus 5 with further relaxed restrictions for enterprises and researchers.

Mythos 5 remains unavailable for general release, and Fable 5 is the safeguarded, publicly available model built on the same underlying technology. The models were previously taken offline due to concerns from the Trump administration regarding potential use by foreign nationals, a situation that has since been resolved. Opus 5 pricing remains at $5 per million input tokens and $25 per million output tokens, with a faster response mode available at double the base rate.

Read the full article at SecurityWeek