CyberSecurityBoardThreat Intel · CVEs · Products
Cyber News

Anthropic Launches Claude Fable 5 and Mythos 5: Dual AI Models with Cyber Safeguards

June 25, 2026

On June 9, Anthropic released Claude Fable 5, its most capable AI model, alongside a restricted version, Claude Mythos 5, designed for vetted cybersecurity professionals. Fable 5 is available to the public with safety classifiers that route flagged requests—including cyber, biology, chemistry, and distillation tasks—to the weaker Claude Opus 4.8. Mythos 5, which retains full cyber capabilities, is limited to authorized defenders and critical infrastructure operators.

Both models cost $10 per million input tokens and $50 per million output tokens, less than half the price of the earlier Mythos Preview. Fable 5 is included in Pro, Max, Team, and Enterprise plans at no extra cost until June 22, after which it shifts to usage credits.

The safety classifiers are designed to block offensive cyber tasks such as exploit development, reconnaissance, and lateral movement. In internal evaluations, the classifiers prevented any progress on these tasks. External testing showed Fable 5 complied with zero harmful requests across 30 jailbreak techniques. However, false positives occur in under 5% of sessions, with Anthropic planning to refine safeguards post-launch.

Anthropic’s earlier Mythos Preview identified zero-day vulnerabilities in all major operating systems and browsers, including a 27-year-old flaw in OpenBSD and CVE-2026-4747 in FreeBSD. The model autonomously developed exploits, highlighting the dual-use nature of advanced AI. During Project Glasswing, partners found over 10,000 high- or critical-severity vulnerabilities, with Cloudflare alone discovering 2,000 bugs. Mozilla fixed 271 vulnerabilities in Firefox 150, a tenfold increase over previous versions.

The bottleneck has shifted from discovery to patching, with open-source maintainers struggling to keep up. Anthropic’s red team demonstrated that Mythos Preview could build working Linux privilege-escalation exploits from disclosed CVEs in under a day. The company has implemented a 30-day data retention policy for all traffic on Fable 5 and Mythos 5 to aid in detecting novel attacks, with data not used for training and deleted after 30 days unless required for safety or legal reasons.

Anthropic has opened a Cyber Verification Program for vetted security professionals and plans to expand Mythos 5 access through a trusted-access program. The launch underscores the challenge of balancing AI capabilities with safety, as similar models from other labs are expected to emerge without such safeguards.

CVEs: CVE-2026-4747, CVE-2026-11645

Companies: Anthropic, Cloudflare, Mozilla

Products: Claude Fable 5, Claude Mythos 5, Claude Opus 4.8, Claude Mythos Preview

Events: Project Glasswing