Anthropic targets vulnerability detection gains with Claude Security public beta — here's what users can expect
The Claude Mythos developer is aiming for a more limited approach to cyber tooling for public consumption
Anthropic has announced the public beta for Claude Security, its cybersecurity tool used for scanning codebases, detecting vulnerabilities, and generating patches.
Claude Security can scan full enterprise repositories to flag potential flaws – then open Claude Code to fix them – to reduce detection and response to one session for cyber workers.
In a video demo, Anthropic showed how Claude Security can conduct scans in just a single click, which prompts the tool to analyze relationships between components, data usage, and the viability of source code.
The tool then provides a list of potential vulnerabilities, including how each flaw can be reproduced and justifications for how severe they are. Along the way, Claude Security suggests how confident it is that the vulnerabilities it detects are legitimate.
Claude Security is accessible directly within Claude, or via a dedicated page on its website.
"Strong potential" with Claude Security
Claude Security was previously known as Claude Code Security, which Anthropic first made available to select organizations as a research preview.
The firm said it has collected feedback from hundreds of firms, which has helped make Claude Security more useful for enterprise applications.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
For example, Anthropic tweaked the tool to place a greater emphasis on validating AI findings, attaching a confidence percentage to each finding to reduce false positives.
New additions also include scheduled and targeted scans, as well as the option to export findings to Slack, Jira, or as CSV and Markdown files.
"Claude Security surfaced novel, high-quality findings during our early testing of the research preview that helped us identify and address potential security issues before they could affect our environment or our customers,” said Krzysztof Katowicz-Kowalewski, staff product security engineer at Snowflake.
“We see strong potential as we expand its use."
Concerns over AI security threats
Claude Security is underpinned by Claude Opus 4.7, Anthropic’s latest model which comes with embedded cyber guardrails. These are intended to prevent users from using the model for high-risk security tasks.
Anthropic’s new commitment to gating its cyber capabilities comes in the wake of its Project Glasswing launch, which saw it provide its most capable cyber model Claude Mythos Preview to select partners but not the public over safety concerns.
The UK’s AI Security Institute (AISI) has independently verified that the model is more capable at cyber tasks, and that it was the first to complete a 32-step enterprise network attack simulation designed to test LLM cyber exploit capabilities.
“Mythos Preview’s success on one cyber range indicates that it is at least capable of autonomously attacking small, weakly defended and vulnerable enterprise systems where access to a network has been gained,” the researchers noted.
However, they added that there are differences between real-world environments and simulations, such as the lack of proactive human defenders, which make it difficult to confirm that a model such as Mythos Preview could successfully breach well-defended systems.
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Rory Bathgate was Features and Multimedia Editor at ITPro until 2026, overseeing all in-depth content and case studies. He also co-hosted the ITPro Podcast with Jane McCallion, swapping a keyboard for a microphone to discuss the latest learnings with thought leaders from across the tech sector.
In his free time, Rory enjoys photography, video editing, and good science fiction. After graduating from the University of Kent with a BA in English and American Literature, Rory undertook an MA in Eighteenth-Century Studies at King’s College London. He joined ITPro in 2022 as a graduate, following four years in student journalism. You can contact Rory on LinkedIn.
-
Gartner: here's how AI will remake business in the next three yearsNews You've got three years to prep for these new attacks and challenges thanks to AI, says Gartner
-
Two-thirds of cyber threats still require manual resolutionNews Security teams are spending most of their time on reactive alert triage and manual data gathering, with little left over for proactive threat hunting
-
OpenAI and Anthropic admit rogue AI agents did more than first thoughtNews The two companies have shared additional details on agent misbehavior
-
Anthropic resumes model testing after recent cyber incidents – but it’s introduced new rules to improve securityNews Anthropic has boosted its security and tweaked its training to avoid rogue AI
-
‘The economics of vulnerability discovery have changed’: NIST wants to modernize the National Vulnerability Database amid AI advances – cyber experts say it needs to be redesigned with machine-speed in mindNews The National Vulnerability Database was designed for human-speed. Advances in AI mean it needs a much-needed overhaul
-
Anthropic’s Mythos AI tried to dupe devs in social engineering attack, collaborated with other agentsInter-agent collaboration is a serious cause for concern, says security expert
-
Cyber criminals are selling discount AI tokens on underground forumsNews Sites such as Poison Claude and Ecomagent.in are taking advantage of genuine promo offers and reselling access
-
1Password teams up with Anthropic to give Claude access to your credentialsNews A new ‘zero-exposure’ security framework allows agents to use stored credentials in the 1Password vault
-
The agents you use to beef up cybersecurity could be turned against you – ‘Friendly Fire’ attacks can manipulate OpenAI and Anthropic models into running malicious codeNews Research shows agents can be fooled into executing malicious code while performing security reviews of third-party software
-
Flaws in some of the most popular AI coding tools left developers wide open to attackNews Malicious repositories can trick advanced AI agents into silently breaking out of their workspace sandboxes