Skip to main content
← Back to Blog

How Good Is Opus 5 For Cybersecurity?

Brandon Veiseh, Co-Founder & CEO at MindFort

Written by

Brandon Veiseh

2026-07-24·4 min read

Claude Opus 5, released by Anthropic on July 24, 2026, is the first generally available model that finds vulnerabilities in source code at close to Mythos-class quality, and Anthropic unblocked that task at every access level. It is still weaker at exploitation, and its classifiers block penetration testing outright.

Claude Opus 5 , released by Anthropic on July 24, 2026, is the first generally available model that finds vulnerabilities in source code at close to Mythos-class quality, and Anthropic unblocked that specific task for every user at every access level. It is still weaker than Mythos 5 at turning those findings into working exploits, and its classifiers block penetration testing outright. That means Opus 5 can tell you a bug looks real in your code, but it cannot prove the bug is exploitable against your running application.

Opus 5 shipped at $5 per million input tokens and $25 per million output tokens, the same price as Opus 4.8. Anthropic says it did not train the model on cyber tasks at all, and that whatever security skill it shows came out of general capability gains. The interesting part for defenders is not the benchmark jump. It is that Anthropic changed the rules on what the model is allowed to do.

Is Opus 5 good at security?

Yes, and for the first time the answer is not hedged by a classifier. Anthropic's system card  states that Opus 5 now permits source-code vulnerability discovery at all access levels, including general availability, on the reasoning that finding bugs in code is part of the secure development lifecycle. Anthropic also reports that Opus 5 blocks significantly less defensive coding work than Fable 5 does, which covers patching known bugs, incident response, containment, and configuration review.

The capability behind that permission is real. On Anthropic's OSS-Fuzz evaluation , which points a model at roughly 830 fuzzing entry points across 228 open-source projects with no vulnerability hints, Opus 5 scored above zero on 79.4% of targets. Opus 4.8 managed 38.5%. Mythos 5, the strongest cyber model Anthropic has built, managed 80%.

Is Opus 5 better than Mythos 5?

No, and the gap is entirely on the exploitation side. Opus 5 fully exploited 4 OSS-Fuzz targets against Mythos 5's 13, and VentureBeat  reads that asymmetry as deliberate: strong at defense-relevant discovery, weak at offense-relevant weaponization. On the Anthropic and Mozilla Firefox 147 evaluation, Opus 5 produced a full working exploit in 131 of 250 trials at 52.4%, against Mythos 5's 88.4%. Opus 4.8 managed 22 trials, or 8.8%.

One benchmark cuts against the clean story, and it is worth knowing about. On ExploitBench , which grades 41 recent Chrome V8 vulnerabilities across 16 capability flags, Opus 5 captured 10.14 flags per trial to Mythos 5's 10.80 and produced 99 complete arbitrary code execution exploits. Opus 4.8 produced 2. On a hardened browser engine with ASLR, stack canaries, and the V8 heap sandbox enabled, Opus 5 is not far off frontier at weaponization.

Can Opus 5 run a penetration test?

No. Opus 5's cyber classifiers block binary-based vulnerability scanning, penetration testing, and exploit generation, per The New Stack . Anthropic expects those classifiers to fire around 85% less often than Fable 5's, and when one fires in Claude.ai, Claude Code, or Cowork, the request quietly falls back to Opus 4.8. This is the same pattern we covered in our Fable 5 writeup, just with a wider aperture.

Two details matter if you plan to build on this. Anthropic's support documentation  notes that the checks review everything the model reads, not just your prompt, so memory, connector output, web results, and files can all trigger a fallback you did not ask for. Enterprises that need the blocks lifted for real pentesting have to go through the Cyber Verification Program .

What should security teams actually do now?

Use Opus 5 for what Anthropic unblocked it for. Point it at your source, let it read CVEs and patch diffs, have it draft threat models and fixes. Then treat every finding as a hypothesis, because a model reading code cannot tell you which of its bugs are reachable in your deployed application.

That gap is what MindFort was built to close. Our autonomous agents run against your running app, API, and infrastructure the way an attacker would, reproduce each exploit in an isolated environment before anything reaches your queue, and hand back every proven finding as a merge-ready patch PR. It runs on MF-1, our own model built for offensive security reasoning rather than a wrapper on someone else's frontier release, and we call the category AXR (Autonomous Exploitation and Remediation). If you are comparing options, our 2026 AI Pentesting Buyer's Guide covers what to ask vendors. Opus 5 gives you more findings. What you need is fewer, and proof for each one.

FAQ

Is Claude Opus 5 good at cybersecurity?

Yes, for defensive work. Opus 5 scored above zero on 79.4% of Anthropic's OSS-Fuzz targets against Opus 4.8's 38.5%, and Anthropic now permits source-code vulnerability discovery at all access levels. It cannot run attacks against a live application, so it cannot confirm that a finding is exploitable.

Is Opus 5 better than Mythos 5 for security?

No. Opus 5 nearly matches Mythos 5 at finding vulnerabilities, at 79.4% versus 80% on OSS-Fuzz, but it fully exploited 4 targets against Mythos 5's 13. On the Firefox 147 evaluation it produced full exploits in 52.4% of trials against Mythos 5's 88.4%. On ExploitBench's V8 targets the gap is much narrower, at 10.14 capability flags per trial versus 10.80.

Can Opus 5 do penetration testing?

No. Opus 5's classifiers block penetration testing, exploit generation, and binary-based vulnerability scanning. Flagged requests in Claude.ai, Claude Code, and Cowork fall back to Opus 4.8. Enterprises can apply to Anthropic's Cyber Verification Program to have those restrictions lifted.

What changed in Opus 5's cyber safeguards?

Opus 5 uses Fable 5's classifier design with one change: source-code vulnerability discovery is now allowed at every access level. Anthropic expects the classifiers to fire around 85% less often than Fable 5's, and the checks also inspect memory, connector data, files, and search results, not just your prompt.

Can Opus 5 replace runtime security testing?

No. Opus 5 reads code, it does not exercise your deployed application. False positives that look exploitable in source and false negatives that only appear when services interact at runtime both live in that gap, and neither shows up in a static pass.

How does MindFort compare to using Opus 5 directly?

MindFort runs autonomous agents against your live application instead of reading your repository. The agents probe apps, APIs, and infrastructure, validate each exploit in an isolated environment before reporting it, and deliver the fix as a merge-ready PR. The category is AXR (Autonomous Exploitation and Remediation).

About the author

Brandon Veiseh, Co-Founder & CEO at MindFort

Brandon Veiseh

Co-Founder & CEO · MindFort

Founded his first startup building NLP models for network packet inspection. Led product at ProjectDiscovery, built their enterprise platform from scratch. At NetSPI, led development of AI tools for offensive security.

Autonomous SecurityFor Every Team. Now.

Agents find vulnerabilities and fix them for you.

Book a demo with our team.

First Results

Hours

Coverage

24/7

False Positives

<1%

Setup

Minutes