Anthropic on Friday rolled out Claude Opus 5, pitching it as a cheaper alternative to its top-tier Fable 5 model. In terms of cybersecurity, the new model is nearly as good as the AI giant’s most capable system, Mythos 5, at spotting software vulnerabilities, but remains well behind it in turning those findings into working exploits.
The difference comes from Anthropic’s own OSS-Fuzz-based evaluation, which measures how well a model can locate and then exploit vulnerabilities with minimal human steering. According to the company, Opus 5 identifies vulnerabilities at a rate close to Mythos 5, but its exploit-development score trails considerably.
Anthropic frames this as a deliberate outcome, noting that it has avoided training Opus 5 directly on offensive cyber tasks. The gains it does show, the company says, are a byproduct of broader capability improvements.
Opus 5’s safety classifiers are tuned to be less restrictive than those on Fable 5, with Anthropic expecting roughly 85 percent fewer interventions.
The model is permitted to search for vulnerabilities directly in source code, but binary-based vulnerability scanning, penetration testing, and exploit generation remain blocked. Requests that trip those classifiers fall back automatically to the older Opus 4.8 model inside Claude.ai, Claude Code, and Claude Cowork.







