Claude Opus 4.8 is now available across every major cloud platform. AWS confirmed availability on May 28, the same day Anthropic announced the model, with access through both Amazon Bedrock, which keeps data inside AWS infrastructure, and the native Claude Platform on AWS. Google Cloud Vertex AI and Microsoft Foundry carried it from day one as well. For organizations already paying for one of those platforms, switching to Opus 4.8 is as simple as updating a model ID in their existing setup.
Pricing held flat at $5 per million words processed as input and $25 per million as output, the same as Opus 4.7. That matters less than the fast-mode price drop: running the model at 2.5 times its normal speed now costs three times less than it did with the previous version. For teams processing high volumes of documents, contracts, or research, that is a real cost difference.
Separately, Anthropic has brought Claude Security, its code-scanning product, out of private preview and into public beta for Enterprise customers, with Team and Max plan support coming. The tool reads through a company's software code the way a security analyst would: tracing how data moves between components, catching logical errors that standard pattern-matching scanners miss, and ranking findings by severity and confidence. Each confirmed issue comes with a suggested fix that a developer reviews before anything is actually changed. Early users reported going from finding a problem to shipping a patch in a single session, work that previously took days of coordination between separate security and engineering teams.
The current version of Claude Security runs on Opus 4.7. But strings visible in the product's source code already reference Mythos being prepared for Claude Security, and a model identifier labelled Mythos 1 briefly appeared in the Claude Code interface before being taken offline. The direction is clear: Mythos is being productized for this specific use case first.
That brings the real story into focus. Mythos, in its one month of restricted use across roughly 50 partner organizations through Project Glasswing, found more than 10,000 high-severity software vulnerabilities across widely used software systems. Cloudflare alone found 2,000 bugs in its own critical systems, 400 rated as serious, with a lower false-positive rate than human-led testing. Mozilla found and fixed 271 vulnerabilities in Firefox, more than ten times its normal rate using an earlier Claude model. Across more than 1,000 open-source projects, Mythos flagged over 6,200 serious candidates; six independent security firms verified 90.6% of the reviewed findings as real.
But here is what those numbers do not say: as of late May, fewer than 100 of the 1,596 vulnerabilities disclosed to software maintainers had been patched. Anthropic itself acknowledged that progress on software security is now limited not by finding problems but by verifying, disclosing, and patching them quickly enough. The model discovers vulnerabilities faster than the human systems designed to fix them can operate.
This is the constraint that sits between Mythos and a general release. Anthropic has said publicly it expects to bring Mythos-class capability to all customers within weeks. The model identifier is already in the code. Partners including Microsoft, Apple, Google, Cloudflare, Cisco, JPMorgan Chase, and others have been using it for weeks. The Cyber Verification Program exists to give legitimate security professionals access ahead of general availability.
The pricing signals suggest Mythos will carry a premium well above Opus: current Project Glasswing partners pay $25 per million input tokens and $125 per million output tokens after their initial credit pool, compared to Opus 4.8's $5 and $25. That is not a general-purpose model. For most business workflows, Opus 4.8 is the right tool and already available everywhere. Mythos, when it arrives, will be a specialist instrument for the hardest security and long-horizon autonomous tasks, and priced accordingly.
The patching gap is the number worth watching. A tool that finds problems at ten times the previous rate only helps if the organizations on the receiving end can act on what it finds. For the vast majority of businesses that do not write their own software, this means the security of the tools and platforms you already use is about to improve, whether your vendor tells you about it or not.