AI
Anthropic Brings Suggested Patches to Claude Code on the Web
Anthropic expands access to Mythos for defenders via suggested patches in Claude Code on the web, using models teams already use.

Anthropic has announced an update to Claude Code that allows suggested patches to be opened directly in the web interface, using the models that user teams already employ. The announcement was made via the official X account (@claudeai) on Saturday, August 22, 2026, as part of the company's effort to give defenders broader access to the results of Mythos without requiring direct access to the model. In the post, Anthropic explained that the Mythos model runs behind the scans and only returns findings to users. These scans are billed as standard token usage under existing plans, so there is no additional cost specifically for using this new feature. The update continues the development of Mythos, which was previously introduced as a frontier cybersecurity model.
In April 2026, Spectrum IEEE reported that Project Glasswing, the foundation for Mythos, aims to catch critical software bugs by adding multiple layers of verification and human oversight as an initial step. Claude Code already had vulnerability scanning capabilities through the Claude Security plugin. Official documentation at code.claude.com explains that users can install the plugin to scan codebases within a Claude Code session and turn findings into patches that are then reviewed and applied manually. This approach differs from traditional code scanning. Analysis from penligent.ai notes that Claude Code Security shifts code scanning from rule matching to semantic reasoning with multi stage verification and human approved patching. This approach reportedly shook the cybersecurity market in February 2026. The development timeline of Mythos shows a consistent pattern.
In April 2026, Project Glasswing was introduced with a focus on layered verification and human oversight. In August 2026, Anthropic began sharing updates about efforts to help more teams leverage frontier capabilities for cyber defense, as detailed in the official Claude blog published on August 21, 2026. The latest announcement reinforces Anthropic's strategic direction to democratize access to advanced security capabilities. By opening suggested patches on the web, security teams are no longer tied to a terminal environment or specific command line interface; instead, they can review scan results through a browser with models they already know. A key aspect of this update is that the model remains behind the scenes. Users only receive findings, not access to the model itself.
This means control over the Mythos model remains with Anthropic, while users benefit from the analysis it produces. On the cost side, using standard tokens means organizations can estimate expenses based on the volume of scans they perform. This aligns with the usage based pricing model common in the AI industry, where costs are determined by the number of tokens processed. For security teams already using Claude Code, this update lowers adoption barriers because it requires no additional infrastructure or significant workflow changes. They simply open suggested patches on the web and review findings with the models their team already uses. The impact on the cybersecurity market warrants attention.
Since February 2026, the Claude Code Security approach has triggered a shift in how code scanning is perceived, moving from mere pattern matching to deeper semantic reasoning. This update has the potential to accelerate adoption of that approach among organizations that were previously hesitant. However, it should be noted that the effectiveness of this approach still has limitations. Analysis from penligent.ai mentions that there are capability differences between this approach and traditional SAST, fuzzing, and DAST. Each method has its own strengths and weaknesses in detecting various types of vulnerabilities. Anthropic itself emphasizes the importance of verification and human oversight. In the development of Project Glasswing, multiple verification layers and human oversight are key components to ensure accurate and accountable results.
The developer community has responded to these developments in various ways. A GitHub gist published before the launch of Mythos provides a 7 phase AI codebase security audit template mapped to OWASP 2025, showing the community's readiness to adopt this new approach. Looking ahead, this update opens the door for tighter integration between development and security tools. With suggested patches available on the web, security review workflows become more flexible and accessible to more team members, not just those familiar with command line interfaces. The next stage of development still awaits market response and user adoption. What is clear is that Anthropic continues to expand the reach of Mythos in a way that maintains control over the model while delivering maximum value to users.
This update is an indicator that competition in the AI based code security segment is intensifying, with approaches increasingly focused on accessibility and ease of use.