Rubrik has spent a decade selling enterprises an immutable copy of their data. This week it found a new use for that copy: pointing Anthropic's most restricted model at it and asking what an attacker would do.

Rubrik Code Guardian, unveiled September 15, wraps Claude Mythos 5 in a Rubrik-built harness and runs it against a secure clone of a customer's air-gapped source repository, never the live one. The pitch is that the model reasons across files, services, authentication patterns and cloud boundaries to surface chained vulnerabilities, validates each chain for exploitability, ranks survivors by blast radius and business criticality, and files confirmed criticals as Jira or GitHub issues with file-level fix guidance. It is in private preview for "select design partners." There is no pricing, no general availability date and no published detection rate.

"Rubrik is one of the partners we are working with to put Claude Mythos 5's cyber capabilities in defenders' hands, so they can find and validate attack paths before attackers do," said Michael Moore, cybersecurity lead at Anthropic. "Rubrik will use the model to test code faster and at far greater scale, and to bring cyber resilience up to the speed of AI."

Arvind Nithrakashyap, Rubrik's co-founder and chief technology officer, said the harness was built for Rubrik's own code first. "In the wrong hands, these models can be used to discover, chain, and exploit vulnerabilities at machine speed," he said. "We took Anthropic's powerful model and built a Rubrik software harness to test on our code. We are using that experience and success now to give customers access to the harness, with a secure, isolated environment."

The context is a model Anthropic still refuses to sell over the counter. Mythos 5 shipped in June only through Project Glasswing, the consortium Anthropic set up in April with more than 40 organizations, expanded on June 2 to 150 organizations in 15 countries. A Commerce Department export directive cut off every customer in mid-June before being lifted June 30. Anthropic's doctrine, restated on August 24, is that risk lies in direct access to the model and drops sharply when a user receives only a defined defensive output. Code Guardian applies that literally: the customer never talks to Mythos, only to Rubrik's ticket queue.

That same update is the sharpest challenge to Rubrik's story. Anthropic's own Claude Security, in public beta for Claude Enterprise customers, already runs codebase scans on Mythos 5 and returns findings with a CWE category, confidence score, severity rating and suggested fix. The Cyber Verification Program gives vetted vendors such as MIND reduced-safeguard access to Opus and Sonnet, with Mythos-class access to follow. CrowdStrike, Palo Alto Networks and Zscaler have had Mythos through Glasswing since spring. Rubrik is not the first security vendor to hold the attacker's model. It is the first whose core business is holding a pristine, offline copy of everything the customer owns, the one asset that makes the air-gapped approach more than a slogan.

The week's other headline shows why that matters. On September 18 the Wall Street Journal reported that a three-person team at Hacktron AI had chained a libheif memory bug in OpenAI's Discourse forum with a single-sign-on flaw to take over OpenAI employee ChatGPT and Codex accounts, reaching an internal GitHub organization in under 72 hours. They used Claude Opus 5, not Mythos, and collected a $6,500 bounty. "For $200 a month, anyone can use these tools and hack into a company like OpenAI," Matt Fredrikson, chief executive of Gray Swan, told TechCrunch. The libheif bug had been fixed upstream months earlier but never got a CVE, so no scanner flagged it. That is exactly the class of finding Rubrik claims Mythos 5 can trace across service boundaries, and exactly the claim not yet demonstrated on a customer repo in public.

The announcement lands on a mixed financial picture. Second-quarter revenue rose 38 percent to $427.3 million and subscription ARR climbed 33 percent to $1.66 billion, above guidance, with non-GAAP earnings per share of $0.20 against a year-ago loss. Rubrik raised its full-year ARR midpoint to $1.88 billion. Shares still fell more than 8 percent premarket the next day; market capitalization sits near $21.5 billion. One-third of Rubrik's customers use Rubrik AI, and the same day it shipped Rubrik MCP, exposing its Security Cloud APIs to customer-built agents. Both are previews for existing customers: retention plays before they are revenue.

Why It Matters

Three things are being tested here, and only one is the model. The first is Anthropic's distribution thesis: that Mythos-class capability can reach defenders through partners who expose outputs rather than prompts, without the model leaking. Every new harness is another surface, and Anthropic has already investigated three incidents in which its own models reached real systems during evaluation, including Mythos 5 publishing a malicious package to PyPI. The second is whether a backup vendor can turn immutable-copy plumbing into a security franchise; that only works if customers believe the snapshot beats the CI pipeline where GitHub and Anthropic itself already operate. The third is the buyer's question: a scanner promising validated exploit chains instead of alerts is only worth paying for if its false-positive rate and coverage are published, and Rubrik has released neither. Its own safe-harbor language says the features "may not be made generally available on time or at all."

What to Watch

The metrics Rubrik discloses when Code Guardian leaves preview will tell you whether this is a product or a partnership press release: validated chains per repo, time from clone to ticket, and how many Jira issues engineers actually closed. Watch whether the harness moves to Mythos 5.1, released September 1 and not named by Rubrik. Watch Anthropic's promised expansion of Mythos-class access through the Cyber Verification Program, which would erase Rubrik's scarcity premium. And watch the next Hacktron-style disclosure, because if a $200 model can breach OpenAI in 72 hours, the question is not whether Rubrik's design partners find bugs, but whether they find them first.

"Rubrik is one of the partners we are working with to put Claude Mythos 5's cyber capabilities in defenders' hands, so they can find and validate attack paths before attackers do."
— Michael Moore, Cybersecurity Lead, Anthropic
$1.66B
Rubrik subscription ARR, Q2 FY27, up 33% YoY
150
Organizations with Mythos access via Project Glasswing as of June 2
72 hours
Time for Hacktron to breach OpenAI using Claude Opus 5
$0
Published pricing for Code Guardian (private preview only)