Penetration Testing
Sakana's Fugu-Cyber finds the vulnerabilities Claude Opus 5 was designed to miss
Anthropic capped Claude Opus 5's security skills. Specialized models like Google's Gemini 3.5 Flash Cyber and Sakana's Fugu-Cyber outperform it in vulnerability discovery. A case for testing alternatives before renewing enterprise licenses.
Emmanuel Fabrice Omgbwa Yasse AI-assisted
2026-07-26 · 2 min read

The deliberate cap
Anthropic deliberately capped Claude Opus 5's cybersecurity abilities, creating a known blind spot for penetration testing workflows. The model remains competitive: it nearly matches Anthropic's flagship Fable 5 on coding and knowledge benchmarks while costing 50% less per token. But that tradeoff means security teams using it for red-teaming may need to supplement their toolchain, as the model's launch disclosure itself acknowledged.
Specialized models already exploit the gap
The gap is not hypothetical. Google's Gemini 3.5 Flash Cyber, a lightweight fine-tune, found 55 unique confirmed vulnerabilities in the V8 JavaScript Engine during testing, compared to 36 found by Claude Opus 4.6. Google says the model is fine-tuned on over 700,000 open-source vulnerabilities from OSV.dev, giving it a data-driven edge that its own benchmark results confirmed. Sakana AI's Fugu-Cyber, a multi-agent orchestration model, matches frontier cyber models like GPT-5.5-Cyber and Mythos-Preview on key benchmarks, adding to the evidence that specialized models can outperform general-purpose ones on security tasks. The broader trend of AI agents rewriting security is documented in this survey of autonomous attacks and defenses.
Why Fugu-Cyber's multi-agent architecture matters
Sakana is not just releasing a model; it is pushing back against the idea that any single model can solve enterprise security. Fugu-Cyber uses multiple sub-agents that validate each potential vulnerability before suggesting a patch, with humans in the loop. The company argues that raw model access alone does not fix enterprise security without proper infrastructure and vetting. Fugu-Cyber supports 13 model providers and includes anti-hallucination measures to keep claims tied to real outputs. The need for such diverse testing tools was underscored by the Hugging Face breach by an autonomous AI agent.
The practical call: test before renewing
For security-conscious teams, the implication is clear: do not treat Claude Opus 5 as a universal red-teaming tool. Before renewing enterprise licenses, test Fugu-Cyber and Gemini 3.5 Flash Cyber (where available) as complements or replacements. The blind spot in Claude's design may leave critical gaps that specialized models are already filling. Open-source alternatives like VulnClaw's automated pentesting pipeline also demonstrate that the ecosystem is moving beyond single-model reliance. As Sakana puts it, the real work is in the post-sale infrastructure: building the pipelines that make models safe and reliable in production.
Get the tech essentials in 3 minutes every morning
One email, every weekday, with what actually matters in AI and tech.