Back to Feed
ToolsOct 9, 2026

Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

Anthropic launches free AI vulnerability scanner for open-source projects.

Summary

Anthropic has introduced OSS Scanner, a free, opt-in AI-powered vulnerability scanner designed to enhance the security of open-source projects. Leveraging its Claude models, the service provides automated, periodic scans without requiring human review, aiming to accelerate vulnerability detection and remediation.

Full text

Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects Ravie LakshmananOct 09, 2026Vulnerability / Artificial Intelligence Anthropic on Thursday unveiled OSS Scanner as an opt-in vulnerability scanner to help secure the open-source ecosystem using artificial intelligence (AI). "It's an opt-in service informed by our experience using Claude to find vulnerabilities during Project Glasswing," Anthropic said. "Projects that join will receive thorough, periodic security scans by our strongest models at no cost." Anthropic also noted that the outputs of the scanner will be fully model-generated and do not require human review or triage, thereby facilitating faster and more frequent scanning. These reports are expected to be generated by its strongest models, including Claude Mythos. The company pointed out that it expects to use a set of criteria similar to Google's OSS-Fuzz to pick projects, while emphasizing that the process may evolve over time. Project maintainers are advised to provide a short description explaining the importance of their project in cases where "it is not already self-evident." Core maintainers of a project can enroll by opening a pull request on the OSS Scanner's GitHub repository along with a YAML configuration file that provides the following information - Link to the git repository that should be cloned Email address of the primary contact A repository-relative path to the Dockerfile that sets up the environment, pre-installs all dependencies and builds the project so to help an offline agent conduct its security audit "The Dockerfile configures the environment that the project will run in and installs all dependencies so that the agent can perform its security audit without any internet access," Anthropic said. "We recommend verifying that the test cases pass inside of the built container." Other optional details that can be added to the YAML file are below - Additional email addresses that are to be CC'ed on all reports Project home page GPG public key to encrypt report emails A repository-relative path to a threat model file ("threat_model.md") that spells out what code should be tested, vulnerability classification, or report formats. Opt out of receiving bug reports by setting "disabled: true" As of writing, a total of 116 pull requests have been submitted. Unlike other vulnerability reporting programs, Anthropic said it does not intend to impose a 90-day disclosure period on the findings, given the risk that they may contain false positives. "If we later validate one of these reports manually through our existing CVD program, we may disclose it under our CVD policy starting 90 days from when you are notified that a human has validated this report," it added. "As we gain greater confidence in OSS Scanner's performance, we may in the future impose a disclosure period on some high-severity vulnerability reports." The AI company said it has identified more than 29,000 candidate vulnerabilities in some of the world's most important software projects, out of which a little more than 6,000 flaws have been reported to maintainers. These have resulted in 584 advisories as of October 2, 2026. The development comes as Anthropic also unveiled the Critical Infrastructure Defense Program to safeguard critical infrastructure and open-source software as part of its Cyber Mission. With AI increasingly equipping bad actors to discover and exploit vulnerabilities, automate various stages of cyber operations, and conduct attacks faster and at scale, the idea behind the initiative is to arm defenders with the right tools to combat the threat, accelerate fixes, and explore new secure architectures and coding practices. "Our forecast is that in two years, AI will favor defense: it will be easier to catch bugs before they ship, write fundamentally secure software from scratch, and actively defend systems with models," Anthropic said. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Application Security, artificial intelligence, Open Source Security, Vulnerability ⚡ Top Stories This Week ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members How Financial Services Companies Can Modernize Their Software Supply Chain US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access Zero Trust for AI Agents Starts With Fixing Zero Visibility ⭐ Featured Resources Discover Hidden AI Agents and Lock Down Their Access — Get a Demo The CISO Playbook for Board-Ready Security Reporting The Browser Attacks Your Security Stack Is Missing 41 Cybersecurity Courses. One Week to Level Up Your Skills

Entities

OSS Scanner (product)Claude (product)Claude Mythos (product)AI (technology)Anthropic (vendor)open-source (technology)