• Home
  • Technology
  • Gaming
  • Entertainment
  • World & Business
  • Science
  • Sports
  • AI
HomeTechnologyGamingEntertainmentWorld & BusinessScienceSportsAI
Technology
Announcement

Anthropic launches free, opt-in OSS Scanner for critical open-source projects

Techmeme, citing Anthropic, says OSS Scanner sends AI-generated vulnerability reports without human review.

TechmemeTE
AnthropicAN
leventLE
8 Sources, 1d ago, first seen 1d ago

TLDR

Techmeme, citing Anthropic, reports that OSS Scanner is a free, opt-in vulnerability scanner for critical open-source projects. Its AI-generated reports are sent without human review.

Combined views

554.7K

8 Sources, first seen 1d ago

2.6K likes113 comments1.2K saves238 reposts

Combined views

554.7K

8 Sources, first seen 1d ago

2.6K likes113 comments1.2K saves238 reposts

OSS Scanner gives eligible open-source projects free, periodic vulnerability scans using Anthropic’s strongest models, including Claude Mythos. The service is opt-in, and its reports are sent without human review or triage.

Featured Source

That trade-off is central to the launch. Maintainers can receive findings faster, but Anthropic says the model-generated reports may be incorrect or invalid. Each report can include a self-contained reproducer, an explanation of the vulnerability and when it was introduced, plus a candidate patch when one is available.

A backlog too large to review by hand

Anthropic says its models found more than 29,000 candidate vulnerabilities over the past six months, while its team manually reviewed and triaged about 6,000. The company also says it has sent nearly 5,000 unverified reports to maintainers who asked to receive everything available.

During early testing across dozens of open-source projects, the company says the scanner produced hundreds of reports. Some findings could be combined into unauthenticated remote-code-execution exploits, according to Anthropic.

The company also asked penetration testers to review 97 critical or high-severity findings across 48 projects. Anthropic says 85, or 88%, met the standard for its coordinated vulnerability disclosure process. Of the remaining 12, 11 duplicated known issues or other scan findings and one was invalid. It cautions that severity ratings can still be inflated or based on a mistaken understanding of a project’s threat model.

Who can enroll

Core maintainers can apply through Anthropic’s OSS Scanner repository. The company says eligibility will be decided case by case for projects with a critical impact on infrastructure and user security.

OSS Scanner is an optional fast track for projects that can triage raw findings. Anthropic says it will continue its human-reviewed disclosure process, particularly for projects that lack the resources to evaluate a stream of unverified reports.

Sentiment

Positive——Negative

Summary

Not enough discussion yet.

No sentiment analysis available yet.

Useful links

AnthropicAI

An opt-in vulnerability-finding service for open-source software

AnthropicAI

Project Glasswing: An initial update

Sentiment

Positive——Negative

Summary

Not enough discussion yet.

No sentiment analysis available yet.

Useful Links

AnthropicAI

An opt-in vulnerability-finding service for open-source software

AnthropicAI

Project Glasswing: An initial update

Useful Links

AnthropicAI

An opt-in vulnerability-finding service for open-source software

AnthropicAI

Project Glasswing: An initial update

Related

Anthropic breaches reportedly spark White House AI reporting mandate

Axios says the administration took a more active stance after Anthropic reported incidents involving government systems.

Anthropic AI model reportedly sent a false homicide tip to Philadelphia police

TechCrunch reports Anthropic did not discover the behavior until over two months after its AI submitted the tip.

Jack Clark left Bloomberg’s AI beat for OpenAI, then co-founded Anthropic

Employment records show a direct 2016 move, correcting a viral account of a months-long study break.

9 Sources

AnthropicAIAn opt-in vulnerability-finding service for open-source software1d
Techmeme@TechmemeAnthropic launches OSS Scanner, a free opt-in vulnerability scanner for critical open-source projects; its AI-generated reports are sent without human review (Anthropic) (Visit Techmeme dot com for the link and full context!)1d
Anthropic@AnthropicAITo secure open-source software, we’re launching OSS Scanner. We’ll use our frontier models to periodically scan opted-in open-source projects for vulnerabilities, at no cost. Our reports will provide a proof-of-concept, explanation, and suggested fix. https://www.anthropic.com/research/launching-opt-in-vuln-finding-service-for-open-source1d
levent@__alpoge__“Highly cyber-capable AI models are widely available to attackers now. But defensive tools—including our own—have not yet reached enough of the defenders who need them. OSS Scanner, our Cyber Verification Program, defensive products our partners build on our platform, and Claude Security are some of our efforts here, and we’ll be adding others as soon as possible.”1d
The Verge@vergeThe new OSS Scanner service offers vulnerability reports from Anthropic’s “strongest models,” including Mythos. https://www.theverge.com/ai-artificial-intelligence/1008521/anthropic-open-source-oss-scanner1d
SiliconANGLE@SiliconANGLEAnthropic launches critical infrastructure program and free OSS Scanner for open source https://ift.tt/UHMVbAu1d
Engadget@engadgetAnthropic is offering open-source projects a new way to check for vulnerabilities with its OSS Scanner.13h
Ghost in the AI 👻@JeanMar61773039OSS Scanner d'Anthropic : les rapports seront générés par le modèle, sans relecture ni tri humain Avant ça, six mois de scans de projets majeurs : plus de 29 000 vulnérabilités candidates, environ 6 000 triées à la main12h
    • Home
    • Technology
    • Gaming
    • Entertainment
    • World & Business
    • Science
    • Sports
    • AI
    Anthropic

    9 Sources

    AnthropicAIAn opt-in vulnerability-finding service for open-source software1d
    Techmeme@TechmemeAnthropic launches OSS Scanner, a free opt-in vulnerability scanner for critical open-source projects; its AI-generated reports are sent without human review (Anthropic) (Visit Techmeme dot com for the link and full context!)1d
    Anthropic@AnthropicAITo secure open-source software, we’re launching OSS Scanner. We’ll use our frontier models to periodically scan opted-in open-source projects for vulnerabilities, at no cost. Our reports will provide a proof-of-concept, explanation, and suggested fix. https://www.anthropic.com/research/launching-opt-in-vuln-finding-service-for-open-source1d
    levent@__alpoge__“Highly cyber-capable AI models are widely available to attackers now. But defensive tools—including our own—have not yet reached enough of the defenders who need them. OSS Scanner, our Cyber Verification Program, defensive products our partners build on our platform, and Claude Security are some of our efforts here, and we’ll be adding others as soon as possible.”1d
    The Verge@vergeThe new OSS Scanner service offers vulnerability reports from Anthropic’s “strongest models,” including Mythos. https://www.theverge.com/ai-artificial-intelligence/1008521/anthropic-open-source-oss-scanner1d
    SiliconANGLE@SiliconANGLEAnthropic launches critical infrastructure program and free OSS Scanner for open source https://ift.tt/UHMVbAu1d
    Engadget@engadgetAnthropic is offering open-source projects a new way to check for vulnerabilities with its OSS Scanner.13h
    Ghost in the AI 👻@JeanMar61773039OSS Scanner d'Anthropic : les rapports seront générés par le modèle, sans relecture ni tri humain Avant ça, six mois de scans de projets majeurs : plus de 29 000 vulnérabilités candidates, environ 6 000 triées à la main12h
    Today's Rank

    —

    Not ranked yet

    Today's Rank

    —

    Not ranked yet