Friday, 9 October 2026NewsWorldBusinessTech
Latest

Anthropic Launches Free OSS Scanner for Open-Source Security

Anthropic launched OSS Scanner, a free automated service that uses advanced language models like Claude Mythos to scan open-source software for security vulnerabilities.

Anthropic debuted an opt-in vulnerability detection tool designed to provide thorough, periodic security scans by our strongest models at no cost to qualifying open-source projects, as reported by outlets including The Verge and UA.News, offering a new option for software maintainers facing a rising tide of automated code submissions as announced by Anthropic. Inspired by Google’s automated fuzzing initiative OSS-Fuzz, the newly established scanner aims to give code maintainers a defensive advantage against attackers who can exploit software flaws within minutes of discovery.

Scanner Generates Unfiltered Bug Reports Without Human Triage

The service operates entirely through automation, generating reports without initial human review or triage without human review or initial screening of reports. Because the outputs come directly from models including Claude Mythos, it is possible reports will be incorrect or invalid, according to Anthropic’s disclosures, even though this model-driven pipeline allows the system to check complex codebases faster and more frequently.

Professional penetration testers evaluated 97 critical and high-severity findings across 48 different projects to test the pipeline prior to launch.

Anthropic Launches Free OSS Scanner for Open-Source Security
Photo: ua.news

Early Results Across PostgreSQL, OpenSSL, wolfSSL, and HotCRP

Several prominent open-source maintainers tested early iterations of the scanner, reporting high signal-to-noise ratios and actionable fixes.

Additional maintainers shared similar findings regarding the actionable nature of the generated patches and bug prioritization models.

Balancing Automated Vulnerability Disclosures With Open-Source Capacity

AI-driven systems have successfully identified severe vulnerabilities such as the Copy Fail bug that impacted nearly all Linux distributions in May, yet maintainers face growing operational strain trying to cope with a sharp increase in AI-generated vulnerability reports, a challenge that prominent developers like Linus Torvalds and Google have encountered, as noted by The Verge and UA.News, as the software community grapples with the dual-edged sword of automated security tooling.

Anthropic stated it will continue its standard coordinated vulnerability disclosure process for projects that lack the internal resources to triage raw data. However, the new fast-track option caters directly to maintainers who prefer bulk unverified submissions accompanied by reproducible exploits and candidate patches.

Project Eligibility and Enrollment Requirements on GitHub

  • Projects must demonstrate a critical impact on infrastructure and user security to qualify.
  • Enrollment applications are evaluated on a case-by-case basis.
  • Maintainers can apply by submitting a pull request to the designated GitHub repository using the standard project template.

Eligible security professionals and project leads can also utilize the company’s separate Cyber Verification Program or access Claude Max 20x subscriptions designed to aid vulnerability remediation across open-source environments.