Science & Tech · Cybersecurity · 2 days ago

Anthropic offers free AI vulnerability scans to open-source projects

Anthropic offers free AI vulnerability scans to open-source projects

Anthropic has launched OSS Scanner, a free service that periodically checks participating open-source projects for security flaws.

Open-source software is code that developers can use and build on, and many widely used services rely on it.

The scanner uses Anthropic’s strongest AI models, including Claude Mythos, and sends suspected flaws and possible fixes to project maintainers without human review.

That can help teams find problems sooner, but maintainers must check the findings because some may be incorrect or misjudge a flaw’s severity.

Anthropic says it has identified more than 29,000 possible vulnerabilities in major projects and manually reviewed a little over 6,000.

In an early test, penetration testers assessed 97 high- and critical-severity findings: 85 met the company’s coordinated disclosure criteria, 11 duplicated known issues or other findings, and one was invalid.

Core maintainers can apply through the OSS Scanner GitHub repository, and Anthropic says scan frequency will depend partly on demand and how widely a project is used.

Sources

Related news