Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

The Hacker News by The Hacker News
October 9, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananOct 09, 2026Vulnerability / Artificial Intelligence

Anthropic on Thursday unveiled OSS Scanner as an opt-in vulnerability scanner to help secure the open-source ecosystem using artificial intelligence (AI).

“It’s an opt-in service informed by our experience using Claude to find vulnerabilities during Project Glasswing,” Anthropic said. “Projects that join will receive thorough, periodic security scans by our strongest models at no cost.”

Anthropic also noted that the outputs of the scanner will be fully model-generated and do not require human review or triage, thereby facilitating faster and more frequent scanning. These reports are expected to be generated by its strongest models, including Claude Mythos.

The company pointed out that it expects to use a set of criteria similar to Google’s OSS-Fuzz to pick projects, while emphasizing that the process may evolve over time. Project maintainers are advised to provide a short description  explaining the importance of their project in cases where “it is not already self-evident.”

Core maintainers of a project can enroll by opening a pull request on the OSS Scanner’s GitHub repository along with a YAML configuration file that provides the following information –

  • Link to the git repository that should be cloned
  • Email address of the primary contact
  • A repository-relative path to the Dockerfile that sets up the environment, pre-installs all dependencies and builds the project so to help an offline agent conduct its security audit

“The Dockerfile configures the environment that the project will run in and installs all dependencies so that the agent can perform its security audit without any internet access,” Anthropic said. “We recommend verifying that the test cases pass inside of the built container.”

Other optional details that can be added to the YAML file are below –

  • Additional email addresses that are to be CC’ed on all reports
  • Project home page
  • GPG public key to encrypt report emails
  • A repository-relative path to a threat model file (“threat_model.md”) that spells out what code should be tested, vulnerability classification, or report formats.
  • Opt out of receiving bug reports by setting “disabled: true”

As of writing, a total of 116 pull requests have been submitted. Unlike other vulnerability reporting programs, Anthropic said it does not intend to impose a 90-day disclosure period on the findings, given the risk that they may contain false positives.

“If we later validate one of these reports manually through our existing CVD program, we may disclose it under our CVD policy starting 90 days from when you are notified that a human has validated this report,” it added. “As we gain greater confidence in OSS Scanner’s performance, we may in the future impose a disclosure period on some high-severity vulnerability reports.”

The AI company said it has identified more than 29,000 candidate vulnerabilities in some of the world’s most important software projects, out of which a little more than 6,000 flaws have been reported to maintainers. These have resulted in 584 advisories as of October 2, 2026.

The development comes as Anthropic also unveiled the Critical Infrastructure Defense Program to safeguard critical infrastructure and open-source software as part of its Cyber Mission.

With AI increasingly equipping bad actors to discover and exploit vulnerabilities, automate various stages of cyber operations, and conduct attacks faster and at scale, the idea behind the initiative is to arm defenders with the right tools to combat the threat, accelerate fixes, and explore new secure architectures and coding practices.

“Our forecast is that in two years, AI will favor defense: it will be easier to catch bugs before they ship, write fundamentally secure software from scratch, and actively defend systems with models,” Anthropic said. 



Source link

The Hacker News

The Hacker News

Next Post

Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

Recommended.

Bank of America CEO on inflation impact on U.S. economy: ‘Rates are going to stay where they are’

Bank of America CEO on inflation impact on U.S. economy: ‘Rates are going to stay where they are’

February 12, 2025
Cyber platformisation: Don’t fall into the ‘integration debt’ trap | Computer Weekly

Cyber platformisation: Don’t fall into the ‘integration debt’ trap | Computer Weekly

March 23, 2026

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026
How ByteDance Made China’s Most Popular AI Chatbot

How ByteDance Made China’s Most Popular AI Chatbot

October 16, 2025
The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

June 9, 2026

AWS Pours $6B Into New US Data Center As Amazon’s $220B Spending Goal Unfolds

August 20, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio