thehackernews.com 9 Oct 2026, 12:47 UTC

Anthropic launches free AI scanner to uncover open source flaws

CyberSIXT Evidence Panel Source marked as original reporting

ANTHROPIC has unveiled OSS Scanner, a free opt-in vulnerability scanner for open-source projects, designed to help secure the ecosystem using artificial intelligence. The service is billed as fully model-generated, with outputs not requiring human review or triage, enabling faster and more frequent scans. Reports are expected to be produced by Anthropic’s strongest models, including Claude Mythos.

Project maintainers can join by submitting a pull request on the OSS Scanner GitHub repository, accompanied by a YAML configuration that specifies the repository to clone, the primary contact email, and a path to the Dockerfile that builds the environment for an offline agent to audit the project.

The YAML can also include optional details such as additional CC emails, project homepage, a GPG key for encrypting reports, a threat model file path, and an option to disable bug reports. Anthropic notes that the Dockerfile pre-installs dependencies and sets up the environment so that the security audit can run with no internet access; project maintainers are advised to verify that test cases pass inside the built container. As of writing, the OSS Scanner project page shows 116 pull requests.

Anthropic emphasises that the service does not currently impose a 90-day disclosure period on its findings, though it may withdraw or adjust policies for high-severity reports as confidence grows. The company also disclosed internal findings of over 29,000 candidate vulnerabilities across major software projects, with more than 6,000 flaws reported to maintainers and 584 advisories issued by 2 October 2026.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline