02
Anthropic opens free AI vulnerability-scanning service to selected open-source projects
Anthropic says its OSS Scanner will periodically scan enrolled open-source projects and send maintainers AI-generated reports describing suspected vulnerabilities, reproduction steps and possible fixes. In testing, penetration testers assessed 97 high- and critical-severity findings across 48 projects: Anthropic said 85 met its coordinated-disclosure criteria, 11 duplicated known issues or findings, and one was invalid. The company cautions that reports may overstate severity or misunderstand security assumptions, and applications are assessed individually.
Why it matters Participating maintainers gain additional vulnerability discovery but inherit the validation workload. Faster reporting therefore does not necessarily mean faster remediation for teams with limited triage capacity.
What to watch next For any unvalidated finding, a consequential next step would be Anthropic validating it through its coordinated-disclosure program: that could start a 90-day disclosure period, but it is not automatic.
HelpNet Security ↗