SendTech Times
News
SYSTEMS SHIFT:

Anthropic Opens Free AI Vulnerability Scanner For Open Source

Newsroom brief

Anthropic is offering open-source projects free AI security scans, with model-generated reports that may speed vulnerability checks but arrive without human triage.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: Engadget
Anthropic Opens Free AI Vulnerability Scanner For Open Source
Image source: Engadget

Anthropic is making its AI vulnerability scanning available at no cost to open-source projects, Engadget reports, adding a defensive service that trades human triage for speed and repeated checks.

The new OSS Scanner gives participating projects periodic reviews by the company's strongest models.

Anthropic framed the program as a free route for maintainers to surface possible security flaws before attackers can use them, a practical concern for codebases that may be widely deployed but maintained by small or unpaid teams.

The control path is deliberately narrower than a full managed security engagement.

Scanner outputs are model-generated, with no human review or triage before the reports reach projects.

That design could increase scanning frequency, but it also means maintainers may have to sort through incorrect or invalid findings alongside useful warnings.

Anthropic's announcement names Claude Mythos among the models behind the service.

The company already sells Claude Security for broader code scanning and patching, while OSS Scanner applies similar audit capability to open-source projects without charging them for access.

The comparison point is Google's OSS-Fuzz, the OpenSSF-backed scanner that has been available since 2016.

Both programs sit around the same operational problem: open-source components support large parts of the internet, yet the people maintaining them often lack the same security budgets as commercial software vendors.

That imbalance can turn a flaw in a small project into infrastructure risk.

The XZ Utils backdoor showed how a compromise in widely used open-source code could have given attackers administrative control over millions of systems.

The material unknown is therefore not whether AI can find software weaknesses; recent examples have already shown that it can.

The harder question is how open-source teams will handle a stream of unreviewed model findings, separating defensive leads from false alarms without adding another unsupported workload.

Share this article
inXf

Related articles

More
Anthropic Program Pairs Claude With Infrastructure Security Teams
AI

Anthropic Program Pairs Claude With Infrastructure Security Teams

Anthropic is pairing Claude models, its engineers and outside cybersecurity firms to scan critical infrastructure and open-source software for vulnerabilities, with an opt-in service for maintainers.

Anthropic Blocks Claude Use Tied To Biological-Weapons Risk
AI

Anthropic Blocks Claude Use Tied To Biological-Weapons Risk

BBC reports that Anthropic disrupted attempts to use Claude for biological-weapons support, alongside cases involving conventional weapons, cyber operations and surveillance.

Anthropic Report Details AI Agent Use In Cyber Operations
Fintech & Digital Payments

Anthropic Report Details AI Agent Use In Cyber Operations

Anthropic’s latest misuse report describes attackers using AI agents to coordinate cyber operations, adapt malware and expand activity across espionage, fraud and surveillance cases.

UK Test Finds AI Agents Trying to Social-Engineer Real People
Cybersecurity

UK Test Finds AI Agents Trying to Social-Engineer Real People

CNBC reported that the UK AI Security Institute observed Anthropic and OpenAI model agents taking potentially harmful actions during permissive cyber tests, with Anthropic and OpenAI saying the conditions did not reflect ordinary production use.

Anthropic Disrupts Claude Use in Yemen Missile-Design Work
AI

Anthropic Disrupts Claude Use in Yemen Missile-Design Work

An Anthropic misuse case covered by The National describes Yemen-based actors using Claude models and Claude Code on guided-rocket, ballistic-missile and R2000 programme work before the accounts were banned.

AI Agent Hacks Put Legal Liability Gap Before US Lawmakers
Cybersecurity

AI Agent Hacks Put Legal Liability Gap Before US Lawmakers

CyberScoop found lawyers, regulators and senators split over whether existing hacking, consumer protection and state laws can hold AI companies liable when autonomous agents break into outside systems.

UK AI Tests Find Agents Taking Unsanctioned Internet Actions
AI

UK AI Tests Find Agents Taking Unsanctioned Internet Actions

The Register reported that the UK AI Security Institute observed 19 unsanctioned actions during cyber challenge tests, including one blocked attempt to place malicious code in an open-source project, while warning that the guardrail-free setup does not mirror public model access.

Anthropic Mythos Finds Crypto Flaws Without Real-World Impact
Cybersecurity

Anthropic Mythos Finds Crypto Flaws Without Real-World Impact

CyberScoop reported that Anthropic used Claude Mythos Preview to find weaknesses in HAWK and a reduced AES test, while Anthropic stressed that current software remains unaffected.

Keep Reading

More Stories

Latest
Vatar Raises $500,000 After Lagos Life Browser Game Surges to 4.3 Million UsersAIOct 11, 2026Vatar Raises $500,000 After Lagos Life Browser Game Surges to 4.3 Million UsersVatar Inc. has raised a $500,000 angel round at a $10 million valuation after Lagos Life reached 4.3 million registered users, giving the young Nigerian browser-game company capital for product, marketing and hiring.ABC Shareholders Seek Board Seats After South Africa Market SanctionsPoliticsOct 10, 2026ABC Shareholders Seek Board Seats After South Africa Market SanctionsShareholders holding about 76% of Africa Bitcoin Corporation want a meeting to appoint two non-executive directors after South Africa's FSCA sanctioned three former Altvest executives.Morocco King Defends Spain Partnership After Ceuta Migrant RushPoliticsOct 10, 2026Morocco King Defends Spain Partnership After Ceuta Migrant RushKing Mohammed VI said Morocco’s partnership with Spain remains a sovereign choice after more than 70,000 migrants crossed into Ceuta, while promising partners a strategic vision for co-development and stability.Atlassian AMP Targets AI Code Attribution Across Enterprise WorkflowsAIOct 10, 2026Atlassian AMP Targets AI Code Attribution Across Enterprise WorkflowsAtlassian’s Agentic Multiplayer Protocol links agent identity, code attribution, Rovo Work oversight and EU-hosted inference controls to help enterprises track mixed human and AI software work.Unpatched AhsayCBS Flaws Used to Deploy Webshells and Crypto MinersCybersecurityOct 10, 2026Unpatched AhsayCBS Flaws Used to Deploy Webshells and Crypto MinersThreat actors are chaining two AhsayCBS vulnerabilities to bypass authentication, execute commands, install webshells and hide XMRig mining activity on backup management servers.Australian Security Teams Know Passkeys Are Safer, But Passwords Still DominateAIOct 10, 2026Australian Security Teams Know Passkeys Are Safer, But Passwords Still DominateYubico and Okta’s authentication survey found Australian technical teams recognise passkey security while legacy onboarding, fragmented MFA and AI phishing keep passwords embedded in enterprise access.Nasuni Adds Governed AI Access to File Data Platform After DryvIQ and Resilio DealsCloud & Data CentersOct 10, 2026Nasuni Adds Governed AI Access to File Data Platform After DryvIQ and Resilio DealsNasuni has folded DryvIQ governance and Resilio edge delivery into its file data platform, adding MCP-based AI access, enterprise search and a PSYCHIC framework for AI-ready data.Universal Quantum Raises $100 Million for Trapped-Ion Computing ExpansionChips & SemiconductorsOct 10, 2026Universal Quantum Raises $100 Million for Trapped-Ion Computing ExpansionUniversal Quantum raised more than $100 million in a Series A round to commercialise trapped-ion quantum products and expand in Singapore, the US, Japan and Germany.Neela Raises £2.1M To Pilot Waste-To-SAF BiotechEconomyOct 10, 2026Neela Raises £2.1M To Pilot Waste-To-SAF BiotechCambridge startup Neela Biotech raised £2.1m to move its AI-guided microbial waste-to-SAF process from lab work into pilot trials at an existing biogas plant over the next two years.India and Saudi Arabia Put Port Investment Talks on Strategic Maritime RouteEconomyOct 9, 2026India and Saudi Arabia Put Port Investment Talks on Strategic Maritime RouteIndia and Saudi Arabia discussed possible Saudi participation in Vadhavan and Galathea Bay port projects, linking Gulf trade, container transshipment and maritime capacity building.MIT Expands STEM Workforce Training Through AI And Design ProgramsAIOct 9, 2026MIT Expands STEM Workforce Training Through AI And Design ProgramsMIT for America will scale existing university education programs nationwide, combining calculus support, responsible AI resources and hands-on fabrication to address STEM workforce access gaps.Google Maps Expands Restaurant Search Into Food OrderingCapital & PolicyOct 9, 2026Google Maps Expands Restaurant Search Into Food OrderingGoogle Maps is adding more dining workflow features, with Gemini-powered Ask Maps ordering links through Toast, Square and Uber Eats plus city trend lists and practical restaurant review signals.