Anthropic has launched OSS Scanner, a free vulnerability-scanning service for open-source projects, according to The Verge and SiliconANGLE. Projects that opt in start receiving periodic security scans at no cost.
The reports come straight out of Anthropic's strongest models, including Claude Mythos, with no human review or triage before they reach maintainers, according to both outlets. That breaks from Anthropic's usual disclosure process, in which an expert confirms a vulnerability before notifying the affected project.
Speed traded for human checking
Removing human review lets Anthropic run scans more often and surface alerts sooner. The trade-off, according to The Verge and SiliconANGLE, is that some reports will be wrong, including incorrect severity ratings. Maintainers are left to verify each alert themselves before acting on it.
SiliconANGLE reports that OSS Scanner grew out of a backlog in Anthropic's own disclosure pipeline: over the past six months, the company's models flagged more than 29,000 candidate vulnerabilities in widely used software, of which staff manually reviewed about 6,000. As maintainers began asking for the full unreviewed batch, Anthropic turned that demand into a standing service.
The same outlet says Anthropic tested the scanner's accuracy before opening it to more projects: the penetration testers who normally vet the company's coordinated disclosures checked 97 critical and high-severity findings across 48 projects and cleared 85 for disclosure. Of the other 12, nearly all were real bugs that duplicated issues already known.
Early testers' results
Encryption library developer wolfSSL told SiliconANGLE that of the 74 reports it received during early trials, all but two were valid, and five became CVEs, the public identifiers assigned to confirmed vulnerabilities. Anton Arapov of OpenSSL, an early tester of the service, told the outlet that a report with a real, working exploit attached is "basically job done for an engineer."
The Verge notes that AI tools have already helped uncover serious open-source flaws in recent months, but that maintainers such as Linus Torvalds have also reported struggling with the sheer volume of AI-generated bug reports arriving in their inboxes. OSS Scanner extends that trend by automating the writing of reports, not just the hunt for the flaws themselves.
SiliconANGLE reports the service is funded by Anthropic's Defender Advantage Fund, set up in August, and that maintainers can enroll by submitting a pull request to an Anthropic GitHub repository, under eligibility rules modeled on Google's OSS-Fuzz, the project that inspired the format.
Part of a broader security push
SiliconANGLE reports that OSS Scanner launched alongside a separate program, the Critical Infrastructure Defense Program, aimed at the security companies that serve operators of power grids, water systems and other critical infrastructure. Both fall under what Anthropic calls the Anthropic Cyber Mission.
Eleven providers signed on as founding partners of the infrastructure program, including consulting firm Booz Allen Hamilton and security vendors CrowdStrike and Palo Alto Networks, according to SiliconANGLE. Andrew Turner, president of commercial cyber at Booz Allen, called the equipment running plants and substations "the next frontier for autonomous AI-enabled attacks," the outlet reported.
SiliconANGLE also notes that both launches build on Project Glasswing, which gave vetted organizations access to Claude Mythos from April until it was folded into an expanded Cyber Verification Program earlier this month.
Anthropic told SiliconANGLE it expects AI to tilt the balance toward defenders within two years, but acknowledged that, for now, the cost of exploiting a flaw keeps falling while verifying and fixing one remains slow, people-dependent work. On operational technology specifically, the company said a fix may have to wait until equipment can be safely taken offline, which in rare cases could take decades.


