Urgent.News

What's breaking now, across thousands of outlets.

AI

Anthropic launches OSS Scanner, a free opt-in vulnerability scanner for critical open-source projects; its AI-generated reports are sent without human review (Anthropic)

We're launching OSS Scanner, an opt-in vulnerability scanner for the open-source ecosystem informed by our experience using Claude …

Anthropic has introduced OSS Scanner, a complimentary, opt-in vulnerability scanner designed for the open-source community. This tool, powered by Anthropic's sophisticated language models, offers thorough, periodic security scans to identified projects at no cost. Drawing from Anthropic's experience with Project Glasswing, which utilized Claude to identify vulnerabilities, the company has observed significant advancements in the efficacy of language models in discovering security flaws.

In a benchmark on CyberGym, they noted that LLMs have improved from detecting less than 20% of vulnerabilities in 2022 to over 85% in the current year. As a result, the frequency of bug reports received by maintainers has shifted from a high volume of dubious findings to high-quality reports. Over the past six months, Anthropic's cutting-edge models have scanned several critical software projects for vulnerabilities, uncovering over 29,000 potential issues, of which approximately 6,000 have been manually reviewed and triaged.

However, Anthropic is currently constrained by its human team's ability to validate these findings. They are actively working on expanding their vulnerability disclosure processes. In response to the growing urgency of addressing vulnerabilities before they can be exploited, Anthropic aims to provide maintainers with swift access to vulnerability reports, including unverified ones.

This service will enable faster scanning but acknowledges the potential for inaccuracies. Since its inception, the scanner has generated hundreds of bug reports, including several that were chained together to create unauthenticated remote code execution exploits. While Anthropic cannot guarantee the perfection of this system, they will continue to refine it based on feedback from maintainers and advancements in AI technology.

Eligible projects can enroll by submitting a PR to Anthropic's GitHub repository, adhering to the project template and guidelines provided in the extended FAQ. The scanner is designed for projects that pose a "critical impact on infrastructure and user security."

Written by urgent.news from Techmeme's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 2 other outlets

Read the original at anthropic.com →

More in AI

More from Thursday 8 October →