{
  "id": 13314504,
  "title": "Anthropic Announces Free AI-Powered Vulnerability Scanner For Open Source Projects",
  "url": "https://urgent.news/2026/10/10/anthropic-announces-free-ai-powered-vulnerability-scanner-for-open",
  "topic": "ai",
  "section": "AI",
  "published": "2026-10-10T03:09:11.000Z",
  "source": {
    "name": "Lowyat.NET",
    "slug": "lowyat-net",
    "url": "https://www.lowyat.net/2026/406917/anthropic-free-vulnerability-scanner/"
  },
  "original_language": "en",
  "account": "Anthropic has introduced a new free AI-powered vulnerability scanner called OSS Scanner, aimed at open source projects. The service is inspired by Google's OSS-Fuzz and utilizes Anthropic's top language models, particularly Claude Mythos, to continuously assess code for security risks and issues. Reports generated by the scanner are entirely AI-generated and require no human review or analysis, enabling swifter and more frequent scans. However, the absence of human oversight raises the risk of potentially inaccurate or invalid findings, as AI models are known to 'hallucinate' or make things up.\n\nAnthropic has found that 88% of OSS Scanner's initial results met the criteria for their coordinated vulnerability disclosure (CVD) process, with just one false positive. Despite this impressive accuracy rate, the company stresses that the scanner is not infallible and will endeavor to enhance it based on user feedback. They will continue to manually disclose verified vulnerabilities through their CVD process.\n\nOSS Scanner is an optional choice for developers who wish to receive vulnerability reports as soon as they arise. For enterprises seeking comprehensive code scanning and patching, Anthropic also offers Claude Security, a paid service. Interested parties can visit Anthropic's official website for enrollment instructions for their projects, though note that not all projects may be eligible for the service.",
  "summary": "The instances of AI models “going rogue” and getting into places they shouldn’t be have proven that the bots are really good at finding vulnerabilities in systems. So it shouldn’t come as a surprise that some companies have decided to leverage these capabilities. Anthropic has recently announced OSS Scanner, a free opt-in service that checks […] The post Anthropic Announces Free AI-Powered…",
  "key_points": [
    "Anthropic launches free AI-powered OSS Scanner for open source projects",
    "Claude Mythos language models assess code for security risks",
    "88% of initial results meet coordinated vulnerability disclosure criteria"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}