Anthropic Launches Free Vulnerability Scanner for Open-Source Software

4 Min Read
  • Anthropic has launched OSS Scanner, a free, opt-in vulnerability-finding service for open-source software.
  • The service uses Anthropic’s most powerful models, including Claude Mythos, and generates reports without human review.
  • Penetration testers found that 85 of 97 critical and high-risk findings across 48 projects met coordinated vulnerability disclosure quality requirements.

Anthropic has launched OSS Scanner, a free service designed to find vulnerabilities in open-source software. The opt-in program will allow eligible projects to receive periodic checks using the company’s most powerful models, including Claude Mythos, expanding access to security audits for open-source developers.

Anthropic built the service using experience gained from deploying artificial intelligence to find vulnerabilities through Project Glasswing. Unlike its enterprise product, Claude Security, OSS Scanner focuses on supporting open-source developers and will provide audits at no cost, the company said.

Models identified more than 29,000 potential vulnerabilities

Anthropic said it used its latest models over the past six months to review some of the most important software projects. The models identified more than 29,000 potential vulnerabilities, but specialists were able to verify and prioritize only about 6,000 manually.

Open-source developers have increasingly asked to receive all identified issues, including findings that specialists have not yet reviewed, according to the company. By the time Anthropic announced OSS Scanner, it had sent project maintainers nearly 5,000 such reports, along with suggested fixes.

OSS Scanner is intended to accelerate that process by generating reports automatically and without human review, allowing projects to be scanned more frequently. Anthropic cautioned that the results may contain false positives, duplicate findings or inaccurate severity assessments.

Before the launch, Anthropic tested the scanner on dozens of open-source projects. The initial results produced hundreds of bug reports, including several cases in which vulnerabilities could be chained to enable unauthenticated remote code execution, or RCE.

Penetration testers reviewed high-risk findings

For further validation, penetration testers analyzed 97 critical and high-risk findings across 48 projects. Of those, 85 findings, or 88%, met the quality requirements of the coordinated vulnerability disclosure process.

Another 11 findings were genuine bugs but duplicated previously known issues or other scan results. Only one finding was a false positive.

Some project maintainers nevertheless said the scanner may overstate severity ratings or misinterpret a project’s threat model. Anthropic said it would continue improving the system based on developer feedback and advances in its models.

Scanner reports will include code that reproduces the bug, an explanation of the vulnerability, information about when it may have entered the code and, when available, a proposed fix.

How projects can apply

Maintainers of eligible projects can apply by creating a request in the service’s GitHub repository and following its standard template and additional instructions.

Anthropic will select projects individually, using criteria similar to those employed by OSS-Fuzz. The principal requirement is that a project have a significant effect on infrastructure and user security.

Separately, Broadcom will provide Anthropic with as much as $42 billion to fund AI infrastructure, according to an earlier report.

Source: Incrypted

DWF Labs Sues BitGo for $141 Million Over Unlocked Token Sales

DWF Maas and Falcon Digital seek $141 million from BitGo in London’s High Court, alleging it sold Falcon Finance and ESPORTS tokens before lock-ups expired, breaching contracts and depressing their…

3 Min Read
Anthropic Launches Free Vulnerability Scanner for Open-Source Software

Anthropic launched OSS Scanner, a free, opt-in service using models including Claude Mythos to find open-source vulnerabilities, after testers said 85 of 97 critical and high-risk findings met disclosure quality…

4 Min Read
Cardano Founder Criticizes Buterin’s Assessment of Post-Quantum Cryptography Risks

Cardano founder Charles Hoskinson criticized Ethereum co-founder Vitalik Buterin’s assessment of lattice-based cryptography, warning that what he called unsupported fears could delay post-quantum protections and expose more communications to future…

4 Min Read
CryptoQuant Attributes Bitcoin Correction to Weak Spot Demand

CryptoQuant linked bitcoin’s pullback to weak spot demand and cooling derivatives activity, reporting open interest fell nearly 10% to $26 billion while spot ETF holdings rose and identifying $69,000 as…

3 Min Read
Greece Plans to Impose 10% Tax on Cryptocurrency Profits

Greece is consulting publicly on a bill expected to reach parliament in November that would impose a 10% capital gains tax on cryptocurrency profits, exempting annual profits up to €500.

2 Min Read