Friday, October 9, 2026 · Anthropic

From Issue 67 (2026-10-09) · 14 stories in this issue

04 PRODUCT

❯ Anthropic launches OSS Scanner, using its strongest models to scan open-source projects for free and sending reports to maintainers without human review

Free, opt-in and recurringAnthropic launched OSS Scanner on October 8, a vulnerability-scanning service for open-source software. Once a project opts in, Anthropic scans its code periodically with its strongest models, including Claude Mythos, at no cost. Each report includes a self-contained reproducer, an explanation of the vulnerability and, where available, a candidate patch.

More findings than reviewersOver the past six months Anthropic’s models found more than 29,000 candidate vulnerabilities in major open-source projects, and humans have only been able to review about 6,000. Many maintainers, after receiving the first reports, asked for everything, validated or not, and nearly 5,000 reports have gone out that way. OSS Scanner makes that fast track permanent: reports are fully model-generated with no human triage, and Anthropic acknowledges some may be wrong.

One false positive in 97To check quality, Anthropic asked expert penetration testers to review 97 critical and high-severity findings from the scanner across 48 projects: 85 met the bar for formal disclosure, 11 were real but duplicated known issues, and only one was a false positive. A maintainer of the cryptography library wolfSSL said all but two of the 74 reports it received were valid and five became CVEs.

Fixing faster than attackersAnthropic’s reasoning is that exploits can now be written in minutes, so whoever finds a flaw first has the edge. Core maintainers enroll by submitting a request to a designated GitHub repository; eligibility follows criteria similar to Google’s OSS-Fuzz, requiring critical impact on infrastructure and user security. The pressure shifts to maintainers: reports arrive faster and in greater volume, while verifying and merging patches still takes people.

▮ SIGNALWith models pushing the cost of finding bugs toward zero, the bottleneck in open-source security has moved from nobody reading the code to nobody having time for the reports; maintainer attention is the scarce resource.