Anthropic's OSSScanner scans open source without human review: 29,000 candidate vulns and counting

AGI Hunt · wechat · 2026-10-09

Anthropic announced its long-term CyberMission with two pillars: a Critical Infrastructure Defense Program (CIDP) for grids, water, and transit, and OSSScanner — a free AI-powered vulnerability scanner for open source projects.

How OSSScanner works

Why skip review: in six months models surfaced 29,000+ candidate vulns but humans triaged only 6,000. With attackers able to write exploits in minutes, Anthropic shipped 5,000 reports directly. wolfSSL got 74 reports with just 2 invalid and 5 CVEs; OpenSSL maintainers said reports read as well as human-written ones. On CyberGym, model vuln discovery jumped from under 20% to over 85% this year. CIDP's 11 founding partners include CrowdStrike, Palo Alto Networks, and Dragos. Anthropic predicts defenders gain the upper hand within two years, while conceding verification and patching remain bottlenecks. Maintainers can also apply for a free Claude Max 20x subscription.

Related event: Anthropic Launches OSS Scanner, Uncovering 29,000 Vulnerabilities in Open Source Projects(3 posts)→

Original post →

More from Safety

Safety channel →