Anthropic introduces free AI-powered security scanner: The wider industry impact

Anthropic introduces free AI-powered security scanner: The wider industry impact

AI giant Anthropic has introduced a free vulnerability-scanning service for open-source software projects, using its latest Claude models to identify security flaws and generate bug reports as the company expands its efforts to apply artificial intelligence to cybersecurity.

Anthropic said the initiative draws on lessons from its vulnerability research efforts under Project Glasswing and is designed to help maintainers discover and fix software weaknesses before attackers can exploit them. The new service, called OSS Scanner, is an opt-in programme that offers periodic security scans to eligible open-source projects at no cost.

  • PostgreSQL: Noah Misch said several reports came with fixes the project could use nearly as they were, and that fast-track access let the team address new issues before a general-availability release. * OpenSSL Corporation: Anton Arapov said the reports, raw model output included, were as good as and sometimes better than those from people, especially when an exploit was attached. * wolfSSL: Todd Ouska said that of 74 reports, all but two were valid and five became CVEs. * HotCRP: Eddie Kohler praised the reports for their grasp of the project’s complex permission model.

The company said AI systems have improved from detecting fewer than 20% of vulnerabilities on a key academic benchmark early last year to finding more than 85% this year.

Language models have become significantly more capable at finding software vulnerabilities, according to Anthropic. Anthropic said this allows faster and more frequent scans but means some reports may be incorrect or invalid. OSS Scanner’s output is fully model-generated, with no human review or triage. Each report includes a self-contained reproducer and an explanation of the vulnerability.

In one validation exercise, expert penetration testers who review Anthropic’s disclosures checked 97 critical and high-severity findings across 48 projects. Of these, 85 (88%) met the bar for the disclosure process. Of the other 12, 11 were real but duplicated known issues or other scan findings, and one was a false positive.

Where possible it also traces when the bug was introduced, and it offers a candidate patch when one is available.

Anthropic acknowledged that some maintainers have said severity ratings can be inflated, or that the scanner misunderstood a project’s threat model. Anthropic will keep sending human-verified reports through its existing coordinated vulnerability disclosure process, especially for projects that lack resources to triage reports themselves. OSS Scanner is an optional fast track for maintainers who want reports as soon as they are generated. It is separate from Claude Security, Anthropic’s general-access code scanning and patching product for enterprises. Anthropic spent several weeks testing the pipeline with dozens of open-source projects. The first disclosures contained hundreds of bug reports, including several vulnerabilities that could be chained into unauthenticated remote code execution exploits. Maintainers who tested early versions were largely positive:

Core maintainers of eligible projects can enroll by submitting a pull request to a GitHub repository Anthropic has set up. Eligibility follows criteria similar to OSS-Fuzz’s, chiefly that a project has “critical impact on infrastructure and user security. Anthropic will decide case by case. Anthropic also pointed to two related programs: a Cyber Verification Program that gives qualifying security professionals advanced cyber capabilities with fewer blocking classifiers, and Claude for OSS, which offers free Claude Max 20x subscriptions to help fix vulnerabilities. You use AI every day. Now get your AI Quotient. Take the AIQ test.

Leave a Reply

Your email address will not be published. Required fields are marked *