
Capital One has open-sourced VulnHunter, an AI-powered code security scanner that reasons like an attacker to identify exploitable vulnerabilities rather than merely flagging suspicious patterns.
Built for Claude Opus, it combines a vulnerability hunter, automated fixer, and independent verifier into a single remediation loop, aimed at cutting false positives and delivering actionable security fixes with evidence of the attack path.
What happened
Capital One released VulnHunter, an open-source AI security tool built for Claude Opus that analyzes source code by simulating an attacker's perspective rather than flagging suspicious patterns. It works through three composable skills—a vulnerability scanner (/vulnhunt), a fixer (/vulnhunter-fix), and a verification agent (/vulnhunt-fix-verify)—that form an automated remediation loop.
Why it matters
Traditional security scanners often produce false positives by flagging risky code patterns without confirming actual exploitability. VulnHunter's "falsification engine" discards findings that rely on unsupported assumptions, meaning teams receive only high-priority, actionable defects with evidence-backed fixes. Given that a single vulnerability in a widely-used open-source component can affect thousands of enterprises simultaneously, this approach could reduce noise and accelerate patching.
What to watch
VulnHunter requires Claude Opus and Claude Code access; users scanning Anthropic platforms must enroll in the Cyber Verification Program to avoid triggering safeguards. The suite includes batch-scanning and benchmarking tools (harness/) for developers testing accuracy across multiple repositories, and a headless runtime agent for CI/CD integration.
Ask the AI about this article →
VulnHunter addresses a structural problem in modern software security: the interconnectedness of open-source components means a single unpatched vulnerability can ripple across thousands of enterprises. Capital One's decision to open-source the tool reflects the recognition that no single organization can solve the challenge alone—the vulnerability landscape is too broad and the supply chain too distributed. The tool's core innovation is its reasoning model: rather than pattern-matching against known dangerous code structures (which floods teams with false positives), it simulates an actual attacker's journey through a codebase, evaluating whether each potential vulnerability is truly exploitable given the specific context and controls in place. This distinction between "flagging a pattern" and "proving exploitability" is what the tool calls its falsification engine. The architecture of three separate, composable skills—scanner, fixer, and independent verifier—creates an automated feedback loop that not only discovers vulnerabilities but also proposes, tests, and validates fixes, potentially reducing the manual burden on security teams. The requirement for Claude Opus reflects the tool's dependence on frontier-class reasoning capabilities; the developers explicitly note that the low false-positive discipline relies heavily on advanced foundation-model reasoning.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Visko raised $10 million in pre-seed funding from Llama Ventures and opened public access to its first foundat…
AI company Runway has unveiled Solaris, the first model in a new category it calls "Interface World Models." I…

Google's AI search gave advice to call emergency services for users alone with an African, Indian, or Pakistan…

John Deere introduced JD, a conversational AI tool that lets farmers ask open-ended questions about their hist…

Nvidia CEO Jensen Huang said on Fox Business that AI is creating 'hundreds of thousands' of jobs, including in…

Israeli startup DataAgent Ltd