
What happened
Anthropic launched OSS Scanner, which runs security audits on open source projects using its most capable models including Claude Mythos, free of charge, with no human review. An expert check of 97 vulnerabilities found across 48 projects showed 85 (88%) met cooperative disclosure standards.
Why it matters
Because the scanning is done entirely by AI with no human review, reports can be wrong or turn out not to be valid issues. Still, initial validation produced hundreds of bug reports, including several chaining multiple vulnerabilities into unauthenticated remote code execution exploits.
WHO IT HITSOpen source maintainers of critical infrastructure projects such as PostgreSQL and OpenSSL, whose workload may shift as AI-generated vulnerability reports arrive, and security researchers who review coordinated vulnerability disclosure findings.
Summaries like this, in your inbox every morning.
Anthropic positions OSS Scanner as a specialised counterpart to Claude Security, its general code scan-and-patch product, narrowing the focus to open source projects. Reporting includes reproduction steps and descriptions of weaknesses, and in some cases binary searches to pinpoint when a bug was introduced as well as draft patches.
Anthropic itself says it cannot guarantee OSS Scanner is perfect, and points to maintainer feedback and model improvements as the basis for ongoing refinement. That caveat reflects the trade-off built into a fully automated workflow: it enables fast and frequent scans, but it carries risks of inaccurate or invalid reports.
Early validation drew participation from projects including PostgreSQL and OpenSSL. Noah Misch, a PostgreSQL developer, said an unusually high share of bugs was found, that several reports contained near-ready fixes, and that a fast delivery route allowed the latest issues to be handled before reaching a GA release.
Pick your industry and the AI tools you use, and get news related to your work every day.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
On a self-built 76-question Jev-format set, six trained 3B–9B open-weight models (Imajev-4B, Clef-Flash 9B, Je…

The Association for Human Mathematics said OpenAI's release of 722 AI-generated "mathematical results" is not…

OpenAI published 719 manuscripts covering 372 topic families on October 6, 2026, all produced by an internal f…

Stanford and Carnegie Mellon researchers tracked 1182 Character.AI users from September 2024 to August 2025, t…

A study presented at USENIX Security Symposium 2026 examined 196,682 resumes from hiring platforms and detecte…

The open-source ax-engine for Apple Silicon Macs measured over 76 tok/s decode on one M5 Max setup, and about…
