Sunday , October 11 2026

Anthropic unveils “OSS Scanner” Free AI Vulnerability Scanner for Open-Source Projects

Anthropic unveiled OSS Scanner on Thursday as an opt-in vulnerability scanner designed to enhance security within the open-source ecosystem through artificial intelligence (AI).

“It’s an opt-in service informed by our experience using Claude to find vulnerabilities during Project Glasswing,” Anthropic said. “Projects that join will receive thorough, periodic security scans by our strongest models at no cost.”

Anthropic unveils “OSS Scanner” Free AI Vulnerability Scanner for Open-Source Projects

Anthropic unveiled OSS Scanner on Thursday as an opt-in vulnerability scanner designed to enhance security within the open-source ecosystem through...
Read More
Anthropic unveils “OSS Scanner” Free AI Vulnerability Scanner for Open-Source Projects

Rise on RCE Exploits Targeting Hikvision Camera Flaw

There was a rise in scanning and remote code execution attempts on video surveillance devices in Ukraine from September 21...
Read More
Rise on RCE Exploits Targeting Hikvision Camera Flaw

FortiBleed Attack Compromised 80,000+ Devices, SonicWall Patches 4 SMA1000 Flaws CVSS 10

The FBI and U.S. Secret Service released a joint warning about cybersecurity. The warning said that the FortiBleed campaign is...
Read More
FortiBleed Attack Compromised 80,000+ Devices, SonicWall Patches 4 SMA1000 Flaws  CVSS 10

Critical Atlassian & IBM Flaws Expose Files and Enable Remote Code Execution

Atlassian has fixed CVE-2026-21589, a serious flaw in Atlassian Data Center with a score of 9.3. This bug allows an...
Read More
Critical Atlassian & IBM Flaws Expose Files and Enable Remote Code Execution

Citrix NetScaler SAML 0-Day Flaw Under Attack

Citrix has put out emergency security updates for a NetScaler SAML flaw that hackers are using. Known as CVE-2026-88779, this...
Read More
Citrix NetScaler SAML 0-Day Flaw Under Attack

Major Danish university breached, 200,000 users at risk

Hackers got into the identity and access management system at the Technical University of Denmark (DTU) and downloaded a lot...
Read More
Major Danish university breached, 200,000 users at risk

Microsoft’s X account hijacked to promote Clippy crypto scam

Microsoft's official X account was taken over to promote an unapproved Clippy-themed cryptocurrency. The tech giant’s X account, with 13...
Read More
Microsoft’s X account hijacked to promote Clippy crypto scam

Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

CPanel has put out security updates to fix three problems in cPanel & WHM. These problems could let attackers take...
Read More
Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Anthropic also noted that the outputs of the scanner will be fully model-generated and do not require human review or triage, thereby facilitating faster and more frequent scanning.

The company pointed out that it expects to use a set of criteria similar to Google’s OSS-Fuzz to pick projects, while emphasizing that the process may evolve over time. Project maintainers are advised to provide a short description explaining the importance of their project in cases where “it is not already self-evident.”

Core maintainers of a project can enroll by opening a pull request on the OSS Scanner’s GitHub repository along with a YAML configuration file that provides the following information –
Link to the git repository that should be cloned
Email address of the primary contact
A repository-relative path to the Dockerfile that sets up the environment, pre-installs all dependencies and builds the project so to help an offline agent conduct its security audit

“The Dockerfile configures the environment that the project will run in and installs all dependencies so that the agent can perform its security audit without any internet access,” Anthropic said. “We recommend verifying that the test cases pass inside of the built container.”

Other optional details that can be added to the YAML file are below –
Additional email addresses that are to be CC’ed on all reports
Project home page
GPG public key to encrypt report emails
A repository-relative path to a threat model file (“threat_model.md”) that spells out what code should be tested, vulnerability classification, or report formats.
Opt out of receiving bug reports by setting “disabled: true”

As of writing, a total of 116 pull requests have been submitted. Unlike other vulnerability reporting programs, Anthropic said it does not intend to impose a 90-day disclosure period on the findings, given the risk that they may contain false positives.

“If we later validate one of these reports manually through our existing CVD program, we may disclose it under our CVD policy starting 90 days from when you are notified that a human has validated this report,” it added. “As we gain greater confidence in OSS Scanner’s performance, we may in the future impose a disclosure period on some high-severity vulnerability reports.”

The AI company said it has identified more than 29,000 candidate vulnerabilities in some of the world’s most important software projects, out of which a little more than 6,000 flaws have been reported to maintainers. These have resulted in 584 advisories as of October 2, 2026.

The development comes as Anthropic also unveiled the Critical Infrastructure Defense Program to safeguard critical infrastructure and open-source software as part of its Cyber Mission.

With AI increasingly equipping bad actors to discover and exploit vulnerabilities, automate various stages of cyber operations, and conduct attacks faster and at scale, the idea behind the initiative is to arm defenders with the right tools to combat the threat, accelerate fixes, and explore new secure architectures and coding practices.

“Our forecast is that in two years, AI will favor defense: it will be easier to catch bugs before they ship, write fundamentally secure software from scratch, and actively defend systems with models,” Anthropic said.

Check Also

German

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor …